Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
SecuriteInfo.com.FileRepMalware.7704.21109.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
initial sample
|
||
C:\Users\user\AppData\Local\windows update\svchost.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\windows update\config
|
data
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exe
|
"C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.7704.21109.exe"
|
||
C:\Users\user\AppData\Local\windows update\svchost.exe
|
"C:\Users\user\AppData\Local\windows update\svchost.exe"
|
||
C:\Users\user\AppData\Local\windows update\svchost.exe
|
"C:\Users\user\AppData\Local\windows update\svchost.exe"
|
||
C:\Users\user\AppData\Local\windows update\svchost.exe
|
"C:\Users\user\AppData\Local\windows update\svchost.exe"
|
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
ruslyz.ftp.narod.ru
|
unknown
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
|
windows update
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
E00000
|
heap
|
page read and write
|
||
678000
|
unkown
|
page read and write
|
||
E2D000
|
heap
|
page read and write
|
||
EF8000
|
heap
|
page read and write
|
||
7F1000
|
heap
|
page read and write
|
||
67C000
|
unkown
|
page readonly
|
||
ABD000
|
heap
|
page read and write
|
||
E24000
|
heap
|
page read and write
|
||
EBE000
|
heap
|
page read and write
|
||
F60000
|
heap
|
page read and write
|
||
AC6000
|
heap
|
page read and write
|
||
925000
|
unkown
|
page readonly
|
||
A00000
|
heap
|
page read and write
|
||
EC1000
|
heap
|
page read and write
|
||
28EE000
|
stack
|
page read and write
|
||
925000
|
unkown
|
page readonly
|
||
2C01000
|
heap
|
page read and write
|
||
BC0000
|
heap
|
page read and write
|
||
2ECE000
|
stack
|
page read and write
|
||
E2D000
|
heap
|
page read and write
|
||
492E000
|
stack
|
page read and write
|
||
A2C000
|
heap
|
page read and write
|
||
E58000
|
heap
|
page read and write
|
||
AFE000
|
heap
|
page read and write
|
||
310E000
|
stack
|
page read and write
|
||
E20000
|
heap
|
page read and write
|
||
E30000
|
heap
|
page read and write
|
||
2645000
|
heap
|
page read and write
|
||
2578000
|
heap
|
page read and write
|
||
7F6000
|
heap
|
page read and write
|
||
E29000
|
heap
|
page read and write
|
||
2750000
|
heap
|
page read and write
|
||
B01000
|
heap
|
page read and write
|
||
4B1E000
|
stack
|
page read and write
|
||
2B50000
|
trusted library allocation
|
page read and write
|
||
4A1E000
|
stack
|
page read and write
|
||
ED3000
|
heap
|
page read and write
|
||
48DE000
|
stack
|
page read and write
|
||
EEE000
|
heap
|
page read and write
|
||
E24000
|
heap
|
page read and write
|
||
670000
|
unkown
|
page readonly
|
||
EE3000
|
heap
|
page read and write
|
||
E1F000
|
stack
|
page read and write
|
||
B6B000
|
stack
|
page read and write
|
||
802000
|
heap
|
page read and write
|
||
78B000
|
stack
|
page read and write
|
||
7E0000
|
heap
|
page read and write
|
||
49DE000
|
stack
|
page read and write
|
||
519F000
|
stack
|
page read and write
|
||
A5B000
|
heap
|
page read and write
|
||
786000
|
stack
|
page read and write
|
||
ED3000
|
heap
|
page read and write
|
||
671000
|
unkown
|
page execute read
|
||
7F1000
|
heap
|
page read and write
|
||
749000
|
stack
|
page read and write
|
||
A0A000
|
heap
|
page read and write
|
||
2A9F000
|
stack
|
page read and write
|
||
676000
|
unkown
|
page readonly
|
||
7F0000
|
heap
