IOC Report
norm01.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\norm01.exe
"C:\Users\user\Desktop\norm01.exe"
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

Memdumps

Base Address
Regiontype
Protect
Malicious
7FF7E7ED0000
unkown
page readonly
7FF7E7ED7000
unkown
page readonly
7FF7E7ED0000
unkown
page readonly
7FF7E7ED7000
unkown
page readonly
7FF7E7EC1000
unkown
page execute read
7FF7E7ED2000
unkown
page readonly
A7431FD000
stack
page read and write
25A2EC70000
heap
page read and write
7FF7E7EC8000
unkown
page write copy
7FF7E7ECD000
unkown
page read and write
7FF7E7EC0000
unkown
page readonly
7FF7E7ED4000
unkown
page readonly
7FF7E7EC9000
unkown
page readonly
7FF7E7ED2000
unkown
page readonly
7FF7E7ED4000
unkown
page readonly
7FF7E7EC1000
unkown
page execute read
7FF7E7EC9000
unkown
page readonly
A7435FF000
stack
page read and write
25A2EE00000
heap
page read and write
7FF7E7ECD000
unkown
page write copy
7FF7E7EC0000
unkown
page readonly
25A2EE06000
heap
page read and write
7FF7E7EC8000
unkown
page write copy
There are 13 hidden memdumps, click here to show them.