Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Windows\System32\loaddll32.exe
|
loaddll32.exe "C:\Users\user\Desktop\msimg32.dll"
|
||
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
||
C:\Windows\SysWOW64\cmd.exe
|
cmd.exe /C rundll32.exe "C:\Users\user\Desktop\msimg32.dll",#1
|
||
C:\Windows\SysWOW64\rundll32.exe
|
rundll32.exe C:\Users\user\Desktop\msimg32.dll,AlphaBlend
|
||
C:\Windows\SysWOW64\rundll32.exe
|
rundll32.exe "C:\Users\user\Desktop\msimg32.dll",#1
|
||
C:\Windows\SysWOW64\rundll32.exe
|
rundll32.exe C:\Users\user\Desktop\msimg32.dll,AppendCaptureDeviceList
|
||
C:\Windows\SysWOW64\rundll32.exe
|
rundll32.exe C:\Users\user\Desktop\msimg32.dll,AppendDeviceList
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://www.3dmm2.com/doom/
|
unknown
|
||
http://icculus.org/physfs/
|
unknown
|
||
http://icculus.org/physfs/4
|
unknown
|
||
http://icculus.org/physfs/T
|
unknown
|
||
http://icculus.org/physfs/t
|
unknown
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
6487A000
|
unkown
|
page readonly
|
||
4D40000
|
heap
|
page read and write
|
||
64979000
|
unkown
|
page readonly
|
||
648A1000
|
unkown
|
page write copy
|
||
64979000
|
unkown
|
page readonly
|
||
647E4000
|
unkown
|
page readonly
|
||
3150000
|
heap
|
page read and write
|
||
64877000
|
unkown
|
page read and write
|
||
70C000
|
stack
|
page read and write
|
||
648A1000
|
unkown
|
page write copy
|
||
860000
|
heap
|
page read and write
|
||
64878000
|
unkown
|
page write copy
|
||
647E4000
|
unkown
|
page readonly
|
||
648B7000
|
unkown
|
page readonly
|
||
64979000
|
unkown
|
page readonly
|
||
6493E000
|
unkown
|
page readonly
|
||
64877000
|
unkown
|
page read and write
|
||
6487A000
|
unkown
|
page readonly
|
||
2D3A000
|
heap
|
page read and write
|
||
647DA000
|
unkown
|
page write copy
|
||
648A0000
|
unkown
|
page read and write
|
||
8BF000
|
heap
|
page read and write
|
||
64878000
|
unkown
|
page write copy
|
||
AD0000
|
heap
|
page read and write
|
||
64871000
|
unkown
|
page write copy
|
||
64979000
|
unkown
|
page readonly
|
||
64878000
|
unkown
|
page write copy
|
||
64877000
|
unkown
|
page read and write
|
||
6493E000
|
unkown
|
page readonly
|
||
648B7000
|
unkown
|
page readonly
|
||
647E4000
|
unkown
|
page readonly
|
||
648A1000
|
unkown
|
page write copy
|
||
99E000
|
stack
|
page read and write
|
||
7D3000
|
heap
|
page read and write
|
||
7BA000
|
heap
|
page read and write
|
||
49F0000
|
heap
|
page read and write
|
||
647E4000
|
unkown
|
page readonly
|
||
648A0000
|
unkown
|
page read and write
|
||
4D0000
|
heap
|
page read and write
|
||
710000
|
heap
|
page read and write
|
||
645C1000
|
unkown
|
page execute read
|
||
9CB000
|
stack
|
page read and write
|
||
47A0000
|
heap
|
page read and write
|
||
BE3000
|
heap
|
page read and write
|
||
8A5000
|
heap
|
page read and write
|
||
64877000
|
unkown
|
page read and write
|
||
86B000
|
heap
|
page read and write
|
||
8EE000
|
stack
|
page read and write
|
||
64871000
|
unkown
|
page write copy
|
||
6493E000
|
unkown
|
page readonly
|
||
2DFC000
|
stack
|
page read and write
|
||
64871000
|
unkown
|
page write copy
|
||
303B000
|
stack
|
page read and write
|
||
6493E000
|
unkown
|
