Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Windows\System32\mmc.exe
|
"C:\Windows\system32\mmc.exe" "C:\Users\user\Desktop\DNSCCB.msc"
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
HKEY_CURRENT_USER_Classes\Local Settings\MuiCache\1e\417C44EB
|
@filemgmt.dll,-3503
|
||
HKEY_CURRENT_USER_Classes\Local Settings\MuiCache\1e\417C44EB
|
@mmcbase.dll,-14008
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
3460000
|
heap
|
page read and write
|
||
3486000
|
heap
|
page read and write
|
||
5454000
|
heap
|
page read and write
|
||
34A0000
|
heap
|
page read and write
|
||
34E6000
|
heap
|
page read and write
|
||
128B000
|
heap
|
page read and write
|
||
1230000
|
heap
|
page read and write
|
||
3330000
|
heap
|
page read and write
|
||
526E000
|
stack
|
page read and write
|
||
34B0000
|
heap
|
page read and write
|
||
34AE000
|
heap
|
page read and write
|
||
1260000
|
heap
|
page read and write
|
||
374C000
|
heap
|
page read and write
|
||
349B000
|
heap
|
page read and write
|
||
32FE000
|
stack
|
page read and write
|
||
FE5000
|
stack
|
page read and write
|
||
349B000
|
heap
|
page read and write
|
||
3440000
|
heap
|
page read and write
|
||
53F0000
|
heap
|
page read and write
|
||
34AA000
|
heap
|
page read and write
|
||
1615000
|
heap
|
page read and write
|
||
34A5000
|
heap
|
page read and write
|
||
1280000
|
heap
|
page read and write
|
||
3580000
|
heap
|
page read and write
|
||
347C000
|
heap
|
page read and write
|
||
3540000
|
heap
|
page read and write
|
||
5270000
|
trusted library allocation
|
page read and write
|
||
3700000
|
heap
|
page read and write
|
||
346F000
|
heap
|
page read and write
|
||
3485000
|
heap
|
page read and write
|
||
3542000
|
heap
|
page read and write
|
||
345D000
|
heap
|
page read and write
|
||
376A000
|
heap
|
page read and write
|
||
34A5000
|
heap
|
page read and write
|
||
3486000
|
heap
|
page read and write
|
||
3433000
|
heap
|
page read and write
|
||
34D4000
|
heap
|
page read and write
|
||
5270000
|
trusted library allocation
|
page read and write
|
||
34E4000
|
heap
|
page read and write
|
||
1240000
|
heap
|
page read and write
|
||
34A5000
|
heap
|
page read and write
|
||
12C0000
|
heap
|
page read and write
|
||
5400000
|
heap
|
page read and write
|
||
3220000
|
trusted library allocation
|
page read and write
|
||
3585000
|
heap
|
page read and write
|
||
3760000
|
heap
|
page read and write
|
||
34C9000
|
heap
|
page read and write
|
||
5434000
|
heap
|
page read and write
|
||
34C9000
|
heap
|
page read and write
|
||
354A000
|
heap
|
page read and write
|
||
51EE000
|
stack
|
page read and write
|
||
3760000
|
heap
|
page read and write
|
||
36F0000
|
heap
|
page read and write
|
||
348A000
|
heap
|
page read and write
|
||
3485000
|
heap
|
page read and write
|
||
36D0000
|
heap
|
page read and write
|
||
34C9000
|
heap
|
page read and write
|
||
346A000
|
heap
|
page read and write
|
||
3751000
|
heap
|
page read and write
|
||
34E6000
|
heap
|
page read and write
|
||
3370000
|
heap
|
page read and write
|
||
34C9000
|
heap
|
page read and write
|
||
3749000
|
heap
|
page read and write
|
||
345D000
|
heap
|
page read and write
|
||
53D0000
|
heap
|
page read and write
|
||
349B000
|
heap
|
page read and write
|
||
12A7000
|
heap
|
page read and write
|
||
12E1000
|
heap
|
page read and write
|
||
34AE000
|
heap
|
page read and write
|
||
5440000
|
heap
|
page read and write
|
||
1610000
|
heap
|
page read and write
|
||
5520000
|
trusted library allocation
|
page read and write
|
||
346F000
|
heap
|
page read and write
|
||
3484000
|
heap
|
page read and write
|
||
34BD000
|
heap
|
page read and write
|
||
3499000
|
heap
|
page read and write
|
||
3463000
|
heap
|
page read and write
|
||
12BB000
|
heap
|
page read and write
|
||
3430000
|
heap
|
page read and write
|
||
3485000
|
heap
|
page read and write
|
||
5280000
|
trusted library allocation
|
page read and write
|
There are 71 hidden memdumps, click here to show them.