Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
2hp5ee36OS.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
initial sample
|
||
C:\Program Files\Common Files\System\symsrv.dll
|
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows, UPX compressed
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\2hp5ee36OS.exe
|
"C:\Users\user\Desktop\2hp5ee36OS.exe"
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://5isohu.com/
|
unknown
|
||
http://5isohu.com/Z
|
unknown
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
680000
|
heap
|
page read and write
|
||
6A0000
|
direct allocation
|
page execute and read and write
|
||
10000000
|
unkown
|
page readonly
|
||
8BF000
|
stack
|
page read and write
|
||
6C0000
|
heap
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
2161000
|
heap
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
228E000
|
stack
|
page read and write
|
||
610000
|
heap
|
page read and write
|
||
684000
|
heap
|
page read and write
|
||
6CE000
|
heap
|
page read and write
|
||
9B000
|
stack
|
page read and write
|
||
19D000
|
stack
|
page read and write
|
||
486000
|
unkown
|
page read and write
|
||
22A0000
|
heap
|
page read and write
|
||
4A0000
|
heap
|
page read and write
|
||
224C000
|
stack
|
page read and write
|
||
5CE000
|
stack
|
page read and write
|
||
1002F000
|
unkown
|
page read and write
|
||
1002D000
|
unkown
|
page execute and write copy
|
||
690000
|
heap
|
page read and write
|
||
24AF000
|
stack
|
page read and write
|
||
406000
|
unkown
|
page execute and read and write
|
||
1002B000
|
unkown
|
page execute and read and write
|
||
10025000
|
unkown
|
page execute and read and write
|
||
10001000
|
unkown
|
page execute and read and write
|
||
9BF000
|
stack
|
page read and write
|
||
580000
|
heap
|
page read and write
|
||
28F0000
|
direct allocation
|
page read and write
|
||
483000
|
unkown
|
page execute and read and write
|
||
488000
|
unkown
|
page read and write
|
||
630000
|
heap
|
page read and write
|
||
60E000
|
stack
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
48D000
|
unkown
|
page readonly
|
||
10020000
|
unkown
|
page execute and read and write
|
||
1001E000
|
unkown
|
page execute and read and write
|
||
23AE000
|
stack
|
page read and write
|
||
2B53000
|
heap
|
page read and write
|
||
2B50000
|
heap
|
page read and write
|
||
27F0000
|
heap
|
page read and write
|
||
6CA000
|
heap
|
page read and write
|
||
484000
|
unkown
|
page write copy
|
||
488000
|
unkown
|
page write copy
|
There are 35 hidden memdumps, click here to show them.