IOCReport

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\Lista produkt#U00f3w.exe
'C:\Users\user\Desktop\Lista produkt#U00f3w.exe'
malicious

URLs

Name
IP
Malicious
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://investor.msn.com/
unknown
clean

Memdumps

Base Address
Regiontype
Protect
Malicious
1D70000
unkown
page execute and read and write
malicious
3225000
unkown
page readonly
clean
401000
unkown image
page execute read
clean
2B30000
unkown
page readonly
clean
31D2000
unkown
page readonly
clean
3126000
unkown
page readonly
clean
7EFDF000
unkown
page read and write
clean
1CE0000
unkown
page read and write
clean
4C0000
heap default
page read and write
clean
3102000
unkown
page readonly
clean
3400000
unkown
page readonly
clean
3186000
unkown
page readonly
clean
2D0000
unkown
page readonly
clean
3B4000
heap private
page read and write
clean
4E4000
heap default
page read and write
clean
8E0000
unkown
page readonly
clean
400000
unkown image
page readonly
clean
2B50000
unkown
page readonly
clean
3094000
unkown
page readonly
clean
3192000
unkown
page readonly
clean
26F0000
heap private
page read and write
clean
414000
unkown image
page readonly
clean
30B4000
unkown
page readonly
clean
412000
unkown image
page read and write
clean
30B2000
unkown
page readonly
clean
3209000
unkown
page readonly
clean
2290000
unkown
page readonly
clean
3F0000
unkown
page read and write
clean
31B6000
unkown
page readonly
clean
26F4000
heap private
page read and write
clean
3156000
unkown
page readonly
clean
31D9000
unkown
page readonly
clean
1E58000
heap private
page read and write
clean
3092000
unkown
page readonly
clean
2712000
heap private
page read and write
clean
401000
unkown image
page execute read
clean
31B9000
unkown
page readonly
clean
3132000
unkown
page readonly
clean
30D2000
unkown
page readonly
clean
3162000
unkown
page readonly
clean
3B0000
heap private
page read and write
clean
33C2000
unkown
page readonly
clean
2730000
unkown
page read and write
clean
250000
heap default
page read and write
clean
2ED8000
unkown
page readonly
clean
3420000
unkown
page readonly
clean
3440000
unkown
page readonly
clean
8A000
unkown
page read and write
clean
30D4000
unkown
page readonly
clean
3239000
unkown
page readonly
clean
1B0000
unkown
page readonly
clean
3647000
unkown
page readonly
clean
1E90000
unkown
page read and write
clean
1E3A000
heap private
page read and write
clean
1E30000
heap private
page read and write
clean
240000
unkown
page readonly
clean
414000
unkown image
page readonly
clean
3B8000
heap private
page read and write
clean
3232000
unkown
page readonly
clean
740000
unkown
page readonly
clean
400000
unkown image
page readonly
clean
1DE0000
heap private
page read and write
clean
2FD2000
unkown
page readonly
clean
3175000
unkown
page readonly
clean
4C7000
heap default
page read and write
clean
3460000
unkown
page readonly
clean
420000
unkown
page read and write
clean
3BB000
heap private
page read and write
clean
1E80000
heap private
page read and write
clean
18D000
unkown
page read and write
clean
31A5000
unkown
page readonly
clean
5C0000
unkown
page readonly
clean
400000
unkown image
page readonly
clean
4A0000
unkown
page write copy
clean
3255000
unkown
page readonly
clean
20000
heap private
page read and write
clean
2ED2000
unkown
page readonly
clean
230000
unkown
page execute read
clean
3115000
unkown
page readonly
clean
31BD000
unkown
page readonly
clean
3145000
unkown
page readonly
clean
3202000
unkown
page readonly
clean
31F5000
unkown
page readonly
clean
There are 73 hidden memdumps, click here to show them.