Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Windows\System32\loaddll32.exe
|
loaddll32.exe "C:\Users\user\Desktop\1728293259cc6e52b482888882dfe5c059be5da0d1632c0622501d4ffa671dd4a2b13e033e282.dat-decoded.dll"
|
||
C:\Windows\SysWOW64\cmd.exe
|
cmd.exe /C rundll32.exe "C:\Users\user\Desktop\1728293259cc6e52b482888882dfe5c059be5da0d1632c0622501d4ffa671dd4a2b13e033e282.dat-decoded.dll",#1
|
||
C:\Windows\SysWOW64\rundll32.exe
|
rundll32.exe "C:\Users\user\Desktop\1728293259cc6e52b482888882dfe5c059be5da0d1632c0622501d4ffa671dd4a2b13e033e282.dat-decoded.dll",#1
|
||
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
A50000
|
heap
|
page read and write
|
||
BAE000
|
stack
|
page read and write
|
||
A40000
|
heap
|
page read and write
|
||
5F24000
|
heap
|
page read and write
|
||
BD7000
|
heap
|
page read and write
|
||
5FD000
|
stack
|
page read and write
|
||
AEF000
|
heap
|
page read and write
|
||
BD2000
|
heap
|
page read and write
|
||
BE0000
|
heap
|
page read and write
|
||
BCB000
|
heap
|
page read and write
|
||
799000
|
stack
|
page read and write
|
||
E1E000
|
stack
|
page read and write
|
||
CEF000
|
stack
|
page read and write
|
||
7DC000
|
stack
|
page read and write
|
||
BCF000
|
heap
|
page read and write
|
||
5F20000
|
heap
|
page read and write
|
||
BF3000
|
heap
|
page read and write
|
||
D4E000
|
stack
|
page read and write
|
||
D8E000
|
stack
|
page read and write
|
||
BD8000
|
heap
|
page read and write
|
||
E2A000
|
heap
|
page read and write
|
||
E20000
|
heap
|
page read and write
|
||
DD0000
|
heap
|
page read and write
|
||
ACE000
|
stack
|
page read and write
|
||
930000
|
heap
|
page read and write
|
||
BD7000
|
heap
|
page read and write
|
||
AEB000
|
heap
|
page read and write
|
||
BE1000
|
heap
|
page read and write
|
||
BD7000
|
heap
|
page read and write
|
||
AE0000
|
heap
|
page read and write
|
||
D20000
|
heap
|
page read and write
|
||
9A0000
|
heap
|
page read and write
|
||
8FD000
|
stack
|
page read and write
|
||
CDF000
|
stack
|
page read and write
|
||
A80000
|
heap
|
page read and write
|
||
62F0000
|
trusted library allocation
|
page read and write
|
||
BBA000
|
heap
|
page read and write
|
||
E6F000
|
stack
|
page read and write
|
||
E26000
|
heap
|
page read and write
|
||
BB0000
|
heap
|
page read and write
|
||
BD4000
|
heap
|
page read and write
|
||
E70000
|
heap
|
page read and write
|
||
A80000
|
heap
|
page read and write
|
There are 33 hidden memdumps, click here to show them.