IOC Report
hwPMkWBZ6O.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\hwPMkWBZ6O.exe
"C:\Users\user\Desktop\hwPMkWBZ6O.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

Memdumps

Base Address
Regiontype
Protect
Malicious
551000
unkown
page read and write
6D0000
heap
page read and write
551000
unkown
page readonly
552000
unkown
page readonly
9D000
stack
page read and write
401000
unkown
page execute read
565000
unkown
page execute and write copy
401000
unkown
page execute read
140000
heap
page read and write
1A0000
heap
page read and write
547000
unkown
page write copy
DD000
stack
page read and write
54C000
unkown
page read and write
190000
heap
page read and write
547000
unkown
page write copy
565000
unkown
page execute and write copy
400000
unkown
page readonly
400000
unkown
page readonly
6D8000
heap
page read and write
There are 9 hidden memdumps, click here to show them.