logo

Malware Analysis: Memory Forensics with Volatility 3

ID: 9223103a-4e6b-5070-b3a2-b9c0009c623a

STIX ID: report--9223103a-4e6b-5070-b3a2-b9c0009c623a

Feed Name: On the Hunt

Threat Score
70/100

Date Published: 2020-11-10

Date Updated: 2026-04-19

Author: Paul Newton

...
...

This post demonstrates using Volatility 3 to analyze a memory dump from an infected Windows host, finding a malicious Word document (Detalii-123393.doc) that executed an obfuscated PowerShell macro which downloaded/attempted to run an executable (I3d47K.exe) and a suspicious process (fphc.exe) identified as Emotet; network artifacts include Azure addresses and two IPs (62.108.35.36 and 185.99.2.123) linked to TrickBot infrastructure. The author highlights Volatility 3 plugin limitations versus Volatility 2, details process and netscan outputs, and provides indicators and recommended next steps for deeper file extraction and analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.