Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\Setup.exe
|
"C:\Users\user\Desktop\Setup.exe"
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
https://autohotkey.com
|
unknown
|
||
https://autohotkey.comCould
|
unknown
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
140125000
|
unkown
|
page execute
|
||
7EF000
|
stack
|
page read and write
|
||
8FE000
|
heap
|
page read and write
|
||
7F8000
|
stack
|
page read and write
|
||
8C0000
|
heap
|
page read and write
|
||
140132000
|
unkown
|
page readonly
|
||
7D2000
|
stack
|
page read and write
|
||
8F9000
|
heap
|
page read and write
|
||
2BB0000
|
heap
|
page read and write
|
||
1400F1000
|
unkown
|
page readonly
|
||
190000
|
heap
|
page read and write
|
||
140001000
|
unkown
|
page execute read
|
||
1400F1000
|
unkown
|
page readonly
|
||
8F9000
|
heap
|
page read and write
|
||
2A60000
|
heap
|
page read and write
|
||
8F5000
|
heap
|
page read and write
|
||
903000
|
heap
|
page read and write
|
||
8F1000
|
heap
|
page read and write
|
||
2C10000
|
heap
|
page read and write
|
||
8C7000
|
heap
|
page read and write
|
||
140001000
|
unkown
|
page execute read
|
||
8EA000
|
heap
|
page read and write
|
||
8F5000
|
heap
|
page read and write
|
||
140128000
|
unkown
|
page readonly
|
||
12B0000
|
heap
|
page read and write
|
||
4BBE000
|
stack
|
page read and write
|
||
12B5000
|
heap
|
page read and write
|
||
800000
|
heap
|
page read and write
|
||
140125000
|
unkown
|
page execute
|
||
140000000
|
unkown
|
page readonly
|
||
4FBF000
|
stack
|
page read and write
|
||
8F1000
|
heap
|
page read and write
|
||
140110000
|
unkown
|
page write copy
|
||
916000
|
heap
|
page read and write
|
||
1400DF000
|
unkown
|
page readonly
|
||
8F1000
|
heap
|
page read and write
|
||
7DF000
|
stack
|
page read and write
|
||
14011D000
|
unkown
|
page readonly
|
||
11BE000
|
stack
|
page read and write
|
||
140119000
|
unkown
|
page read and write
|
||
8F9000
|
heap
|
page read and write
|
||
7E3000
|
stack
|
page read and write
|
||
8F5000
|
heap
|
page read and write
|
||
140132000
|
unkown
|
page readonly
|
||
8F5000
|
heap
|
page read and write
|
||
140000000
|
unkown
|
page readonly
|
||
8E6000
|
heap
|
page read and write
|
||
2A70000
|
heap
|
page read and write
|
||
8F9000
|
heap
|
page read and write
|
||
916000
|
heap
|
page read and write
|
||
1400DF000
|
unkown
|
page readonly
|
||
140128000
|
unkown
|
page readonly
|
||
170000
|
heap
|
page read and write
|
||
14011D000
|
unkown
|
page readonly
|
||
DBE000
|
stack
|
page read and write
|
||
140110000
|
unkown
|
page read and write
|
||
90000
|
heap
|
page read and write
|
||
2BB3000
|
heap
|
page read and write
|
||
911000
|
heap
|
page read and write
|
||
8D7000
|
heap
|
page read and write
|
||
904000
|
heap
|
page read and write
|
There are 51 hidden memdumps, click here to show them.