Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
SecuriteInfo.com.Win32.MalwareX-gen.16263.14680.dll
|
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
|
initial sample
|
||
C:\Windows\Prairie Wind.bmp.bak
|
ASCII text, with no line terminators
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Windows\System32\loaddll32.exe
|
loaddll32.exe "C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.16263.14680.dll"
|
||
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
||
C:\Windows\SysWOW64\cmd.exe
|
cmd.exe /C rundll32.exe "C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.16263.14680.dll",#1
|
||
C:\Windows\SysWOW64\rundll32.exe
|
rundll32.exe "C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.16263.14680.dll",#1
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://ds1.mentality-us.com/ld/HiQueen/v1/down.bmp
|
unknown
|
||
http://ds1.mentality-us.com/ld/HiQueen/v1/index.
|
unknown
|
||
http://ds1.mentality-us.com/ld/HiQueen/v1/index.jpg
|
unknown
|
||
http://ds1.mentality-us.com/ld/HiQueen/v1/getnews.php?s=
|
unknown
|
||
http://ds1.mentality-us.com/ld/HiQueen/v1/index.jpgficmanager.nety
|
unknown
|
||
http://ds1.mentality-us.com/ld/HiQueen/v1/index.jpgrX
|
unknown
|
||
http://ds1.mentality-us.com/ld/HiQueen/v1/news.jpg
|
unknown
|
||
http://www.rsac.org/ratingsv01.html
|
unknown
|
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
ds1.mentality-us.com
|
unknown
|
||
time.windows.com
|
unknown
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
2DD0000
|
heap
|
page read and write
|
||
2D88000
|
heap
|
page read and write
|
||
2CAE000
|
stack
|
page read and write
|
||
476C000
|
stack
|
page read and write
|
||
2C6D000
|
stack
|
page read and write
|
||
2AB0000
|
heap
|
page read and write
|
||
58E000
|
stack
|
page read and write
|
||
6444000
|
heap
|
page read and write
|
||
2F87000
|
heap
|
page read and write
|
||
22FE000
|
stack
|
page read and write
|
||
2D8B000
|
heap
|
page read and write
|
||
2DD0000
|
heap
|
page read and write
|
||
6430000
|
heap
|
page read and write
|
||
1EC000
|
stack
|
page read and write
|
||
2E50000
|
direct allocation
|
page read and write
|
||
287F000
|
stack
|
page read and write
|
||
2B50000
|
heap
|
page read and write
|
||
2170000
|
heap
|
page read and write
|
||
2DA3000
|
heap
|
page read and write
|
||
2D10000
|
heap
|
page read and write
|
||
2D50000
|
heap
|
page read and write
|
||
638B000
|
stack
|
page read and write
|
||
2F8C000
|
heap
|
page read and write
|
||
7E9000
|
stack
|
page read and write
|
||
2A7C000
|
stack
|
page read and write
|
||
2B3E000
|
stack
|
page read and write
|
||
2B56000
|
heap
|
page read and write
|
||
540000
|
heap
|
page read and write
|
||
63CD000
|
stack
|
page read and write
|
||
5C0000
|
heap
|
page read and write
|
||
9C000
|
stack
|
page read and write
|
||
47EE000
|
stack
|
page read and write
|
||
243C000
|
stack
|
page read and write
|
||
482F000
|
stack
|
page read and write
|
||
657E000
|
stack
|
page read and write
|
||
5EF000
|
heap
|
page read and write
|
||
2D5A000
|
heap
|
page read and write
|
||
6420000
|
heap
|
page read and write
|
||
2D8E000
|
heap
|
page read and write
|
||
4860000
|
heap
|
page read and write
|
||
545000
|
heap
|
page read and write
|
||
2F80000
|
heap
|
page read and write
|
||
2DA3000
|
heap
|
page read and write
|
||
210C000
|
stack
|
page read and write
|
||
47AC000
|
stack
|
page read and write
|
||
2D8E000
|
heap
|
page read and write
|
||
7BE000
|
stack
|
page read and write
|
||
5D7000
|
heap
|
page read and write
|
||
8FF000
|
stack
|
page read and write
|
||
2CEF000
|
stack
|
page read and write
|
||
2D8E000
|
heap
|
page read and write
|
||
5CB000
|
heap
|
page read and write
|
||
2330000
|
heap
|
page read and write
|
||
2D79000
|
heap
|
page read and write
|
||
22BE000
|
stack
|
page read and write
|
||
430000
|
heap
|
page read and write
|
||
2AC0000
|
heap
|
page read and write
|
||
4960000
|
heap
|
page read and write
|
||
7FE000
|
stack
|
page read and write
|
||
2180000
|
direct allocation
|
page read and write
|
||
48FD000
|
stack
|
page read and write
|
||
5CF000
|
heap
|
page read and write
|
||
2D91000
|
heap
|
page read and write
|
||
2ABF000
|
stack
|
page read and write
|
||
65BF000
|
stack
|
page read and write
|
||
297F000
|
stack
|
page read and write
|
||
2D78000
|
heap
|
page read and write
|
||
29BE000
|
stack
|
page read and write
|
||
634D000
|
stack
|
page read and write
|
||
6690000
|
trusted library allocation
|
page read and write
|
||
48BE000
|
stack
|
page read and write
|
||
510000
|
heap
|
page read and write
|
||
640E000
|
stack
|
page read and write
|
||
2D84000
|
heap
|
page read and write
|
||
20B0000
|
heap
|
page read and write
|
||
6440000
|
heap
|
page read and write
|
There are 66 hidden memdumps, click here to show them.