Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\YBuzMywtqU.exe
|
"C:\Users\user\Desktop\YBuzMywtqU.exe"
|
||
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
https://login.microsoftonline.com/
|
unknown
|
||
https://login.microsoftonline.com/error?code=70000
|
unknown
|
||
https://login.microsoftonline.com/8/I
|
unknown
|
||
http://crl.micro
|
unknown
|
||
http://crl.microsoft
|
unknown
|
||
https://login.microsoftonline.com/common/oauth2/v2.0/token0
|
unknown
|
||
https://login.microsoftonline.com/osoftonline.com/5)6
|
unknown
|
||
https://login.microsoftonline.com/common/oauth2/v2.0/token03
|
unknown
|
||
https://login.microsoftonline.com/common/oauth2/v2.0/tokenK-
|
unknown
|
||
https://login.microsoftonline.com/common/oauth2/v2.0/tokenlt
|
unknown
|
||
https://login.microsoftonline.com/common/oauth2/v2.0/tokenSY
|
unknown
|
||
https://login.microsoftonline.com/common/oauth2/v2.0/tokenou
|
unknown
|
||
https://login.microsoftonline.com/common/oauth2/v2.0/tokenltificate
|
unknown
|
||
https://login.microsoftonline.com/common/oauth2/v2.0/token3-
|
unknown
|
||
https://login.microsoftonline.com/common/oauth2/v2.0/token
|
unknown
|
There are 5 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
login.microsoftonline.com
|
unknown
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive
|
GrimiApplication
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
5A4000
|
heap
|
page read and write
|
||
140000000
|
unkown
|
page readonly
|
||
2170000
|
heap
|
page read and write
|
||
5C4000
|
heap
|
page read and write
|
||
1C0000
|
heap
|
page read and write
|
||
587000
|
heap
|
page read and write
|
||
5F2000
|
heap
|
page read and write
|
||
140149000
|
unkown
|
page write copy
|
||
5BC000
|
heap
|
page read and write
|
||
1FF5000
|
heap
|
page read and write
|
||
140178000
|
unkown
|
page readonly
|
||
606000
|
heap
|
page read and write
|
||
2140000
|
unkown
|
page execute read
|
||
5EE000
|
heap
|
page read and write
|
||
2CCB000
|
unkown
|
page read and write
|
||
140166000
|
unkown
|
page readonly
|
||
534000
|
heap
|
page read and write
|
||
2CC5000
|
unkown
|
page read and write
|
||
2BBF000
|
stack
|
page read and write
|
||
2CBF000
|
stack
|
page read and write
|
||
14C000
|
stack
|
page read and write
|
||
2CCA000
|
unkown
|
page read and write
|
||
140166000
|
unkown
|
page readonly
|
||
2160000
|
unkown
|
page execute read
|
||
2140000
|
unkown
|
page read and write
|
||
1E0000
|
heap
|
page read and write
|
||
14015A000
|
unkown
|
page read and write
|
||
581000
|
heap
|
page read and write
|
||
5C4000
|
heap
|
page read and write
|
||
587000
|
heap
|
page read and write
|
||
5F3000
|
heap
|
page read and write
|
||
140119000
|
unkown
|
page readonly
|
||
190000
|
heap
|
page read and write
|
||
2CCB000
|
unkown
|
page read and write
|
||
140001000
|
unkown
|
page execute read
|
||
28BF000
|
stack
|
page read and write
|
||
5EE000
|
heap
|
page read and write
|
||
510000
|
heap
|
page read and write
|
||
180000
|
heap
|
page read and write
|
||
55B000
|
heap
|
page read and write
|
||
29BD000
|
stack
|
page read and write
|
||
20F6000
|
stack
|
page read and write
|
||
140119000
|
unkown
|
page readonly
|
||
51C000
|
heap
|
page read and write
|
||
2CC0000
|
unkown
|
page read and write
|
||
5BC000
|
heap
|
page read and write
|
||
2140000
|
remote allocation
|
page read and write
|
||
565000
|
heap
|
page read and write
|
||
5A4000
|
heap
|
page read and write
|
||
27BE000
|
stack
|
page read and write
|
||
140178000
|
unkown
|
page readonly
|
||
140001000
|
unkown
|
page execute read
|
||
5F0000
|
heap
|
page read and write
|
||
559000
|
heap
|
page read and write
|
||
556000
|
heap
|
page read and write
|
||
5F2000
|
heap
|
page read and write
|
||
2140000
|
remote allocation
|
page read and write
|
||
2ABB000
|
stack
|
page read and write
|
||
2140000
|
remote allocation
|
page read and write
|
||
1FF0000
|
heap
|
page read and write
|
||
140149000
|
unkown
|
page read and write
|
||
606000
|
heap
|
page read and write
|
||
26BF000
|
stack
|
page read and write
|
||
5EE000
|
heap
|
page read and write
|
||
140000000
|
unkown
|
page read and write
|
||
5BC000
|
heap
|
page read and write
|
||
5F0000
|
heap
|
page read and write
|
||
140152000
|
unkown
|
page read and write
|
||
5EE000
|
heap
|
page read and write
|
There are 59 hidden memdumps, click here to show them.