Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\faktura_fk.exe
|
'C:\Users\user\Desktop\faktura_fk.exe'
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
|
unknown
|
||
http://www.windows.com/pctv.
|
unknown
|
||
http://investor.msn.com
|
unknown
|
||
http://www.msnbc.com/news/ticker.txt
|
unknown
|
||
http://www.icra.org/vocabulary/.
|
unknown
|
||
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
|
unknown
|
||
http://www.hotmail.com/oe
|
unknown
|
||
http://investor.msn.com/
|
unknown
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
2D0000
|
unkown
|
page execute and read and write
|
||
2DA8000
|
unkown
|
page readonly
|
||
30A9000
|
unkown
|
page readonly
|
||
6A0000
|
unkown
|
page readonly
|
||
1B0000
|
unkown
|
page readonly
|
||
2F62000
|
unkown
|
page readonly
|
||
230000
|
unkown
|
page execute read
|
||
32F0000
|
unkown
|
page readonly
|
||
3330000
|
unkown
|
page readonly
|
||
7EFDF000
|
unkown
|
page read and write
|
||
3002000
|
unkown
|
page readonly
|
||
240000
|
unkown
|
page readonly
|
||
400000
|
unkown image
|
page readonly
|
||
27C0000
|
heap private
|
page read and write
|
||
3310000
|
unkown
|
page readonly
|
||
3102000
|
unkown
|
page readonly
|
||
3089000
|
unkown
|
page readonly
|
||
9C0000
|
unkown
|
page readonly
|
||
401000
|
unkown image
|
page execute read
|
||
431000
|
unkown image
|
page read and write
|
||
308D000
|
unkown
|
page readonly
|
||
2FA4000
|
unkown
|
page readonly
|
||
30A2000
|
unkown
|
page readonly
|
||
1F04000
|
heap private
|
page read and write
|
||
3032000
|
unkown
|
page readonly
|
||
3125000
|
unkown
|
page readonly
|
||
2A20000
|
unkown
|
page readonly
|
||
5A0000
|
heap default
|
page read and write
|
||
2F82000
|
unkown
|
page readonly
|
||
3075000
|
unkown
|
page readonly
|
||
1F60000
|
heap private
|
page read and write
|
||
2FA2000
|
unkown
|
page readonly
|
||
1F00000
|
heap private
|
page read and write
|
||
3062000
|
unkown
|
page readonly
|
||
30D9000
|
unkown
|
page readonly
|
||
433000
|
unkown image
|
page readonly
|
||
2FE5000
|
unkown
|
page readonly
|
||
2A00000
|
unkown
|
page readonly
|
||
3015000
|
unkown
|
page readonly
|
||
5C4000
|
heap default
|
page read and write
|
||
2F64000
|
unkown
|
page readonly
|
||
520000
|
unkown
|
page read and write
|
||
3056000
|
unkown
|
page readonly
|
||
27E8000
|
heap private
|
page read and write
|
||
3026000
|
unkown
|
page readonly
|
||
30F5000
|
unkown
|
page readonly
|
||
260000
|
unkown
|
page write copy
|
||
250000
|
unkown
|
page read and write
|
||
30D2000
|
unkown
|
page readonly
|
||
401000
|
unkown image
|
page execute read
|
||
20000
|
heap private
|
page read and write
|
||
400000
|
unkown image
|
page readonly
|
||
2FD2000
|
unkown
|
page readonly
|
||
310000
|
heap default
|
page read and write
|
||
27CA000
|
heap private
|
page read and write
|
||
2F84000
|
unkown
|
page readonly
|
||
278000
|
heap private
|
page read and write
|
||
2EA2000
|
unkown
|
page readonly
|
||
270000
|
heap private
|
page read and write
|
||
433000
|
unkown image
|
page readonly
|
||
29F0000
|
heap private
|
page read and write
|
||
440000
|
unkown
|
page readonly
|
||
5E1000
|
heap default
|
page read and write
|
||
27FB000
|
heap private
|
page read and write
|
||
1F22000
|
heap private
|
page read and write
|
||
274000
|
heap private
|
page read and write
|
||
27B000
|
heap private
|
page read and write
|
||
18D000
|
unkown
|
page read and write
|
||
3517000
|
unkown
|
page readonly
|
||
2FF6000
|
unkown
|
page readonly
|
||
8A000
|
unkown
|
page read and write
|
||
5A7000
|
heap default
|
page read and write
|
||
820000
|
unkown
|
page readonly
|
||
32D0000
|
unkown
|
page readonly
|
||
1F70000
|
unkown
|
page read and write
|
||
30C5000
|
unkown
|
page readonly
|
||
2370000
|
unkown
|
page readonly
|
||
3086000
|
unkown
|
page readonly
|
||
400000
|
unkown image
|
page readonly
|
||
3045000
|
unkown
|
page readonly
|
||
2DA2000
|
unkown
|
page readonly
|
||
3292000
|
unkown
|
page readonly
|
||
3109000
|
unkown
|
page readonly
|
There are 73 hidden memdumps, click here to show them.