Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Windows\System32\wscript.exe
|
"C:\WINDOWS\system32\wscript.exe" Dark_Files\Cthulhu.vbs The_call 30000
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
1E09E820000
|
heap
|
page read and write
|
||
1E09CDD8000
|
heap
|
page read and write
|
||
7FFB226E5000
|
unkown
|
page readonly
|
||
7FFB226E0000
|
unkown
|
page read and write
|
||
7FFB226D6000
|
unkown
|
page readonly
|
||
1E09CE07000
|
heap
|
page read and write
|
||
7FFB226C1000
|
unkown
|
page execute read
|
||
1E09CDEC000
|
heap
|
page read and write
|
||
1E09CE07000
|
heap
|
page read and write
|
||
7FFB226C0000
|
unkown
|
page readonly
|
||
1E09CE0C000
|
heap
|
page read and write
|
||
1E0A0C00000
|
heap
|
page read and write
|
||
1E09CDF1000
|
heap
|
page read and write
|
||
1E09CE38000
|
heap
|
page read and write
|
||
1E09CDD0000
|
heap
|
page read and write
|
||
4C111FE000
|
stack
|
page read and write
|
||
4C110FD000
|
stack
|
page read and write
|
||
1E0A0400000
|
trusted library allocation
|
page read and write
|
||
1E09CE40000
|
heap
|
page read and write
|
||
4C113FF000
|
stack
|
page read and write
|
||
1E09CE23000
|
heap
|
page read and write
|
||
1E09CE12000
|
heap
|
page read and write
|
||
1E09CF8C000
|
heap
|
page read and write
|
||
1E09E824000
|
heap
|
page read and write
|
||
1E09CE40000
|
heap
|
page read and write
|
||
1E09CDB0000
|
heap
|
page read and write
|
||
1E09CE12000
|
heap
|
page read and write
|
||
1E09CF80000
|
heap
|
page read and write
|
||
1E09CE12000
|
heap
|
page read and write
|
||
1E0A02E0000
|
heap
|
page read and write
|
||
1E09CE07000
|
heap
|
page read and write
|
||
7FFB226E2000
|
unkown
|
page readonly
|
||
1E09CDFE000
|
heap
|
page read and write
|
||
1E09CE12000
|
heap
|
page read and write
|
||
1E09CE1C000
|
heap
|
page read and write
|
||
1E09CED0000
|
heap
|
page read and write
|
||
4C10DBA000
|
stack
|
page read and write
|
||
1E09CDFE000
|
heap
|
page read and write
|
||
1E09CCD0000
|
heap
|
page read and write
|
||
1E09CF85000
|
heap
|
page read and write
|
||
1E09CE18000
|
heap
|
page read and write
|
||
1E09CE0B000
|
heap
|
page read and write
|
||
1E09CDF1000
|
heap
|
page read and write
|
There are 33 hidden memdumps, click here to show them.