IOC Report
norm01_upx.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\norm01_upx.exe
"C:\Users\user\Desktop\norm01_upx.exe"
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

Memdumps

Base Address
Regiontype
Protect
Malicious
7FF7D443B000
unkown
page read and write
1C8C4DC0000
heap
page read and write
288C9FD000
stack
page read and write
7FF7D4420000
unkown
page readonly
1C8C4E10000
heap
page read and write
7FF7D443B000
unkown
page write copy
288CBFE000
stack
page read and write
1C8C4E1B000
heap
page read and write
7FF7D4435000
unkown
page execute and write copy
1C8C4E16000
heap
page read and write
1C8C4DD0000
heap
page read and write
7FF7D4420000
unkown
page readonly
7FF7D4435000
unkown
page execute and write copy
There are 3 hidden memdumps, click here to show them.