IOC Report
5BL9UfLKF4

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\5BL9UfLKF4.exe
"C:\Users\user\Desktop\5BL9UfLKF4.exe"

URLs

Name
IP
Malicious
http://www.openssl.org/support/faq.html.
unknown
http://www.openssl.org/support/faq.html
unknown

Domains

Name
IP
Malicious
test.local
unknown

Memdumps

Base Address
Regiontype
Protect
Malicious
8D5000
heap
page read and write
400000
trusted library allocation
page read and write
4D5000
heap
page read and write
149000
stack
page read and write
8D0000
heap
page read and write
480000
heap
page read and write
14025F000
unkown
page write copy
14026A000
unkown
page write copy
140001000
unkown
page execute read
140269000
unkown
page read and write
48D000
heap
page read and write
140000000
unkown
page readonly
140271000
unkown
page write copy
140292000
unkown
page read and write
14024D000
unkown
page write copy
1402BA000
unkown
page read and write
1402C1000
unkown
page write copy
190000
heap
page read and write
84F000
stack
page read and write
1F0000
trusted library allocation
page read and write
1402C1000
unkown
page write copy
140253000
unkown
page write copy
74F000
stack
page read and write
14024E000
unkown
page write copy
140270000
unkown
page read and write
14024F000
unkown
page read and write
4C0000
heap
page read and write
1C0000
heap
page read and write
1402C2000
unkown
page readonly
14024D000
unkown
page read and write
140001000
unkown
page execute read
24BF000
unkown
page read and write
140251000
unkown
page write copy
140000000
unkown
page readonly
1402C2000
unkown
page readonly
14025D000
unkown
page read and write
140252000
unkown
page read and write
140294000
unkown
page write copy
1A0000
heap
page read and write
1402C0000
unkown
page read and write
There are 30 hidden memdumps, click here to show them.