IOCReport

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\faktura_fk.exe
'C:\Users\user\Desktop\faktura_fk.exe'
malicious

URLs

Name
IP
Malicious
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://investor.msn.com/
unknown
clean

Memdumps

Base Address
Regiontype
Protect
Malicious
2D0000
unkown
page execute and read and write
malicious
2DA8000
unkown
page readonly
clean
30A9000
unkown
page readonly
clean
6A0000
unkown
page readonly
clean
1B0000
unkown
page readonly
clean
2F62000
unkown
page readonly
clean
230000
unkown
page execute read
clean
32F0000
unkown
page readonly
clean
3330000
unkown
page readonly
clean
7EFDF000
unkown
page read and write
clean
3002000
unkown
page readonly
clean
240000
unkown
page readonly
clean
400000
unkown image
page readonly
clean
27C0000
heap private
page read and write
clean
3310000
unkown
page readonly
clean
3102000
unkown
page readonly
clean
3089000
unkown
page readonly
clean
9C0000
unkown
page readonly
clean
401000
unkown image
page execute read
clean
431000
unkown image
page read and write
clean
308D000
unkown
page readonly
clean
2FA4000
unkown
page readonly
clean
30A2000
unkown
page readonly
clean
1F04000
heap private
page read and write
clean
3032000
unkown
page readonly
clean
3125000
unkown
page readonly
clean
2A20000
unkown
page readonly
clean
5A0000
heap default
page read and write
clean
2F82000
unkown
page readonly
clean
3075000
unkown
page readonly
clean
1F60000
heap private
page read and write
clean
2FA2000
unkown
page readonly
clean
1F00000
heap private
page read and write
clean
3062000
unkown
page readonly
clean
30D9000
unkown
page readonly
clean
433000
unkown image
page readonly
clean
2FE5000
unkown
page readonly
clean
2A00000
unkown
page readonly
clean
3015000
unkown
page readonly
clean
5C4000
heap default
page read and write
clean
2F64000
unkown
page readonly
clean
520000
unkown
page read and write
clean
3056000
unkown
page readonly
clean
27E8000
heap private
page read and write
clean
3026000
unkown
page readonly
clean
30F5000
unkown
page readonly
clean
260000
unkown
page write copy
clean
250000
unkown
page read and write
clean
30D2000
unkown
page readonly
clean
401000
unkown image
page execute read
clean
20000
heap private
page read and write
clean
400000
unkown image
page readonly
clean
2FD2000
unkown
page readonly
clean
310000
heap default
page read and write
clean
27CA000
heap private
page read and write
clean
2F84000
unkown
page readonly
clean
278000
heap private
page read and write
clean
2EA2000
unkown
page readonly
clean
270000
heap private
page read and write
clean
433000
unkown image
page readonly
clean
29F0000
heap private
page read and write
clean
440000
unkown
page readonly
clean
5E1000
heap default
page read and write
clean
27FB000
heap private
page read and write
clean
1F22000
heap private
page read and write
clean
274000
heap private
page read and write
clean
27B000
heap private
page read and write
clean
18D000
unkown
page read and write
clean
3517000
unkown
page readonly
clean
2FF6000
unkown
page readonly
clean
8A000
unkown
page read and write
clean
5A7000
heap default
page read and write
clean
820000
unkown
page readonly
clean
32D0000
unkown
page readonly
clean
1F70000
unkown
page read and write
clean
30C5000
unkown
page readonly
clean
2370000
unkown
page readonly
clean
3086000
unkown
page readonly
clean
400000
unkown image
page readonly
clean
3045000
unkown
page readonly
clean
2DA2000
unkown
page readonly
clean
3292000
unkown
page readonly
clean
3109000
unkown
page readonly
clean
There are 73 hidden memdumps, click here to show them.