IOC Report
prevhost.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\prevhost.exe
"C:\Users\user\Desktop\prevhost.exe"

Memdumps

Base Address
Regiontype
Protect
Malicious
3F00000
heap
page read and write
480000
heap
page read and write
A90000
heap
page read and write
AD7000
unkown
page readonly
1F0000
heap
page read and write
AD1000
unkown
page execute read
AD0000
unkown
page readonly
18C000
stack
page read and write
580000
heap
page read and write
14B000
stack
page read and write
588000
heap
page read and write
47F000
stack
page read and write
AD1000
unkown
page execute read
AD7000
unkown
page readonly
6BE000
stack
page read and write
AD0000
unkown
page readonly
490000
heap
page read and write
43E000
stack
page read and write
6FF000
stack
page read and write
There are 9 hidden memdumps, click here to show them.