|
page read and write
|
||
671000
|
unkown
|
page execute read
|
||
3612000
|
heap
|
page read and write
|
||
67C000
|
unkown
|
page readonly
|
||
924000
|
unkown
|
page read and write
|
||
505E000
|
stack
|
page read and write
|
||
676000
|
unkown
|
page readonly
|
||
D9E000
|
stack
|
page read and write
|
||
C9E000
|
stack
|
page read and write
|
||
C00000
|
heap
|
page read and write
|
||
676000
|
unkown
|
page readonly
|
||
E29000
|
heap
|
page read and write
|
||
2FCF000
|
stack
|
page read and write
|
||
C00000
|
heap
|
page read and write
|
||
67C000
|
unkown
|
page readonly
|
||
E52000
|
heap
|
page read and write
|
||
2560000
|
heap
|
page read and write
|
||
E12000
|
heap
|
page read and write
|
||
44DE000
|
stack
|
page read and write
|
||
15C0000
|
heap
|
page read and write
|
||
A48000
|
heap
|
page read and write
|
||
E9A000
|
heap
|
page read and write
|
||
770000
|
heap
|
page read and write
|
||
7B0000
|
heap
|
page read and write
|
||
638000
|
stack
|
page read and write
|
||
670000
|
unkown
|
page readonly
|
||
2764000
|
heap
|
page read and write
|
||
2720000
|
heap
|
page read and write
|
||
2570000
|
heap
|
page read and write
|
||
4520000
|
trusted library allocation
|
page read and write
|
||
920000
|
unkown
|
page readonly
|
||
67C000
|
unkown
|
page readonly
|
||
A26000
|
heap
|
page read and write
|
||
7A0000
|
heap
|
page read and write
|
||
2C13000
|
heap
|
page read and write
|
||
EE3000
|
heap
|
page read and write
|
||
479F000
|
stack
|
page read and write
|
||
EDC000
|
heap
|
page read and write
|
||
C02000
|
heap
|
page read and write
|
||
317E000
|
stack
|
page read and write
|
||
4B5E000
|
stack
|
page read and write
|
||
676000
|
unkown
|
page readonly
|
||
2760000
|
trusted library allocation
|
page read and write
|
||
80C000
|
heap
|
page read and write
|
||
E80000
|
heap
|
page read and write
|
||
A6A000
|
stack
|
page read and write
|
||
ED3000
|
heap
|
page read and write
|
||
2A20000
|
heap
|
page read and write
|
||
814000
|
heap
|
page read and write
|
||
2813000
|
heap
|
page read and write
|
||
7E7000
|
heap
|
page read and write
|
||
E47000
|
heap
|
page read and write
|
||
E20000
|
heap
|
page read and write
|
||
2B40000
|
heap
|
page read and write
|
||
736000
|
stack
|
page read and write
|
||
C02000
|
heap
|
page read and write
|
||
921000
|
unkown
|
page execute read
|
||
32BD000
|
stack
|
page read and write
|
||
1210000
|
heap
|
page read and write
|
||
A56000
|
heap
|
page read and write
|
||
670000
|
unkown
|
page readonly
|
||
2C13000
|
heap
|
page read and write
|
||
509E000
|
stack
|
page read and write
|
||
678000
|
unkown
|
page read and write
|
||
676000
|
unkown
|
page readonly
|
||
E00000
|
heap
|
page read and write
|
||
923000
|
unkown
|
page readonly
|
||
33FD000
|
stack
|
page read and write
|
||
2760000
|
heap
|
page read and write
|
||
E55000
|
heap
|
page read and write
|
||
EE3000
|
heap
|
page read and write
|
||
E5A000
|
heap
|
page read and write
|
||
E58000
|
heap
|
page read and write
|
||
790000
|
heap
|
page read and write
|
||
2801000
|
heap
|
page read and write
|
||
EC1000
|
heap
|
page read and write
|
||
E41000
|
heap
|
page read and write
|
||
BA0000
|
heap
|
page read and write
|
||
E5A000
|
heap
|
page read and write
|
||
B66000
|
stack
|
page read and write
|
||
EC1000
|
heap
|
page read and write
|
||
676000
|
unkown
|
page readonly
|
||
EE3000
|
heap
|
page read and write
|
||
