Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
SecuriteInfo.com.Trojan.GenericKD.71965879.10556.925.exe
|
PE32+ executable (console) x86-64, for MS Windows
|
initial sample
|
||
\Device\ConDrv
|
ASCII text, with CRLF line terminators
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.71965879.10556.925.exe
|
"C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.71965879.10556.925.exe"
|
||
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
https://www.sysinternals.com0
|
unknown
|
||
http://www.microsoft.co
|
unknown
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
HKEY_CURRENT_USER\SOFTWARE\Sysinternals\????????.
|
EulaAccepted
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
288AAC45000
|
heap
|
page read and write
|
||
288AAA84000
|
heap
|
page read and write
|
||
9595CFE000
|
stack
|
page read and write
|
||
288AAB60000
|
heap
|
page read and write
|
||
288AAA69000
|
heap
|
page read and write
|
||
7FF7D95A6000
|
unkown
|
page readonly
|
||
288AC820000
|
trusted library allocation
|
page read and write
|
||
288AE120000
|
trusted library allocation
|
page read and write
|
||
288AAA70000
|
heap
|
page read and write
|
||
7FF7D95A6000
|
unkown
|
page readonly
|
||
7FF7D958A000
|
unkown
|
page readonly
|
||
288AAA73000
|
heap
|
page read and write
|
||
7FF7D95A3000
|
unkown
|
page read and write
|
||
288AABB0000
|
heap
|
page read and write
|
||
288AAA6C000
|
heap
|
page read and write
|
||
288AAA4C000
|
heap
|
page read and write
|
||
288AABE0000
|
heap
|
page read and write
|
||
95959FE000
|
stack
|
page read and write
|
||
288AAC20000
|
heap
|
page read and write
|
||
288AAA8C000
|
heap
|
page read and write
|
||
288AAC40000
|
heap
|
page read and write
|
||
95958FA000
|
stack
|
page read and write
|
||
7FF7D95A9000
|
unkown
|
page readonly
|
||
7FF7D9560000
|
unkown
|
page readonly
|
||
288AAA87000
|
heap
|
page read and write
|
||
7FF7D958A000
|
unkown
|
page readonly
|
||
9595BFE000
|
stack
|
page read and write
|
||
7FF7D95A3000
|
unkown
|
page write copy
|
||
7FF7D9561000
|
unkown
|
page execute read
|
||
288AC820000
|
heap
|
page read and write
|
||
288AAAA4000
|
heap
|
page read and write
|
||
7FF7D9560000
|
unkown
|
page readonly
|
||
288AAA6C000
|
heap
|
page read and write
|
||
288AA960000
|
heap
|
page read and write
|
||
288AABB4000
|
heap
|
page read and write
|
||
288AAA8C000
|
heap
|
page read and write
|
||
288AAA9B000
|
heap
|
page read and write
|
||
288AAA82000
|
heap
|
page read and write
|
||
9595AFE000
|
stack
|
page read and write
|
||
288AAA68000
|
heap
|
page read and write
|
||
288AAA40000
|
heap
|
page read and write
|
||
288AAB40000
|
heap
|
page read and write
|
||
7FF7D95A9000
|
unkown
|
page readonly
|
||
288AAA95000
|
heap
|
page read and write
|
||
288AAA70000
|
heap
|
page read and write
|
||
7FF7D9561000
|
unkown
|
page execute read
|
||
288AAC4B000
|
heap
|
page read and write
|
||
288AAA74000
|
heap
|
page read and write
|
||
288AAA9B000
|
heap
|
page read and write
|
There are 39 hidden memdumps, click here to show them.