IOC Report
file.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\file.exe
"C:\Users\user\Desktop\file.exe"
malicious

URLs

Name
IP
Malicious
https://api.ipify.org/
104.26.13.205
https://api.ipify.org
unknown
http://crl.v
unknown
https://api.ipify.org/=
unknown

Domains

Name
IP
Malicious
api.ipify.org
104.26.13.205

IPs

IP
Domain
Country
Malicious
109.172.94.66
unknown
Russian Federation
malicious
104.26.13.205
api.ipify.org
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
2674DF30000
heap
page read and write
malicious
2674E120000
direct allocation
page execute and read and write
malicious
2674C5C0000
heap
page read and write
2674C73A000
heap
page read and write
2674EAA1000
heap
page read and write
2674C625000
heap
page read and write
7FF67E3C5000
unkown
page readonly
2674C6B2000
heap
page read and write
2674E53D000
heap
page read and write
2674EA80000
heap
page read and write
2674C620000
heap
page read and write
2674EAAA000
heap
page read and write
FD0A0FB000
stack
page read and write
7FF67E3C2000
unkown
page read and write
FD09DFE000
stack
page read and write
2674C70F000
heap
page read and write
2674C4E0000
heap
page read and write
2674E02E000
heap
page read and write
2674E115000
heap
page read and write
7FF67E3B8000
unkown
page readonly
2674E363000
heap
page read and write
7FF67E17A000
unkown
page readonly
2674C711000
heap
page read and write
2674E01E000
heap
page read and write
2674C6C3000
heap
page read and write
2674ECB3000
heap
page read and write
2674C630000
heap
page read and write
FD098ED000
stack
page read and write
2674C6C1000
heap
page read and write
FD0A1FF000
stack
page read and write
7FF67E141000
unkown
page execute read
2674C6D2000
heap
page read and write
2674EA90000
heap
page read and write
2674E110000
heap
page read and write
FD09FFD000
stack
page read and write
FD09BFE000
stack
page read and write
7FF67E17A000
unkown
page readonly
2674C741000
heap
page read and write
2674E330000
heap
page read and write
2674EB90000
heap
page read and write
7FF67E3C2000
unkown
page write copy
2674C6CF000
heap
page read and write
2674C690000
heap
page read and write
2674ECF9000
heap
page read and write
FD09EFE000
stack
page read and write
FD099FE000
stack
page read and write
2674C699000
heap
page read and write
2674C73D000
heap
page read and write
2674C5F0000
heap
page read and write
2674C6A6000
heap
page read and write
FD098F7000
stack
page read and write
FD09AFE000
stack
page read and write
7FF67E140000
unkown
page readonly
2674FD10000
heap
page read and write
2674DF80000
heap
page read and write
2674C6DF000
heap
page read and write
FD09CFE000
stack
page read and write
There are 47 hidden memdumps, click here to show them.