Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
PO#001498.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
initial sample
|
||
C:\Users\user\AppData\Local\Temp\autF61A.tmp
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\miaoued
|
data
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\PO#001498.exe
|
"C:\Users\user\Desktop\PO#001498.exe"
|
||
C:\Windows\SysWOW64\svchost.exe
|
"C:\Users\user\Desktop\PO#001498.exe"
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
400000
|
system
|
page execute and read and write
|
||
2F60000
|
direct allocation
|
page read and write
|
||
3F39000
|
direct allocation
|
page read and write
|
||
1629000
|
heap
|
page read and write
|
||
2813000
|
heap
|
page read and write
|
||
15BE000
|
heap
|
page read and write
|
||
1609000
|
heap
|
page read and write
|
||
14A0000
|
direct allocation
|
page read and write
|
||
102A000
|
unkown
|
page write copy
|
||
101E000
|
unkown
|
page readonly
|
||
3F3D000
|
direct allocation
|
page read and write
|
||
102A000
|
unkown
|
page read and write
|
||
2813000
|
heap
|
page read and write
|
||
2FB0000
|
direct allocation
|
page read and write
|
||
2813000
|
heap
|
page read and write
|
||
3F3D000
|
direct allocation
|
page read and write
|
||
2813000
|
heap
|
page read and write
|
||
FFD000
|
unkown
|
page readonly
|
||
F70000
|
unkown
|
page readonly
|
||
2813000
|
heap
|
page read and write
|
||
3FAE000
|
direct allocation
|
page read and write
|
||
3F39000
|
direct allocation
|
page read and write
|
||
2813000
|
heap
|
page read and write
|
||
2813000
|
heap
|
page read and write
|
||
15C1000
|
heap
|
page read and write
|
||
1726000
|
heap
|
page read and write
|
||
3601000
|
heap
|
page read and write
|
||
155A000
|
heap
|
page read and write
|
||
3FAE000
|
direct allocation
|
page read and write
|
||
3229000
|
direct allocation
|
page execute and read and write
|
||
3FAE000
|
direct allocation
|
page read and write
|
||
F71000
|
unkown
|
page execute read
|
||
3E10000
|
direct allocation
|
page read and write
|
||
309E000
|
heap
|
page read and write
|
||
155A000
|
heap
|
page read and write
|
||
2F5F000
|
stack
|
page read and write
|
||
9CE000
|
stack
|
page read and write
|
||
3E10000
|
direct allocation
|
page read and write
|
||
3E10000
|
direct allocation
|
page read and write
|
||
3F39000
|
direct allocation
|
page read and write
|
||
146E000
|
stack
|
page read and write
|
||
2802000
|
heap
|
page read and write
|
||
3AC0000
|
heap
|
page read and write
|
||
2813000
|
heap
|
page read and write
|
||
322D000
|
direct allocation
|
page execute and read and write
|
||
16C3000
|
heap
|
page read and write
|
||
3AC4000
|
heap
|
page read and write
|
||
2D5E000
|
stack
|
page read and write
|
||
F70000
|
unkown
|
page readonly
|
||
25A0000
|
heap
|
page read and write
|
||
2813000
|
heap
|
page read and write
|
||
2813000
|
heap
|
page read and write
|
||
3F3D000
|
direct allocation
|
page read and write
|
||
154C000
|
heap
|
page read and write
|
||
98E000
|
stack
|
page read and write
|
||
154E000
|
heap
|
page read and write
|
||
3F39000
|
direct allocation
|
page read and write
|
||
1519000
|
heap
|
page read and write
|
||
3F39000
|
direct allocation
|
page read and write
|
||
3F39000
|
direct allocation
|
page read and write
|
||
8CA000
|
stack
|
page read and write
|
||
1723000
|
heap
|
page read and write
|
||
2CD0000
|
heap
|
page read and write
|
||
3029000
|
heap
|
page read and write
|
||
3A13000
|
direct allocation
|
page read and write
|
||
2813000
|
heap
|
page read and write
|
||
2E5F000
|
stack
|
page read and write
|
||
252D000
|
stack
|
page read and write
|
||
2813000
|
heap
|
page read and write
|
||
33CD000
|
direct allocation
|
page execute and read and write
|
||
1723000
|
heap
|
page read and write
|
||
2813000
|
heap
|
page read and write
|
||
147B000
|
stack
|
page read and write
|
||
2F00000
|
heap
|
page read and write
|
||
2A05000
|
heap
|
page read and write
|
||
3A13000
|
direct allocation
|
page read and write
