IOC Report
plushvcioffattkingstore17774t85.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\plushvcioffattkingstore17774t85.exe
"C:\Users\user\Desktop\plushvcioffattkingstore17774t85.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

URLs

Name
IP
Malicious
https://github.com/googlefonts/lexend)6_ju
unknown
https://scripts.sil.org/OFLThis
unknown
https://scripts.sil.org/OFLhttps://www.lexend.comBonnie
unknown
https://curl.haxx.se/docs/http-cookies.html
unknown

Memdumps

Base Address
Regiontype
Protect
Malicious
204E58BC000
heap
page read and write
204E58B0000
heap
page read and write
7FF60F14D000
unkown
page write copy
204E5820000
heap
page read and write
7FF60F3DB000
unkown
page read and write
EF0D35C000
stack
page read and write
7FF60EFE1000
unkown
page execute read
7FF60EFE1000
unkown
page execute read
7FF60F3DD000
unkown
page readonly
7FF60F102000
unkown
page readonly
7FF60F101000
unkown
page readonly
7FF60F3DD000
unkown
page readonly
7FF60F101000
unkown
page read and write
204E5740000
heap
page read and write
7FF60F14E000
unkown
page write copy
7FF60F14D000
unkown
page read and write
7FF60EFE0000
unkown
page readonly
EF0D6FE000
stack
page read and write
7FF60EFE0000
unkown
page readonly
There are 9 hidden memdumps, click here to show them.