Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
SecuriteInfo.com.Trojan.Win32.Krypt.14164.25813.exe
|
PE32 executable (console) Intel 80386, for MS Windows
|
initial sample
|
||
\Device\ConDrv
|
ASCII text, with CRLF line terminators
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win32.Krypt.14164.25813.exe
|
"C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win32.Krypt.14164.25813.exe"
|
||
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://jd.sscltan.com/jd/tp1.txthttp://jd.sscltan.com/jd/tp2.txt
|
unknown
|
||
http://jd.sscltan.com/jd/sscjh.txt
|
unknown
|
||
http://jd.sscltan.com/jd/tp2.txt
|
unknown
|
||
http://jd.sscltan.com/jd/zgg.txt
|
unknown
|
||
http://jd.sscltan.com/jd/tp1.txt
|
unknown
|
||
https://http://=deletedUTF-8GBKAdodb.StreamTypeWritePositionCharsetReadTextCloseWriteTextRead
|
unknown
|
||
http://www.sscltan.comhttp://jd.sscltan.com/jd/zgg.txt
|
unknown
|
||
http://img1.tbcdn.cn/tfscom/T1ouC2FdpbXXXtxVjX.swf
|
unknown
|
||
http://www.sscltan.com
|
unknown
|
||
http://s104.cnzz.com/stat.php?id=1935778&web_id=1935778
|
unknown
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
1000000
|
unkown
|
page readonly
|
||
1CF000
|
stack
|
page read and write
|
||
1000000
|
unkown
|
page readonly
|
||
12D4000
|
unkown
|
page readonly
|
||
67F000
|
stack
|
page read and write
|
||
1E0000
|
heap
|
page read and write
|
||
54A000
|
heap
|
page read and write
|
||
1001000
|
unkown
|
page execute read
|
||
12D4000
|
unkown
|
page readonly
|
||
9C000
|
stack
|
page read and write
|
||
1001000
|
unkown
|
page execute read
|
||
130000
|
heap
|
page read and write
|
||
540000
|
heap
|
page read and write
|
||
140000
|
heap
|
page read and write
|
||
6C0000
|
heap
|
page read and write
|
||
18E000
|
stack
|
page read and write
|
||
DD000
|
stack
|
page read and write
|
||
54E000
|
heap
|
page read and write
|
||
50E000
|
stack
|
page read and write
|
There are 9 hidden memdumps, click here to show them.