Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
C:\Users\user\Downloads\Unconfirmed 293673.crdownload
|
PE32+ executable (GUI) x86-64, for MS Windows
|
dropped
|
||
C:\Users\user\Downloads\hp-hpia-5.2.1.exe (copy)
|
PE32+ executable (GUI) x86-64, for MS Windows
|
dropped
|
||
Chrome Cache Entry: 43
|
PE32+ executable (GUI) x86-64, for MS Windows
|
downloaded
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US
--service-sandbox-type=none --mojo-platform-channel-handle=1884 --field-trial-handle=2520,i,9680638350717332926,39774128382146307,262144
--disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction
/prefetch:8
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://hpia.hpcloud.hp.com/downloads/hpia/hp-hpia-5.2.1.exe"
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilReadIcon --lang=en-US
--service-sandbox-type=icon_reader --mojo-platform-channel-handle=5416 --field-trial-handle=2520,i,9680638350717332926,39774128382146307,262144
--disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction
/prefetch:8
|
||
C:\Users\user\Downloads\hp-hpia-5.2.1.exe
|
"C:\Users\user\Downloads\hp-hpia-5.2.1.exe"
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
https://hpia.hpcloud.hp.com/downloads/hpia/hp-hpia-5.2.1.exe
|
|||
https://hpia.hpcloud.hp.com/downloads/hpia/hp-hpia-5.2.1.exe
|
18.160.60.98
|
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
hpia.hpcloud.hp.com
|
18.160.60.98
|
||
www.google.com
|
64.233.177.99
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
239.255.255.250
|
unknown
|
Reserved
|
||
18.160.60.98
|
hpia.hpcloud.hp.com
|
United States
|
||
192.168.2.4
|
unknown
|
unknown
|
||
64.233.177.99
|
www.google.com
|
United States
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
7FF649E5A000
|
unkown
|
page readonly
|
||
A88F8EE000
|
stack
|
page read and write
|
||
22EC72F0000
|
trusted library section
|
page read and write
|
||
22EC5AA1000
|
heap
|
page read and write
|
||
7FF649E55000
|
unkown
|
page read and write
|
||
7FF649DD1000
|
unkown
|
page execute read
|
||
22EC5ABA000
|
heap
|
page read and write
|
||
7FF649DD1000
|
unkown
|
page execute read
|
||
7FF649DD0000
|
unkown
|
page readonly
|
||
22EC5A5C000
|
heap
|
page read and write
|
||
22EC5AA2000
|
heap
|
page read and write
|
||
22EC7E09000
|
heap
|
page read and write
|
||
22EC74D0000
|
heap
|
page read and write
|
||
22EC5A9E000
|
heap
|
page read and write
|
||
7FF649E31000
|
unkown
|
page readonly
|
||
22EC5A50000
|
heap
|
page read and write
|
||
22EC7310000
|
trusted library section
|
page read and write
|
||
22EC74C0000
|
heap
|
page read and write
|
||
22EC58D0000
|
heap
|
page read and write
|
||
22EC7673000
|
heap
|
page read and write
|
||
22EC7672000
|
heap
|
page read and write
|
||
7FF649E53000
|
unkown
|
page read and write
|
||
22EC7393000
|
heap
|
page read and write
|
||
22EC5AB9000
|
heap
|
page read and write
|
||
7FF649E53000
|
unkown
|
page write copy
|
||
22EC7350000
|
heap
|
page read and write
|
||
7FF649E54000
|
unkown
|
page write copy
|
||
22EC7E00000
|
heap
|
page read and write
|
||
22EC7340000
|
heap
|
page read and write
|
||
A88F8F7000
|
stack
|
page read and write
|
||
22EC5A8E000
|
heap
|
page read and write
|
||
22EC74D4000
|
heap
|
page read and write
|
||
22EC7670000
|
heap
|
page read and write
|
||
22EC7390000
|
heap
|
page read and write
|
||
22EC5A59000
|
heap
|
page read and write
|
||
7FF649DD0000
|
unkown
|
page readonly
|
||
22EC5A8E000
|
heap
|
page read and write
|
||
7FF649E31000
|
unkown
|
page readonly
|
||
22EC59B0000
|
heap
|
page read and write
|
||
A88FAFE000
|
stack
|
page read and write
|
||
A88F9FE000
|
stack
|
page read and write
|
||
22EC74C5000
|
heap
|
page read and write
|
||
22EC5A92000
|
heap
|
page read and write
|
||
22EC5AD7000
|
heap
|
page read and write
|
||
22EC5A8E000
|
heap
|
page read and write
|
||
22EC7671000
|
heap
|
page read and write
|
||
7FF649E5A000
|
unkown
|
page readonly
|
||
22EC9160000
|
trusted library allocation
|
page read and write
|
||
22EC59E0000
|
heap
|
page read and write
|
||
A88FBFE000
|
stack
|
page read and write
|
||
22EC5A82000
|
heap
|
page read and write
|
||
22EC7300000
|
trusted library section
|
page read and write
|
There are 42 hidden memdumps, click here to show them.