Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\SecuriteInfo.com.Trojan.MulDrop28.21322.11416.10977.exe
|
"C:\Users\user\Desktop\SecuriteInfo.com.Trojan.MulDrop28.21322.11416.10977.exe"
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
119.91.152.151
|
|||
http://114.132.64.209:9652/mstsc.exe
|
114.132.64.209
|
||
http://114.132.64.209/
|
unknown
|
||
http://114.132.64.209:9652/mstsc.exeTx
|
unknown
|
||
http://114.132.64.209:9652/mstsc.exeC:
|
unknown
|
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
bg.microsoft.map.fastly.net
|
199.232.210.172
|
||
fp2e7a.wpc.phicdn.net
|
192.229.221.95
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
119.91.152.151
|
unknown
|
China
|
||
114.132.64.209
|
unknown
|
China
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Rsymwe miusskwq
|
ConnectGroup
|
||
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Rsymwe miusskwq
|
MarkTime
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\ActiveMovie\devenum
|
Version
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
992000
|
unkown
|
page read and write
|
||
10015000
|
direct allocation
|
page readonly
|
||
300E000
|
stack
|
page read and write
|
||
1208000
|
heap
|
page read and write
|
||
349E000
|
direct allocation
|
page read and write
|
||
10000000
|
direct allocation
|
page read and write
|
||
426E000
|
stack
|
page read and write
|
||
9E0000
|
unkown
|
page read and write
|
||
3DDF000
|
stack
|
page read and write
|
||
40DC000
|
stack
|
page read and write
|
||
351B000
|
stack
|
page read and write
|
||
FC0000
|
heap
|
page read and write
|
||
3781000
|
heap
|
page read and write
|
||
92A000
|
unkown
|
page readonly
|
||
308C000
|
stack
|
page read and write
|
||
3780000
|
heap
|
page read and write
|
||
11BE000
|
heap
|
page read and write
|
||
FC6000
|
heap
|
page read and write
|
||
411E000
|
stack
|
page read and write
|
||
9E7000
|
unkown
|
page readonly
|
||
6D0000
|
unkown
|
page readonly
|
||
376F000
|
stack
|
page read and write
|
||
92A000
|
unkown
|
page readonly
|
||
2CA0000
|
heap
|
page read and write
|
||
3FDF000
|
stack
|
page read and write
|
||
117A000
|
heap
|
page read and write
|
||
11E1000
|
heap
|
page read and write
|
||
2EC0000
|
heap
|
page read and write
|
||
F90000
|
heap
|
page read and write
|
||
2D20000
|
heap
|
page read and write
|
||
3EDE000
|
stack
|
page read and write
|
||
10001000
|
direct allocation
|
page execute read
|
||
1214000
|
heap
|
page read and write
|
||
2CE0000
|
heap
|
page read and write
|
||
9D8000
|
unkown
|
page write copy
|
||
421E000
|
stack
|
page read and write
|
||
6D1000
|
unkown
|
page execute read
|
||
9E7000
|
unkown
|
page readonly
|
||
1170000
|
heap
|
page read and write
|
||
11B1000
|
heap
|
page read and write
|
||
3094000
|
heap
|
page read and write
|
||
3090000
|
heap
|
page read and write
|
||
376D000
|
stack
|
page read and write
|
||
117E000
|
heap
|
page read and write
|
||
1150000
|
heap
|
page read and write
|
||
2CE3000
|
heap
|
page read and write
|
||
6D0000
|
unkown
|
page readonly
|
||
1160000
|
heap
|
page read and write
|
||
2CC0000
|
heap
|
page read and write
|
||
F80000
|
heap
|
page read and write
|
||
30A0000
|
direct allocation
|
page read and write
|
||
992000
|
unkown
|
page write copy
|
||
1001B000
|
direct allocation
|
page read and write
|
||
2D27000
|
heap
|
page read and write
|
||
F39000
|
stack
|
page read and write
|
||
FC7000
|
heap
|
page read and write
|
||
3620000
|
heap
|
page read and write
|
||
366C000
|
stack
|
page read and write
|
||
10020000
|
direct allocation
|
page readonly
|
||
361B000
|
stack
|
page read and write
|
||
436F000
|
stack
|
page read and write
|
||
E3B000
|
stack
|
page read and write
|
||
2E9E000
|
stack
|
page read and write
|
||
9D8000
|
unkown
|
page read and write
|
||
11F5000
|
heap
|
page read and write
|
||
3097000
|
heap
|
page read and write
|
||
304E000
|
stack
|
page read and write
|
||
6D1000
|
unkown
|
page execute read
|
||
3880000
|
trusted library allocation
|
page read and write
|
||
10021000
|
direct allocation
|
page read and write
|
There are 60 hidden memdumps, click here to show them.