Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\rhc.exe
|
"C:\Users\user\Desktop\rhc.exe"
|
||
C:\Users\user\Desktop\rhc.exe
|
rhc.exe php.exe include.php
|
||
C:\Windows\System32\rundll32.exe
|
C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6}
-Embedding
|
||
C:\Windows\System32\cmd.exe
|
"C:\Windows\system32\cmd.exe"
|
||
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
641000
|
heap
|
page read and write
|
||
610000
|
heap
|
page read and write
|
||
648000
|
heap
|
page read and write
|
||
3B10000
|
heap
|
page read and write
|
||
1F0000
|
heap
|
page read and write
|
||
19C000
|
stack
|
page read and write
|
||
22EF000
|
stack
|
page read and write
|
||
646000
|
heap
|
page read and write
|
||
242F000
|
stack
|
page read and write
|
||
63D000
|
heap
|
page read and write
|
||
242B775E000
|
heap
|
page read and write
|
||
63B000
|
heap
|
page read and write
|
||
62E000
|
heap
|
page read and write
|
||
52E000
|
stack
|
page read and write
|
||
26C0000
|
heap
|
page read and write
|
||
242B7700000
|
heap
|
page read and write
|
||
4E0000
|
heap
|
page read and write
|
||
65F317E000
|
stack
|
page read and write
|
||
4E0000
|
heap
|
page read and write
|
||
653000
|
heap
|
page read and write
|
||
3EE0000
|
trusted library allocation
|
page read and write
|
||
248E000
|
stack
|
page read and write
|
||
63E000
|
heap
|
page read and write
|
||
2719000
|
heap
|
page read and write
|
||
870000
|
heap
|
page read and write
|
||
654000
|
heap
|
page read and write
|
||
258F000
|
stack
|
page read and write
|
||
61E000
|
heap
|
page read and write
|
||
636000
|
heap
|
page read and write
|
||
4F5000
|
heap
|
page read and write
|
||
72F000
|
stack
|
page read and write
|
||
242B7600000
|
heap
|
page read and write
|
||
633000
|
heap
|
page read and write
|
||
401000
|
unkown
|
page execute and write copy
|
||
4F0000
|
heap
|
page read and write
|
||
53E000
|
stack
|
page read and write
|
||
9BF000
|
stack
|
page read and write
|
||
242B7985000
|
heap
|
page read and write
|
||
61A000
|
heap
|
page read and write
|
||
64C000
|
heap
|
page read and write
|
||
242B76E0000
|
heap
|
page read and write
|
||
2710000
|
heap
|
page read and write
|
||
638000
|
heap
|
page read and write
|
||
242B92D0000
|
heap
|
page read and write
|
||
57E000
|
stack
|
page read and write
|
||
63E000
|
heap
|
page read and write
|
||
5BE000
|
stack
|
page read and write
|
||
80F000
|
stack
|
page read and write
|
||
64E000
|
heap
|
page read and write
|
||
3B14000
|
heap
|
page read and write
|
||
242B7980000
|
heap
|
page read and write
|
||
658000
|
heap
|
page read and write
|
||
8BE000
|
stack
|
page read and write
|
||
90F000
|
stack
|
page read and write
|
||
76E000
|
stack
|
page read and write
|
||
654000
|
heap
|
page read and write
|
||
2430000
|
heap
|
page read and write
|
||
401000
|
unkown
|
page execute and read and write
|
||
2715000
|
heap
|
page read and write
|
||
9C000
|
stack
|
page read and write
|
||
637000
|
heap
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
65F30FE000
|
stack
|
page read and write
|
||
63A000
|
heap
|
page read and write
|
||
63A000
|
heap
|
page read and write
|
||
65F307C000
|
stack
|
page read and write
|
||
242B7750000
|
heap
|
page read and write
|
||
530000
|
heap
|
page read and write
|
||
631000
|
heap
|
page read and write
|
||
637000
|
heap
|
page read and write
|
||
62A000
|
heap
|
page read and write
|
||
232E000
|
stack
|
page read and write
|
||
63D000
|
heap
|
page read and write
|
||
63D000
|
heap
|
page read and write
|
||
26B0000
|
heap
|
page read and write
|
||
9A000
|
stack
|
page read and write
|
||
86F000
|
stack
|
page read and write
|
||
636000
|
heap
|
page read and write
|
||
641000
|
heap
|
page read and write
|
||
65F31FE000
|
stack
|
page read and write
|
||
A0E000
|
stack
|
page read and write
|
||
19D000
|
stack
|
page read and write
|
||
63E000
|
heap
|
page read and write
|
||
1F0000
|
heap
|
page read and write
|
||
632000
|
heap
|
page read and write
|
||
21EE000
|
stack
|
page read and write
|
||
242B7758000
|
heap
|
page read and write
|
||
637000
|
heap
|
page read and write
|
||
656000
|
heap
|
page read and write
|
||
538000
|
heap
|
page read and write
|
There are 80 hidden memdumps, click here to show them.