Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\Evolution des moyens de trasport.exe
|
'C:\Users\user\Desktop\Evolution des moyens de trasport.exe'
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://127.0.0.1:
|
unknown
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
61E000
|
unkown image
|
page readonly
|
||
401000
|
unkown image
|
page execute read
|
||
3E8000
|
unkown
|
page read and write
|
||
504000
|
unkown image
|
page execute read
|
||
2D59000
|
heap private
|
page read and write
|
||
448000
|
unkown image
|
page execute read
|
||
7C0000
|
heap default
|
page read and write
|
||
5C1000
|
unkown image
|
page readonly
|
||
5B5000
|
unkown image
|
page read and write
|
||
4D0000
|
unkown image
|
page execute read
|
||
45B000
|
unkown image
|
page execute read
|
||
930000
|
heap default
|
page read and write
|
||
4A6000
|
unkown image
|
page execute read
|
||
7B0000
|
unkown
|
page execute read
|
||
504000
|
unkown image
|
page execute read
|
||
5C1000
|
unkown image
|
page readonly
|
||
4D0000
|
unkown image
|
page execute read
|
||
78E000
|
unkown
|
page read and write
|
||
953000
|
unkown
|
page read and write
|
||
B2F000
|
stack
|
page read and write
|
||
8CF000
|
stack
|
page read and write
|
||
2490000
|
heap private
|
page read and write
|
||
4A1000
|
unkown image
|
page execute read
|
||
401000
|
unkown image
|
page execute read
|
||
49F000
|
unkown image
|
page execute read
|
||
7A0000
|
unkown
|
page read and write
|
||
49F000
|
unkown image
|
page execute read
|
||
790000
|
unkown
|
page readonly
|
||
8F0000
|
unkown
|
page read and write
|
||
441000
|
unkown image
|
page execute read
|
||
625000
|
unkown image
|
page readonly
|
||
400000
|
unkown image
|
page readonly
|
||
4AD000
|
unkown image
|
page execute read
|
||
2F00000
|
heap private
|
page read and write
|
||
61A000
|
unkown image
|
page readonly
|
||
700000
|
unkown
|
page read and write
|
||
44E000
|
unkown image
|
page execute read
|
||
95E000
|
unkown
|
page read and write
|
||
61A000
|
unkown image
|
page readonly
|
||
4C0000
|
unkown image
|
page execute read
|
||
625000
|
unkown image
|
page readonly
|
||
46C000
|
unkown image
|
page execute read
|
||
4A1000
|
unkown image
|
page execute read
|
||
93A000
|
heap default
|
page read and write
|
||
60D000
|
unkown image
|
page readonly
|
||
45B000
|
unkown image
|
page execute read
|
||
441000
|
unkown image
|
page execute read
|
||
46C000
|
unkown image
|
page execute read
|
||
24A0000
|
unkown
|
page read and write
|
||
B30000
|
unkown
|
page readonly
|
||
60D000
|
unkown image
|
page readonly
|
||
900000
|
unkown
|
page read and write
|
||
2400000
|
heap private
|
page read and write
|
||
44E000
|
unkown image
|
page execute read
|
||
22D0000
|
unkown
|
page read and write
|
||
630000
|
unkown
|
page readonly
|
||
94F000
|
unkown
|
page read and write
|
||
61E000
|
unkown image
|
page readonly
|
||
4C0000
|
unkown image
|
page execute read
|
||
400000
|
unkown image
|
page readonly
|
||
4AD000
|
unkown image
|
page execute read
|
||
448000
|
unkown image
|
page execute read
|
||
19C000
|
stack
|
page read and write
|
||
28A0000
|
unkown
|
page readonly
|
||
4B3000
|
unkown image
|
page execute read
|
||
74E000
|
unkown
|
page read and write
|
||
4A6000
|
unkown image
|
page execute read
|
||
9C000
|
unkown
|
page read and write
|
||
400000
|
unkown image
|
page readonly
|
||
95A000
|
unkown
|
page read and write
|
||
3E4000
|
unkown
|
page read and write
|
||
948000
|
unkown
|
page read and write
|
||
4B3000
|
unkown image
|
page execute read
|
||
2D50000
|
heap private
|
page read and write
|
There are 64 hidden memdumps, click here to show them.