Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Windows\System32\loaddll32.exe
|
loaddll32.exe "C:\Users\user\Desktop\1728837011f2c8c4409febaf6c32a8ab478efe1cbe481eec5860f61fb84d06b6e12e91d6fe985.dat-decoded.dll"
|
||
C:\Windows\SysWOW64\cmd.exe
|
cmd.exe /C rundll32.exe "C:\Users\user\Desktop\1728837011f2c8c4409febaf6c32a8ab478efe1cbe481eec5860f61fb84d06b6e12e91d6fe985.dat-decoded.dll",#1
|
||
C:\Windows\SysWOW64\rundll32.exe
|
rundll32.exe "C:\Users\user\Desktop\1728837011f2c8c4409febaf6c32a8ab478efe1cbe481eec5860f61fb84d06b6e12e91d6fe985.dat-decoded.dll",#1
|
||
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
3469000
|
heap
|
page read and write
|
||
33DE000
|
stack
|
page read and write
|
||
3468000
|
heap
|
page read and write
|
||
57D000
|
stack
|
page read and write
|
||
331F000
|
stack
|
page read and write
|
||
2F0C000
|
stack
|
page read and write
|
||
7C0000
|
heap
|
page read and write
|
||
5F0000
|
heap
|
page read and write
|
||
345C000
|
heap
|
page read and write
|
||
3483000
|
heap
|
page read and write
|
||
335A000
|
heap
|
page read and write
|
||
3350000
|
heap
|
page read and write
|
||
9BF000
|
stack
|
page read and write
|
||
65E4000
|
heap
|
page read and write
|
||
7CB000
|
heap
|
page read and write
|
||
63E000
|
stack
|
page read and write
|
||
650000
|
heap
|
page read and write
|
||
65E0000
|
heap
|
page read and write
|
||
344A000
|
heap
|
page read and write
|
||
2EC9000
|
stack
|
page read and write
|
||
7CF000
|
heap
|
page read and write
|
||
346C000
|
heap
|
page read and write
|
||
5E0000
|
heap
|
page read and write
|
||
32D0000
|
heap
|
page read and write
|
||
3410000
|
heap
|
page read and write
|
||
3440000
|
heap
|
page read and write
|
||
47D000
|
stack
|
page read and write
|
||
3471000
|
heap
|
page read and write
|
||
2F80000
|
heap
|
page read and write
|
||
3472000
|
heap
|
page read and write
|
||
A50000
|
heap
|
page read and write
|
||
3420000
|
heap
|
page read and write
|
||
2FFE000
|
stack
|
page read and write
|
||
7D7000
|
heap
|
page read and write
|
||
346D000
|
heap
|
page read and write
|
||
3468000
|
heap
|
page read and write
|
||
3465000
|
heap
|
page read and write
|
||
3469000
|
heap
|
page read and write
|
||
3460000
|
heap
|
page read and write
|
||
3463000
|
heap
|
page read and write
|
||
3468000
|
heap
|
page read and write
|
||
6980000
|
trusted library allocation
|
page read and write
|
||
3356000
|
heap
|
page read and write
|
||
2F70000
|
heap
|
page read and write
|
||
339D000
|
stack
|
page read and write
|
There are 35 hidden memdumps, click here to show them.