page readonly
|
||
760000
|
heap
|
page read and write
|
||
645C0000
|
unkown
|
page readonly
|
||
647E4000
|
unkown
|
page readonly
|
||
645C1000
|
unkown
|
page execute read
|
||
C40000
|
heap
|
page read and write
|
||
648B7000
|
unkown
|
page readonly
|
||
3AC000
|
stack
|
page read and write
|
||
A20000
|
heap
|
page read and write
|
||
648A0000
|
unkown
|
page read and write
|
||
BC0000
|
heap
|
page read and write
|
||
8E0000
|
heap
|
page read and write
|
||
33FF000
|
stack
|
page read and write
|
||
648A0000
|
unkown
|
page read and write
|
||
648A0000
|
unkown
|
page read and write
|
||
9B0000
|
heap
|
page read and write
|
||
647DA000
|
unkown
|
page write copy
|
||
645C0000
|
unkown
|
page readonly
|
||
3EB000
|
stack
|
page read and write
|
||
BCA000
|
heap
|
page read and write
|
||
96E000
|
stack
|
page read and write
|
||
A9F000
|
stack
|
page read and write
|
||
31D3000
|
heap
|
page read and write
|
||
33BE000
|
stack
|
page read and write
|
||
2D53000
|
heap
|
page read and write
|
||
C00000
|
heap
|
page read and write
|
||
645C1000
|
unkown
|
page execute read
|
||
2D30000
|
heap
|
page read and write
|
||
31BA000
|
heap
|
page read and write
|
||
3080000
|
heap
|
page read and write
|
||
648B7000
|
unkown
|
page readonly
|
||
7B0000
|
heap
|
page read and write
|
||
6487A000
|
unkown
|
page readonly
|
||
4E0000
|
heap
|
page read and write
|
||
730000
|
heap
|
page read and write
|
||
C30000
|
heap
|
page read and write
|
||
64871000
|
unkown
|
page write copy
|
||
64877000
|
unkown
|
page read and write
|
||
64979000
|
unkown
|
page readonly
|
||
30B0000
|
heap
|
page read and write
|
||
645C0000
|
unkown
|
page readonly
|
||
650000
|
heap
|
page read and write
|
||
6493E000
|
unkown
|
page readonly
|
||
2E20000
|
heap
|
page read and write
|
||
31B0000
|
heap
|
page read and write
|
||
98C000
|
stack
|
page read and write
|
||
648A1000
|
unkown
|
page write copy
|
||
647DA000
|
unkown
|
page write copy
|
||
7D0000
|
heap
|
page read and write
|
||
312E000
|
stack
|
page read and write
|
||
645C1000
|
unkown
|
page execute read
|
||
7C0000
|
heap
|
page read and write
|
||
85F000
|
stack
|
page read and write
|
||
64878000
|
unkown
|
page write copy
|
||
30A0000
|
heap
|
page read and write
|
||
62B000
|
stack
|
page read and write
|
||
75E000
|
stack
|
page read and write
|
||
648A1000
|
unkown
|
page write copy
|
||
64871000
|
unkown
|
page write copy
|
||
645C0000
|
unkown
|
page readonly
|
||
7B0000
|
heap
|
page read and write
|
||
92F000
|
stack
|
page read and write
|
||
2EA0000
|
heap
|
page read and write
|
||
3470000
|
heap
|
page read and write
|
||
9AF000
|
stack
|
page read and write
|
||
645C0000
|
unkown
|
page readonly
|
||
74B000
|
stack
|
page read and write
|
||
647DA000
|
unkown
|
page write copy
|
||
319F000
|
stack
|
page read and write
|
||
6487A000
|
unkown
|
page readonly
|
||
647DA000
|
unkown
|
page write copy
|
||
648B7000
|
unkown
|
page readonly
|
||
645C1000
|
unkown
|
page execute read
|
||
64878000
|
unkown
|
page write copy
|
||
46C000
|
stack
|
page read and write
|
||
6487A000
|
unkown
|
page readonly
|
||
86F000
|
heap
|
page read and write
|
There are 120 hidden memdumps, click here to show them.