Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
SecuriteInfo.com.HackTool.Win32.Crack.28815.11045.exe
|
PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
|
initial sample
|
||
\Device\ConDrv
|
ASCII text, with CRLF line terminators
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\SecuriteInfo.com.HackTool.Win32.Crack.28815.11045.exe
|
"C:\Users\user\Desktop\SecuriteInfo.com.HackTool.Win32.Crack.28815.11045.exe"
|
||
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
https://www.newtonsoft.com/json
|
unknown
|
||
https://www.nuget.org/packages/Newtonsoft.Json.Bson
|
unknown
|
||
http://james.newtonking.com/projects/json
|
unknown
|
||
https://www.newtonsoft.com/jsonschema
|
unknown
|
||
https://github.com/JamesNK/Newtonsoft.Json
|
unknown
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
2611000
|
trusted library allocation
|
page read and write
|
||
92000
|
unkown
|
page readonly
|
||
800000
|
trusted library allocation
|
page read and write
|
||
E6000
|
unkown
|
page readonly
|
||
8D1000
|
heap
|
page read and write
|
||
25B7000
|
trusted library allocation
|
page read and write
|
||
A80000
|
heap
|
page read and write
|
||
860000
|
trusted library allocation
|
page execute and read and write
|
||
510000
|
heap
|
page read and write
|
||
A70000
|
trusted library allocation
|
page read and write
|
||
870000
|
trusted library allocation
|
page read and write
|
||
827000
|
trusted library allocation
|
page execute and read and write
|
||
49FE000
|
stack
|
page read and write
|
||
1AC000
|
stack
|
page read and write
|
||
81A000
|
trusted library allocation
|
page execute and read and write
|
||
690000
|
heap
|
page read and write
|
||
89A000
|
heap
|
page read and write
|
||
8E3000
|
heap
|
page read and write
|
||
7F0000
|
trusted library allocation
|
page read and write
|
||
6E6000
|
heap
|
page read and write
|
||
25C0000
|
trusted library allocation
|
page read and write
|
||
259E000
|
stack
|
page read and write
|
||
2430000
|
trusted library section
|
page read and write
|
||
4A3E000
|
stack
|
page read and write
|
||
249E000
|
stack
|
page read and write
|
||
363D000
|
trusted library allocation
|
page read and write
|
||
25B5000
|
trusted library allocation
|
page read and write
|
||
2600000
|
heap
|
page execute and read and write
|
||
890000
|
heap
|
page read and write
|
||
7FD000
|
trusted library allocation
|
page execute and read and write
|
||
242E000
|
stack
|
page read and write
|
||
850000
|
heap
|
page read and write
|
||
25BA000
|
trusted library allocation
|
page read and write
|
||
4DEF000
|
stack
|
page read and write
|
||
25C7000
|
trusted library allocation
|
page read and write
|
||
7F3000
|
trusted library allocation
|
page execute and read and write
|
||
4F5000
|
stack
|
page read and write
|
||
7F4000
|
trusted library allocation
|
page read and write
|
||
6E0000
|
heap
|
page read and write
|
||
8C4000
|
heap
|
page read and write
|
||
4A40000
|
heap
|
page execute and read and write
|
||
8BB000
|
heap
|
page read and write
|
||
4B3E000
|
stack
|
page read and write
|
||
9CE000
|
stack
|
page read and write
|
||
90000
|
unkown
|
page readonly
|
||
FC000
|
unkown
|
page readonly
|
||
2450000
|
heap
|
page read and write
|
||
6D0000
|
trusted library allocation
|
page read and write
|
||
38AB000
|
trusted library allocation
|
page read and write
|
||
82B000
|
trusted library allocation
|
page execute and read and write
|
||
89E000
|
heap
|
page read and write
|
||
25B3000
|
trusted library allocation
|
page read and write
|
||
25B0000
|
trusted library allocation
|
page read and write
|
||
816000
|
trusted library allocation
|
page execute and read and write
|
||
A79000
|
trusted library allocation
|
page read and write
|
||
4EEE000
|
stack
|
page read and write
|
||
3611000
|
trusted library allocation
|
page read and write
|
||
5F0000
|
heap
|
page read and write
|
||
4C4E000
|
stack
|
page read and write
|
||
25D0000
|
trusted library allocation
|
page read and write
|
||
4A50000
|
trusted library section
|
page read and write
|
There are 51 hidden memdumps, click here to show them.