Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\SecuriteInfo.com.Win32.TrojanX-gen.14399.1813.exe
|
"C:\Users\user\Desktop\SecuriteInfo.com.Win32.TrojanX-gen.14399.1813.exe"
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
https://www.clubedasluluzinhasro.com.br/assets/image
|
unknown
|
||
http://79.124.78.45/hockamore.php%temp%
|
unknown
|
||
https://www.clubedasluluzinhasro.com.br/assets/image/c
|
unknown
|
||
http://79.124.78.45/hockamore.php
|
unknown
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
2B81000
|
direct allocation
|
page execute read
|
||
FBE000
|
stack
|
page read and write
|
||
2B80000
|
direct allocation
|
page readonly
|
||
100A000
|
heap
|
page read and write
|
||
FFE000
|
stack
|
page read and write
|
||
F60000
|
heap
|
page read and write
|
||
90A000
|
unkown
|
page readonly
|
||
2B8C000
|
direct allocation
|
page execute and read and write
|
||
8F1000
|
unkown
|
page execute read
|
||
2CC0000
|
heap
|
page read and write
|
||
BEC000
|
stack
|
page read and write
|
||
8F0000
|
unkown
|
page readonly
|
||
13CE000
|
stack
|
page read and write
|
||
F70000
|
heap
|
page read and write
|
||
8F0000
|
unkown
|
page readonly
|
||
EFC000
|
stack
|
page read and write
|
||
F50000
|
heap
|
page read and write
|
||
901000
|
unkown
|
page readonly
|
||
8F1000
|
unkown
|
page execute read
|
||
100E000
|
heap
|
page read and write
|
||
2B8B000
|
direct allocation
|
page readonly
|
||
901000
|
unkown
|
page readonly
|
||
908000
|
unkown
|
page write copy
|
||
90A000
|
unkown
|
page readonly
|
||
1000000
|
heap
|
page read and write
|
||
908000
|
unkown
|
page read and write
|
||
12CE000
|
stack
|
page read and write
|
There are 17 hidden memdumps, click here to show them.