|
||
3A13000
|
direct allocation
|
page read and write
|
||
2A05000
|
heap
|
page read and write
|
||
1723000
|
heap
|
page read and write
|
||
3F3D000
|
direct allocation
|
page read and write
|
||
3442000
|
direct allocation
|
page execute and read and write
|
||
2813000
|
heap
|
page read and write
|
||
3E10000
|
direct allocation
|
page read and write
|
||
2FB0000
|
direct allocation
|
page read and write
|
||
2813000
|
heap
|
page read and write
|
||
2813000
|
heap
|
page read and write
|
||
38F0000
|
direct allocation
|
page read and write
|
||
2813000
|
heap
|
page read and write
|
||
940000
|
heap
|
page read and write
|
||
3FAE000
|
direct allocation
|
page read and write
|
||
2FB0000
|
direct allocation
|
page read and write
|
||
2800000
|
heap
|
page read and write
|
||
DC0000
|
heap
|
page read and write
|
||
155A000
|
heap
|
page read and write
|
||
3E10000
|
direct allocation
|
page read and write
|
||
2B01000
|
heap
|
page read and write
|
||
2A12000
|
heap
|
page read and write
|
||
25C0000
|
heap
|
page read and write
|
||
302D000
|
heap
|
page read and write
|
||
1726000
|
heap
|
page read and write
|
||
2813000
|
heap
|
page read and write
|
||
101E000
|
unkown
|
page readonly
|
||
2813000
|
heap
|
page read and write
|
||
1034000
|
unkown
|
page readonly
|
||
2D00000
|
heap
|
page read and write
|
||
210F000
|
stack
|
page read and write
|
||
145B000
|
stack
|
page read and write
|
||
1722000
|
heap
|
page execute and read and write
|
||
2813000
|
heap
|
page read and write
|
||
2FB0000
|
direct allocation
|
page read and write
|
||
2A17000
|
heap
|
page read and write
|
||
2FB0000
|
direct allocation
|
page read and write
|
||
2813000
|
heap
|
page read and write
|
||
2813000
|
heap
|
page read and write
|
||
15A3000
|
heap
|
page read and write
|
||
329E000
|
direct allocation
|
page execute and read and write
|
||
22D0000
|
heap
|
page read and write
|
||
151E000
|
heap
|
page read and write
|
||
1609000
|
heap
|
page read and write
|
||
25F0000
|
heap
|
page read and write
|
||
2813000
|
heap
|
page read and write
|
||
38F0000
|
direct allocation
|
page read and write
|
||
2813000
|
heap
|
page read and write
|
||
160A000
|
heap
|
page read and write
|
||
930000
|
heap
|
page read and write
|
||
2E23000
|
heap
|
page read and write
|
||
1D0E000
|
stack
|
page read and write
|
||
F71000
|
unkown
|
page execute read
|
||
256C000
|
stack
|
page read and write
|
||
FFD000
|
unkown
|
page readonly
|
||
2FB0000
|
direct allocation
|
page read and write
|
||
3F3D000
|
direct allocation
|
page read and write
|
||
3E10000
|
direct allocation
|
page read and write
|
||
2A17000
|
heap
|
page read and write
|
||
38F0000
|
direct allocation
|
page read and write
|
||
3F3D000
|
direct allocation
|
page read and write
|
||
3A13000
|
direct allocation
|
page read and write
|
||
102F000
|
unkown
|
page write copy
|
||
2813000
|
heap
|
page read and write
|
||
2813000
|
heap
|
page read and write
|
||
1510000
|
heap
|
page read and write
|
||
3100000
|
direct allocation
|
page execute and read and write
|
||
149C000
|
stack
|
page read and write
|
||
3FAE000
|
direct allocation
|
page read and write
|
||
3A13000
|
direct allocation
|
page read and write
|
||
155A000
|
heap
|
page read and write
|
||
2813000
|
heap
|
page read and write
|
||
2A00000
|
heap
|
page read and write
|
||
33D1000
|
direct allocation
|
page execute and read and write
|
||
2CE0000
|
direct allocation
|
page read and write
|
||
38F0000
|
direct allocation
|
page read and write
|
||
1559000
|
heap
|
page read and write
|
||
38F0000
|
direct allocation
|
page read and write
|
||
D80000
|
heap
|
page read and write
|
||
2D1E000
|
stack
|
page read and write
|
||
1034000
|
unkown
|
page readonly
|
||
3FAE000
|
direct allocation
|
page read and write
|
||
2813000
|
heap
|
page read and write
|
||
3A13000
|
direct allocation
|
page read and write
|
||
38F0000
|
direct allocation
|
page read and write
|
There are 150 hidden memdumps, click here to show them.