IOC Report
czcansrv.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\czcansrv.exe
"C:\Users\user\Desktop\czcansrv.exe"

Memdumps

Base Address
Regiontype
Protect
Malicious
C90000
heap
page read and write
E3A000
unkown
page readonly
EAE000
stack
page read and write
E54000
unkown
page readonly
9F0000
heap
page read and write
B10000
heap
page read and write
C9E000
heap
page read and write
DC1000
unkown
page execute read
E54000
unkown
page readonly
DC0000
unkown
page readonly
E50000
unkown
page write copy
AD0000
heap
page read and write
88C000
stack
page read and write
E3A000
unkown
page readonly
B5E000
stack
page read and write
E50000
unkown
page read and write
C5E000
stack
page read and write
C9A000
heap
page read and write
1160000
heap
page read and write
DC0000
unkown
page readonly
98D000
stack
page read and write
FAE000
stack
page read and write
DC1000
unkown
page execute read
There are 13 hidden memdumps, click here to show them.