Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\Aura.exe
|
"C:\Users\user\Desktop\Aura.exe"
|
||
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
2C2C000
|
direct allocation
|
page read and write
|
||
2BC5000
|
heap
|
page read and write
|
||
841000
|
unkown
|
page write copy
|
||
30D0000
|
direct allocation
|
page execute read
|
||
D5C000
|
stack
|
page read and write
|
||
2BC0000
|
heap
|
page read and write
|
||
111F000
|
stack
|
page read and write
|
||
F4B000
|
heap
|
page read and write
|
||
F63000
|
heap
|
page read and write
|
||
F5F000
|
heap
|
page read and write
|
||
2C1D000
|
direct allocation
|
page readonly
|
||
F20000
|
heap
|
page read and write
|
||
F60000
|
heap
|
page read and write
|
||
85A000
|
unkown
|
page write copy
|
||
841000
|
unkown
|
page write copy
|
||
858000
|
unkown
|
page read and write
|
||
DC0000
|
heap
|
page read and write
|
||
51000
|
unkown
|
page execute read
|
||
F60000
|
heap
|
page read and write
|
||
84B000
|
unkown
|
page read and write
|
||
50000
|
unkown
|
page readonly
|
||
679000
|
unkown
|
page readonly
|
||
2C2E000
|
direct allocation
|
page readonly
|
||
2A20000
|
heap
|
page read and write
|
||
F5F000
|
heap
|
page read and write
|
||
84C000
|
unkown
|
page write copy
|
||
8AA000
|
unkown
|
page readonly
|
||
9D62000
|
direct allocation
|
page execute read
|
||
9EE0000
|
trusted library allocation
|
page read and write
|
||
2B90000
|
heap
|
page read and write
|
||
2BB4000
|
heap
|
page read and write
|
||
325B000
|
heap
|
page read and write
|
||
DD0000
|
heap
|
page read and write
|
||
F5C000
|
heap
|
page read and write
|
||
8AA000
|
unkown
|
page readonly
|
||
2BD0000
|
direct allocation
|
page readonly
|
||
51000
|
unkown
|
page execute read
|
||
4BDD000
|
direct allocation
|
page read and write
|
||
E1E000
|
stack
|
page read and write
|
||
51000
|
unkown
|
page execute read
|
||
2BD1000
|
direct allocation
|
page execute read
|
||
84A000
|
unkown
|
page write copy
|
||
8A7000
|
unkown
|
page read and write
|
||
2D7E000
|
stack
|
page read and write
|
||
2B80000
|
heap
|
page read and write
|
||
F2E000
|
heap
|
page read and write
|
||
FC3000
|
heap
|
page read and write
|
||
679000
|
unkown
|
page readonly
|
||
2C7B000
|
stack
|
page read and write
|
||
2BB0000
|
heap
|
page read and write
|
||
F2A000
|
heap
|
page read and write
|
||
849000
|
unkown
|
page read and write
|
||
2BC9000
|
heap
|
page read and write
|
||
E40000
|
heap
|
page read and write
|
||
50000
|
unkown
|
page readonly
|
||
C5C000
|
stack
|
page read and write
|
There are 46 hidden memdumps, click here to show them.