Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\IMG_3322101870451.exe
|
"C:\Users\user\Desktop\IMG_3322101870451.exe"
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://185.167.61.13
|
unknown
|
||
http://185.167.61.13/aa/Ubeyvibl.vdfP
|
unknown
|
||
http://crl.thawte.com/ThawteTimestampingCA.crl0
|
unknown
|
||
http://185.167.61.13D
|
unknown
|
||
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
|
unknown
|
||
http://ocsp.thawte.com0
|
unknown
|
||
http://185.167.61.13/aa/Ubeyvibl.vdf
|
185.167.61.13
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
185.167.61.13
|
unknown
|
Turkey
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing
|
EnableConsoleTracing
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\IMG_3322101870451_RASAPI32
|
EnableFileTracing
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\IMG_3322101870451_RASAPI32
|
EnableAutoFileTracing
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\IMG_3322101870451_RASAPI32
|
EnableConsoleTracing
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\IMG_3322101870451_RASAPI32
|
FileTracingMask
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\IMG_3322101870451_RASAPI32
|
ConsoleTracingMask
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\IMG_3322101870451_RASAPI32
|
MaxFileSize
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\IMG_3322101870451_RASAPI32
|
FileDirectory
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\IMG_3322101870451_RASMANCS
|
EnableFileTracing
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\IMG_3322101870451_RASMANCS
|
EnableAutoFileTracing
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\IMG_3322101870451_RASMANCS
|
EnableConsoleTracing
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\IMG_3322101870451_RASMANCS
|
FileTracingMask
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\IMG_3322101870451_RASMANCS
|
ConsoleTracingMask
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\IMG_3322101870451_RASMANCS
|
MaxFileSize
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\IMG_3322101870451_RASMANCS
|
FileDirectory
|
There are 5 hidden registries, click here to show them.
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
33F2000
|
trusted library allocation
|
page read and write
|
||
1350000
|
heap
|
page read and write
|
||
31C0000
|
trusted library allocation
|
page read and write
|
||
17FE000
|
stack
|
page read and write
|
||
42C1000
|
trusted library allocation
|
page read and write
|
||
344C000
|
trusted library allocation
|
page read and write
|
||
338A000
|
trusted library allocation
|
page read and write
|
||
33C6000
|
trusted library allocation
|
page read and write
|
||
1519000
|
heap
|
page read and write
|
||
1453000
|
trusted library allocation
|
page execute and read and write
|
||
3456000
|
trusted library allocation
|
page read and write
|
||
587D000
|
stack
|
page read and write
|
||
53BE000
|
stack
|
page read and write
|
||
5730000
|
heap
|
page execute and read and write
|
||
6D10000
|
heap
|
page read and write
|
||
12FB000
|
stack
|
page read and write
|
||
3366000
|
trusted library allocation
|
page read and write
|
||
14A5000
|
heap
|
page read and write
|
||
3392000
|
trusted library allocation
|
page read and write
|
||
1377000
|
heap
|
page read and write
|
||
6460000
|
heap
|
page read and write
|
||
1454000
|
trusted library allocation
|
page read and write
|
||
147E000
|
heap
|
page read and write
|
||
3439000
|
trusted library allocation
|
page read and write
|
||
333E000
|
trusted library allocation
|
page read and write
|
||
32B7000
|
heap
|
page read and write
|
||
31BE000
|
stack
|
page read and write
|
||
1770000
|
trusted library allocation
|
page read and write
|
||
3319000
|
trusted library allocation
|
page read and write
|
||
6D00000
|
heap
|
page read and write
|
||
1470000
|
heap
|
page read and write
|
||
13A0000
|
heap
|
page read and write
|
||
6BFD000
|
stack
|
page read and write
|
||
13ED000
|
stack
|
page read and write
|
||
5D4D000
|
stack
|
page read and write
|
||
6463000
|
heap
|
page read and write
|
||
646B000
|
heap
|
page read and write
|
||
5CCE000
|
stack
|
page read and write
|
||
1800000
|
trusted library allocation
|
page execute and read and write
|
||
6471000
|
heap
|
page read and write
|
||
3379000
|
trusted library allocation
|
page read and write
|
||
337E000
|
trusted library allocation
|
page read and write
|
||
F20000
|
unkown
|
page readonly
|
||
5B8D000
|
stack
|
page read and write
|
||
5720000
|
heap
|
page read and write
|
||
5E4C000
|
stack
|
page read and write
|
||
6010000
|
trusted library section
|
page read and write
|
||
577D000
|
stack
|
page read and write
|
||
58BE000
|
stack
|
page read and write
|
||
3358000
|
trusted library allocation
|
page read and write
|
||
1757000
|
trusted library allocation
|
page execute and read and write
|
||
338C000
|
trusted library allocation
|
page read and write
|
||
1810000
|
heap
|
page read and write
|
||
1740000
|
trusted library allocation
|
page read and write
|
||
6473000
|
heap
|
page read and write
|
||
FEC000
|
stack
|
page read and write
|
||
3396000
|
trusted library allocation
|
page read and write
|
||
609E000
|
stack
|
page read and write
|
||
605D000
|
stack
|
page read and write
|
||
5F0E000
|
stack
|
page read and write
|
||
174A000
|
trusted library allocation
|
page execute and read and write
|
||
17BE000
|
stack
|
page read and write
|
||
147A000
|
heap
|
page read and write
|
||
5C88000
|
stack
|
page read and write
|
||
1746000
|
trusted library allocation
|
page execute and read and write
|
||
67DD000
|
stack
|
page read and write
|
||
335F000
|
trusted library allocation
|
page read and write
|
||
32C1000
|
trusted library allocation
|
page read and write
|
||
31E0000
|
trusted library allocation
|
page read and write
|
||
1750000
|
trusted library allocation
|
page read and write
|
||
145D000
|
trusted library allocation
|
page execute and read and write
|
||
33FA000
|
trusted library allocation
|
page read and write
|
||
59BE000
|
stack
|
page read and write
|
||
1817000
|
heap
|
page read and write
|
||
32C6000
|
trusted library allocation
|
page read and write
|
||
3448000
|
trusted library allocation
|
page read and write
|
||
3450000
|
trusted library allocation
|
page read and write
|
||
6CFC000
|
stack
|
page read and write
|
||
151E000
|
heap
|
page read and write
|
||
F22000
|
unkown
|
page readonly
|
||
3390000
|
trusted library allocation
|
page read and write
|
||
5D0E000
|
stack
|
page read and write
|
||
1440000
|
trusted library allocation
|
page read and write
|
||
600F000
|
stack
|
page read and write
|
||
173D000
|
stack
|
page read and write
|
||
66DD000
|
stack
|
page read and write
|
||
621D000
|
stack
|
page read and write
|
||
631E000
|
stack
|
page read and write
|
||
142D000
|
stack
|
page read and write
|
||
1460000
|
trusted library allocation
|
page read and write
|
||
5700000
|
trusted library allocation
|
page read and write
|
||
1370000
|
heap
|
page read and write
|
||
31F0000
|
heap
|
page execute and read and write
|
||
338E000
|
trusted library allocation
|
page read and write
|
||
175B000
|
trusted library allocation
|
page execute and read and write
|
||
14B2000
|
heap
|
page read and write
|
||
1360000
|
heap
|
page read and write
|
||
6465000
|
heap
|
page read and write
|
||
191D000
|
stack
|
page read and write
|
||
1450000
|
trusted library allocation
|
page read and write
|
||
32B0000
|
heap
|
page read and write
|
||
33BE000
|
trusted library allocation
|
page read and write
|
There are 92 hidden memdumps, click here to show them.