Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\LisectAVT_2403002A_240.exe
|
"C:\Users\user\Desktop\LisectAVT_2403002A_240.exe"
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
https://ipinfo.io/https://www.maxmind.com/en/locate-my-ip-addressWs2_32.dll
|
unknown
|
||
http://www.winimage.com/zLibDll
|
unknown
|
||
https://t.me/RiseProSUPPORT
|
unknown
|
||
http://www.altools.co.kr
|
unknown
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
5.42.65.117
|
unknown
|
Russian Federation
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
148F000
|
heap
|
page read and write
|
||
13D4000
|
heap
|
page read and write
|
||
13D0000
|
heap
|
page read and write
|
||
13D4000
|
heap
|
page read and write
|
||
145A000
|
heap
|
page read and write
|
||
324D000
|
heap
|
page read and write
|
||
13D4000
|
heap
|
page read and write
|
||
1483000
|
heap
|
page read and write
|
||
13D4000
|
heap
|
page read and write
|
||
620000
|
unkown
|
page readonly
|
||
1450000
|
heap
|
page read and write
|
||
F2B000
|
unkown
|
page readonly
|
||
12FC000
|
stack
|
page read and write
|
||
13D4000
|
heap
|
page read and write
|
||
13F0000
|
trusted library allocation
|
page read and write
|
||
13D4000
|
heap
|
page read and write
|
||
148F000
|
heap
|
page read and write
|
||
3090000
|
heap
|
page read and write
|
||
145E000
|
heap
|
page read and write
|
||
13D4000
|
heap
|
page read and write
|
||
72D000
|
unkown
|
page readonly
|
||
13D4000
|
heap
|
page read and write
|
||
143D000
|
stack
|
page read and write
|
||
30A1000
|
heap
|
page read and write
|
||
77B000
|
unkown
|
page read and write
|
||
1340000
|
heap
|
page read and write
|
||
1330000
|
heap
|
page read and write
|
||
74E000
|
unkown
|
page read and write
|
||
1487000
|
heap
|
page read and write
|
||
620000
|
unkown
|
page readonly
|
||
30A0000
|
heap
|
page read and write
|
||
A08000
|
unkown
|
page execute read
|
||
A07000
|
unkown
|
page read and write
|
||
30A1000
|
heap
|
page read and write
|
||
FCC000
|
stack
|
page read and write
|
||
3230000
|
heap
|
page read and write
|
||
A08000
|
unkown
|
page execute read
|
||
147B000
|
heap
|
page read and write
|
||
621000
|
unkown
|
page execute read
|
||
F2B000
|
unkown
|
page readonly
|
||
353E000
|
stack
|
page read and write
|
||
781000
|
unkown
|
page execute read
|
||
753000
|
unkown
|
page execute read
|
There are 33 hidden memdumps, click here to show them.