IOC Report
antiunpack_norm01_upx.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\antiunpack_norm01_upx.exe
"C:\Users\user\Desktop\antiunpack_norm01_upx.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

Domains

Name
IP
Malicious
171.39.242.20.in-addr.arpa
unknown

Memdumps

Base Address
Regiontype
Protect
Malicious
1E6FCA40000
heap
page read and write
50DD3FD000
stack
page read and write
7FF7C69A5000
unkown
page execute and write copy
1E6FCBB6000
heap
page read and write
1E6FCBBC000
heap
page read and write
7FF7C69A5000
unkown
page execute and write copy
1E6FCB20000
heap
page read and write
7FF7C69AB000
unkown
page write copy
50DD5FE000
stack
page read and write
1E6FCBB0000
heap
page read and write
7FF7C6990000
unkown
page readonly
7FF7C69AB000
unkown
page read and write
7FF7C6990000
unkown
page readonly
There are 3 hidden memdumps, click here to show them.