Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Windows\System32\notepad.exe
|
"C:\Windows\system32\NOTEPAD.EXE" C:\Users\user\Desktop\checksums.txt
|
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
18.31.95.13.in-addr.arpa
|
unknown
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
1CDD80C0000
|
heap
|
page read and write
|
||
1CDD99A0000
|
heap
|
page read and write
|
||
1CDD8100000
|
heap
|
page read and write
|
||
1CDD9A20000
|
heap
|
page read and write
|
||
1CDD813C000
|
heap
|
page read and write
|
||
1CDD99C5000
|
heap
|
page read and write
|
||
1CDD9EF0000
|
heap
|
page read and write
|
||
B5A1A78000
|
stack
|
page read and write
|
||
1CDDB790000
|
trusted library allocation
|
page read and write
|
||
1CDD9A23000
|
heap
|
page read and write
|
||
B5A1BFD000
|
stack
|
page read and write
|
||
1CDD99CC000
|
heap
|
page read and write
|
||
1CDD817D000
|
heap
|
page read and write
|
||
1CDD8108000
|
heap
|
page read and write
|
||
1CDDA1C0000
|
heap
|
page read and write
|
||
1CDD9DE0000
|
trusted library allocation
|
page read and write
|
||
1CDD99C0000
|
heap
|
page read and write
|
||
1CDD8132000
|
heap
|
page read and write
|
||
1CDD8110000
|
heap
|
page read and write
|
||
B5A1CFF000
|
stack
|
page read and write
|
||
1CDD7FE0000
|
heap
|
page read and write
|
There are 11 hidden memdumps, click here to show them.