IOC Report
SecuriteInfo.com.FileRepMalware.20421.11857.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.20421.11857.exe
"C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.20421.11857.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

URLs

Name
IP
Malicious
https://github.com/googlefonts/lexend)6_ju
unknown
https://scripts.sil.org/OFLThis
unknown
https://scripts.sil.org/OFLhttps://www.lexend.comBonnie
unknown
https://curl.haxx.se/docs/http-cookies.html
unknown

Memdumps

Base Address
Regiontype
Protect
Malicious
20E2E0DC000
heap
page read and write
20E2E050000
heap
page read and write
20E2E0D0000
heap
page read and write
7FF677807000
unkown
page write copy
F00DFE000
stack
page read and write
7FF677B03000
unkown
page read and write
7FF6777BB000
unkown
page readonly
20E2E0D6000
heap
page read and write
F00EFE000
stack
page read and write
7FF677806000
unkown
page read and write
7FF6777BA000
unkown
page readonly
7FF677691000
unkown
page execute read
7FF677B05000
unkown
page readonly
7FF6777BA000
unkown
page read and write
7FF677690000
unkown
page readonly
20E2DF70000
heap
page read and write
F00CFC000
stack
page read and write
7FF677690000
unkown
page readonly
7FF677691000
unkown
page execute read
7FF677B05000
unkown
page readonly
7FF677806000
unkown
page write copy
There are 11 hidden memdumps, click here to show them.