Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\LisectAVT_2403002A_262.exe
|
"C:\Users\user\Desktop\LisectAVT_2403002A_262.exe"
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
https://ipinfo.io/https://www.maxmind.com/en/locate-my-ip-addressWs2_32.dll
|
unknown
|
||
http://www.winimage.com/zLibDll
|
unknown
|
||
https://t.me/RiseProSUPPORT
|
unknown
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
193.233.132.190
|
unknown
|
Russian Federation
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
2FD0000
|
heap
|
page read and write
|
||
502000
|
unkown
|
page execute read
|
||
3BD000
|
unkown
|
page readonly
|
||
2FE2000
|
heap
|
page read and write
|
||
10FC000
|
stack
|
page read and write
|
||
2B0000
|
unkown
|
page readonly
|
||
14DF000
|
heap
|
page read and write
|
||
14CB000
|
heap
|
page read and write
|
||
7D1000
|
unkown
|
page readonly
|
||
14A0000
|
heap
|
page read and write
|
||
DCC000
|
stack
|
page read and write
|
||
14AA000
|
heap
|
page read and write
|
||
502000
|
unkown
|
page execute read
|
||
1210000
|
heap
|
page read and write
|
||
3E6000
|
unkown
|
page execute read
|
||
7D1000
|
unkown
|
page readonly
|
||
14D3000
|
heap
|
page read and write
|
||
501000
|
unkown
|
page read and write
|
||
1130000
|
heap
|
page read and write
|
||
12E0000
|
heap
|
page read and write
|
||
2B1000
|
unkown
|
page execute read
|
||
2B0000
|
unkown
|
page readonly
|
||
14AE000
|
heap
|
page read and write
|
||
14DF000
|
heap
|
page read and write
|
||
14D7000
|
heap
|
page read and write
|
||
3E1000
|
unkown
|
page read and write
|
||
2F3E000
|
stack
|
page read and write
|
||
142D000
|
stack
|
page read and write
|
There are 18 hidden memdumps, click here to show them.