AFB000
|
stack
|
page read and write
|
||
A42000
|
heap
|
page read and write
|
||
67C000
|
unkown
|
page readonly
|
||
2575000
|
heap
|
page read and write
|
||
3600000
|
heap
|
page read and write
|
||
EDC000
|
heap
|
page read and write
|
||
780000
|
heap
|
page read and write
|
||
7F8000
|
heap
|
page read and write
|
||
137E000
|
stack
|
page read and write
|
||
2BFF000
|
stack
|
page read and write
|
||
4200000
|
heap
|
page read and write
|
||
2D01000
|
heap
|
page read and write
|
||
73B000
|
stack
|
page read and write
|
||
147F000
|
stack
|
page read and write
|
||
67C000
|
unkown
|
page readonly
|
||
BD0000
|
heap
|
page read and write
|
||
671000
|
unkown
|
page execute read
|
||
4CBE000
|
stack
|
page read and write
|
||
923000
|
unkown
|
page readonly
|
||
4212000
|
heap
|
page read and write
|
||
E41000
|
heap
|
page read and write
|
||
110E000
|
stack
|
page read and write
|
||
A12000
|
heap
|
page read and write
|
||
671000
|
unkown
|
page execute read
|
||
E30000
|
heap
|
page read and write
|
||
671000
|
unkown
|
page execute read
|
||
43DE000
|
stack
|
page read and write
|
||
807000
|
heap
|
page read and write
|
||
EC1000
|
heap
|
page read and write
|
||
2AFE000
|
stack
|
page read and write
|
||
ABD000
|
heap
|
page read and write
|
||
2901000
|
heap
|
page read and write
|
||
B9E000
|
stack
|
page read and write
|
||
2C01000
|
heap
|
page read and write
|
||
670000
|
unkown
|
page readonly
|
||
7CA000
|
heap
|
page read and write
|
||
671000
|
unkown
|
page execute read
|
||
7CE000
|
heap
|
page read and write
|
||
34FF000
|
stack
|
page read and write
|
||
2550000
|
heap
|
page read and write
|
||
659000
|
stack
|
page read and write
|
||
4A2E000
|
stack
|
page read and write
|
||
7C0000
|
heap
|
page read and write
|
||
D1E000
|
stack
|
page read and write
|
||
E12000
|
heap
|
page read and write
|
||
469E000
|
stack
|
page read and write
|
||
670000
|
unkown
|
page readonly
|
||
7F6000
|
heap
|
page read and write
|
||
F01000
|
heap
|
page read and write
|
||
2640000
|
heap
|
page read and write
|
||
7D0000
|
heap
|
page read and write
|
||
2A30000
|
trusted library allocation
|
page read and write
|
||
E6E000
|
heap
|
page read and write
|
||
BF0000
|
heap
|
page read and write
|
||
4E0E000
|
stack
|
page read and write
|
||
AF6000
|
stack
|
page read and write
|
||
47EE000
|
stack
|
page read and write
|
||
E6E000
|
heap
|
page read and write
|
||
120F000
|
stack
|
page read and write
|
||
4C5E000
|
stack
|
page read and write
|
||
4F5E000
|
stack
|
page read and write
|
||
7D0000
|
heap
|
page read and write
|
||
921000
|
unkown
|
page execute read
|
||
EB9000
|
heap
|
page read and write
|
||
300E000
|
stack
|
page read and write
|
||
A6F000
|
heap
|
page read and write
|
||
33BE000
|
stack
|
page read and write
|
||
670000
|
unkown
|
page readonly
|
||
4DBF000
|
stack
|
page read and write
|
||
2D01000
|
heap
|
page read and write
|
||
F01000
|
heap
|
page read and write
|
||
780000
|
heap
|
page read and write
|
||
920000
|
unkown
|
page readonly
|
||
48EE000
|
stack
|
page read and write
|
||
AE1000
|
heap
|
page read and write
|
||
EC1000
|
heap
|
page read and write
|
||
4F0E000
|
stack
|
page read and write
|
||
678000
|
unkown
|
page read and write
|
||
27EE000
|
stack
|
page read and write
|
||
327F000
|
stack
|
page read and write
|
||
7B0000
|
heap
|
page read and write
|
There are 212 hidden memdumps, click here to show them.