Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
Cleaning_Tool_for_Driver_Select1.17.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
initial sample
|
||
C:\Users\user\Desktop\DriverSelect_CleaningTool.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
dropped
|
||
C:\Users\user\Desktop\DriverSelect_CleaningTool.pdf
|
PDF document, version 1.5 (zip deflate encoded)
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\Cleaning_Tool_for_Driver_Select1.17.exe
|
"C:\Users\user\Desktop\Cleaning_Tool_for_Driver_Select1.17.exe"
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
8CF000
|
stack
|
page read and write
|
||
98000
|
stack
|
page read and write
|
||
2A23000
|
heap
|
page read and write
|
||
434000
|
unkown
|
page write copy
|
||
22DE000
|
stack
|
page read and write
|
||
4B70000
|
direct allocation
|
page read and write
|
||
2350000
|
heap
|
page read and write
|
||
2270000
|
heap
|
page read and write
|
||
460A000
|
heap
|
page read and write
|
||
28DE000
|
stack
|
page read and write
|
||
4E10000
|
direct allocation
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
29DF000
|
stack
|
page read and write
|
||
3E00000
|
trusted library allocation
|
page read and write
|
||
6B7000
|
heap
|
page read and write
|
||
2A62000
|
heap
|
page read and write
|
||
4C90000
|
heap
|
page read and write
|
||
6BD000
|
heap
|
page read and write
|
||
2A22000
|
heap
|
page read and write
|
||
4C91000
|
heap
|
page read and write
|
||
1F0000
|
heap
|
page read and write
|
||
4CD0000
|
heap
|
page read and write
|
||
42D000
|
unkown
|
page readonly
|
||
401000
|
unkown
|
page execute read
|
||
4C11000
|
heap
|
page read and write
|
||
434000
|
unkown
|
page read and write
|
||
2180000
|
heap
|
page read and write
|
||
2353000
|
heap
|
page read and write
|
||
19C000
|
stack
|
page read and write
|
||
2B70000
|
heap
|
page read and write
|
||
57E000
|
stack
|
page read and write
|
||
4B6D000
|
direct allocation
|
page read and write
|
||
69E000
|
heap
|
page read and write
|
||
535000
|
heap
|
page read and write
|
||
6CE000
|
heap
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
6E1000
|
heap
|
page read and write
|
||
6E1000
|
heap
|
page read and write
|
||
2AA2000
|
heap
|
page read and write
|
||
47E2000
|
direct allocation
|
page read and write
|
||
4C91000
|
heap
|
page read and write
|
||
29E1000
|
heap
|
page read and write
|
||
2A22000
|
heap
|
page read and write
|
||
6DE000
|
heap
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
2A63000
|
heap
|
page read and write
|
||
6C5000
|
heap
|
page read and write
|
||
21B5000
|
heap
|
page read and write
|
||
7CE000
|
stack
|
page read and write
|
||
6E1000
|
heap
|
page read and write
|
||
43A000
|
unkown
|
page readonly
|
||
4D10000
|
heap
|
page read and write
|
||
6C1000
|
heap
|
page read and write
|
||
29E0000
|
heap
|
page read and write
|
||
510000
|
heap
|
page read and write
|
||
69A000
|
heap
|
page read and write
|
||
21B0000
|
heap
|
page read and write
|
||
6C6000
|
heap
|
page read and write
|
||
21BA000
|
heap
|
page read and write
|
||
47E0000
|
direct allocation
|
page read and write
|
||
47ED000
|
direct allocation
|
page read and write
|
||
530000
|
heap
|
page read and write
|
||
67F000
|
stack
|
page read and write
|
||
6C5000
|
heap
|
page read and write
|
||
6CB000
|
heap
|
page read and write
|
||
4C10000
|
heap
|
page read and write
|
||
29E3000
|
heap
|
page read and write
|
||
47F0000
|
direct allocation
|
page read and write
|
||
4860000
|
direct allocation
|
page read and write
|
||
4C50000
|
heap
|
page read and write
|
||
279F000
|
stack
|
page read and write
|
||
43A000
|
unkown
|
page readonly
|
||
6C1000
|
heap
|
page read and write
|
||
6C9000
|
heap
|
page read and write
|
||
690000
|
heap
|
page read and write
|
||
2A63000
|
heap
|
page read and write
|
||
4B62000
|
direct allocation
|
page read and write
|
||
6CE000
|
heap
|
page read and write
|
||
2170000
|
heap
|
page read and write
|
||
42D000
|
unkown
|
page readonly
|
||
4C11000
|
heap
|
page read and write
|
||
2180000
|
heap
|
page read and write
|
There are 72 hidden memdumps, click here to show them.