Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
R2T8ccXCek.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
initial sample
|
||
C:\Users\user\AppData\Roaming\ConsolHQ LTD\ConsoleHQ 1.12.3\install\decoder.dll
|
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\R2T8ccXCek.exe
|
"C:\Users\user\Desktop\R2T8ccXCek.exe"
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
2D2E000
|
stack
|
page read and write
|
||
9F1000
|
unkown
|
page execute read
|
||
605000
|
heap
|
page read and write
|
||
26A0000
|
heap
|
page read and write
|
||
9C0000
|
heap
|
page read and write
|
||
271E000
|
stack
|
page read and write
|
||
CB6000
|
unkown
|
page readonly
|
||
727000
|
heap
|
page read and write
|
||
704000
|
heap
|
page read and write
|
||
281E000
|
stack
|
page read and write
|
||
DFE000
|
stack
|
page read and write
|
||
9F0000
|
unkown
|
page readonly
|
||
2FB0000
|
trusted library allocation
|
page read and write
|
||
C8E000
|
unkown
|
page read and write
|
||
439000
|
stack
|
page read and write
|
||
6A0000
|
heap
|
page read and write
|
||
70F000
|
heap
|
page read and write
|
||
6B4000
|
heap
|
page read and write
|
||
2840000
|
heap
|
page read and write
|
||
9F0000
|
unkown
|
page readonly
|
||
C08000
|
unkown
|
page readonly
|
||
6CC000
|
heap
|
page read and write
|
||
2CEF000
|
stack
|
page read and write
|
||
26D5000
|
heap
|
page read and write
|
||
70A000
|
heap
|
page read and write
|
||
2F20000
|
heap
|
page read and write
|
||
600000
|
heap
|
page read and write
|
||
580000
|
heap
|
page read and write
|
||
38FF000
|
stack
|
page read and write
|
||
704000
|
heap
|
page read and write
|
||
6EC000
|
heap
|
page read and write
|
||
26DB000
|
heap
|
page read and write
|
||
26D0000
|
heap
|
page read and write
|
||
6EC000
|
heap
|
page read and write
|
||
96F000
|
stack
|
page read and write
|
||
6AA000
|
heap
|
page read and write
|
||
5CE000
|
stack
|
page read and write
|
||
64E000
|
stack
|
page read and write
|
||
53B000
|
stack
|
page read and write
|
||
670000
|
heap
|
page read and write
|
||
C97000
|
unkown
|
page readonly
|
||
2844000
|
heap
|
page read and write
|
||
C97000
|
unkown
|
page readonly
|
||
727000
|
heap
|
page read and write
|
||
C93000
|
unkown
|
page write copy
|
||
C94000
|
unkown
|
page read and write
|
||
C92000
|
unkown
|
page write copy
|
||
C08000
|
unkown
|
page readonly
|
||
C8E000
|
unkown
|
page write copy
|
||
37FE000
|
stack
|
page read and write
|
||
570000
|
heap
|
page read and write
|
||
CB6000
|
unkown
|
page readonly
|
||
6B3000
|
heap
|
page read and write
|
||
9F1000
|
unkown
|
page execute read
|
||
2BEE000
|
stack
|
page read and write
|
||
6CF000
|
heap
|
page read and write
|
||
2E2F000
|
stack
|
page read and write
|
||
690000
|
heap
|
page read and write
|
There are 48 hidden memdumps, click here to show them.