Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Windows\System32\loaddll32.exe
|
loaddll32.exe "C:\Users\user\Desktop\17283737684bd86655892d68ec8069bdd2f47d78d953272c24d1231ed47fa5f444cf553321351.dat-decoded.dll"
|
||
C:\Windows\SysWOW64\cmd.exe
|
cmd.exe /C rundll32.exe "C:\Users\user\Desktop\17283737684bd86655892d68ec8069bdd2f47d78d953272c24d1231ed47fa5f444cf553321351.dat-decoded.dll",#1
|
||
C:\Windows\SysWOW64\rundll32.exe
|
rundll32.exe "C:\Users\user\Desktop\17283737684bd86655892d68ec8069bdd2f47d78d953272c24d1231ed47fa5f444cf553321351.dat-decoded.dll",#1
|
||
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
30B3000
|
heap
|
page read and write
|
||
113E000
|
stack
|
page read and write
|
||
11B0000
|
heap
|
page read and write
|
||
2E7E000
|
stack
|
page read and write
|
||
2E3E000
|
stack
|
page read and write
|
||
153F000
|
stack
|
page read and write
|
||
2E9A000
|
heap
|
page read and write
|
||
65F0000
|
trusted library allocation
|
page read and write
|
||
DD0000
|
heap
|
page read and write
|
||
1270000
|
heap
|
page read and write
|
||
2B90000
|
heap
|
page read and write
|
||
30BC000
|
heap
|
page read and write
|
||
10FD000
|
stack
|
page read and write
|
||
2B2C000
|
stack
|
page read and write
|
||
30AB000
|
heap
|
page read and write
|
||
30C2000
|
heap
|
page read and write
|
||
2EC0000
|
heap
|
page read and write
|
||
127F000
|
heap
|
page read and write
|
||
309A000
|
heap
|
page read and write
|
||
2AEA000
|
stack
|
page read and write
|
||
625F000
|
stack
|
page read and write
|
||
301E000
|
stack
|
page read and write
|
||
30D4000
|
heap
|
page read and write
|
||
3030000
|
heap
|
page read and write
|
||
30B7000
|
heap
|
page read and write
|
||
2FDD000
|
stack
|
page read and write
|
||
2E96000
|
heap
|
page read and write
|
||
163F000
|
stack
|
page read and write
|
||
30D4000
|
heap
|
page read and write
|
||
2E90000
|
heap
|
page read and write
|
||
30BF000
|
heap
|
page read and write
|
||
30B3000
|
heap
|
page read and write
|
||
30AF000
|
heap
|
page read and write
|
||
1760000
|
heap
|
page read and write
|
||
2BA0000
|
heap
|
page read and write
|
||
D6D000
|
stack
|
page read and write
|
||
DE0000
|
heap
|
page read and write
|
||
127B000
|
heap
|
page read and write
|
||
30B7000
|
heap
|
page read and write
|
||
307E000
|
stack
|
page read and write
|
||
6190000
|
heap
|
page read and write
|
||
6194000
|
heap
|
page read and write
|
||
3080000
|
heap
|
page read and write
|
||
3090000
|
heap
|
page read and write
|
||
117E000
|
stack
|
page read and write
|
||
30D4000
|
heap
|
page read and write
|
There are 36 hidden memdumps, click here to show them.