Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Windows\System32\loaddll64.exe
|
loaddll64.exe "C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Krypt.28688.30024.dll"
|
||
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
||
C:\Windows\System32\cmd.exe
|
cmd.exe /C rundll32.exe "C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Krypt.28688.30024.dll",#1
|
||
C:\Windows\System32\rundll32.exe
|
rundll32.exe "C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Krypt.28688.30024.dll",#1
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
248F9985000
|
heap
|
page read and write
|
||
248FCDE3000
|
heap
|
page read and write
|
||
248F9985000
|
heap
|
page read and write
|
||
B75B11A000
|
stack
|
page read and write
|
||
248F997C000
|
heap
|
page read and write
|
||
B75B4FE000
|
stack
|
page read and write
|
||
248FCDE0000
|
heap
|
page read and write
|
||
248FCCA0000
|
heap
|
page read and write
|
||
B75B19E000
|
stack
|
page read and write
|
||
248F9985000
|
heap
|
page read and write
|
||
248F9C40000
|
heap
|
page read and write
|
||
248F9900000
|
heap
|
page read and write
|
||
248F9996000
|
heap
|
page read and write
|
||
248F9C45000
|
heap
|
page read and write
|
||
241DCA50000
|
heap
|
page read and write
|
||
248F9979000
|
heap
|
page read and write
|
||
248F98D0000
|
heap
|
page read and write
|
||
248F9968000
|
heap
|
page read and write
|
||
248FD180000
|
trusted library allocation
|
page read and write
|
||
248F9C4B000
|
heap
|
page read and write
|
||
248F98E0000
|
heap
|
page read and write
|
||
9CEC4FF000
|
stack
|
page read and write
|
||
9CEC2FC000
|
stack
|
page read and write
|
||
241DCA60000
|
heap
|
page read and write
|
||
248F9990000
|
heap
|
page read and write
|
||
B75B47F000
|
stack
|
page read and write
|
||
248F9986000
|
heap
|
page read and write
|
||
248FB530000
|
heap
|
page read and write
|
||
241DCA89000
|
heap
|
page read and write
|
||
248F9985000
|
heap
|
page read and write
|
||
241DCA8D000
|
heap
|
page read and write
|
||
248F9960000
|
heap
|
page read and write
|
||
241DCA98000
|
heap
|
page read and write
|
||
241DCA80000
|
heap
|
page read and write
|
||
248F997C000
|
heap
|
page read and write
|
||
248F9980000
|
heap
|
page read and write
|
||
9CEC3FF000
|
stack
|
page read and write
|
||
248F9982000
|
heap
|
page read and write
|
There are 28 hidden memdumps, click here to show them.