Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\plAI22fb26.exe
|
'C:\Users\user\Desktop\plAI22fb26.exe'
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
https://www.instagram.com/invertexto/
|
unknown
|
||
http://94.228.123.161/dashboard/
|
unknown
|
||
http://www.indyproject.org/
|
unknown
|
||
https://pagead2.goog
|
unknown
|
||
http://abrilprorock2018.webcindario.com/br/config.php
|
unknown
|
||
https://www.invertexto.com/
|
unknown
|
||
https://www.invertexto.com/aja
|
unknown
|
||
http://94.228.126.231/lending/
|
unknown
|
||
https://www.invertexto.com/img/face-note.png
|
unknown
|
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
www.invertexto.com
|
54.207.65.61
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
54.207.65.61
|
www.invertexto.com
|
United States
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\plAI22fb26.exe
|
AlphaColor
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
2AF77258000
|
unkown
|
page read and write
|
||
7FF57A1CA000
|
unkown image
|
page readonly
|
||
6070000
|
unkown
|
page read and write
|
||
1150000
|
unkown image
|
page write copy
|
||
7FF50213F000
|
unkown image
|
page readonly
|
||
7FF57A16C000
|
unkown image
|
page readonly
|
||
7DF58D930000
|
unkown image
|
page readonly
|
||
2A6D9702000
|
unkown
|
page read and write
|
||
2AF77200000
|
unkown
|
page read and write
|
||
7FF502194000
|
unkown image
|
page readonly
|
||
1ED537E0000
|
unkown
|
page read and write
|
||
7FF57B542000
|
unkown image
|
page readonly
|
||
1FEF7E90000
|
unkown image
|
page read and write
|
||
2A6DEC60000
|
unkown
|
page read and write
|
||
20D3EF60000
|
unkown image
|
page read and write
|
||
7FF57B62E000
|
unkown image
|
page readonly
|
||
2A6DEB70000
|
unkown
|
page read and write
|
||
7FF515DBA000
|
unkown image
|
page readonly
|
||
7FF5BB725000
|
unkown image
|
page readonly
|
||
1147000
|
unkown image
|
page read and write
|
||
1651000
|
heap default
|
page read and write
|
||
7FF5BB323000
|
unkown image
|
page readonly
|
||
1910A44A000
|
unkown
|
page read and write
|
||
7FF57A235000
|
unkown image
|
page readonly
|
||
7DF5283A0000
|
unkown image
|
page readonly
|
||
22A665F0000
|
unkown image
|
page readonly
|
||
11A4000
|
unkown image
|
page readonly
|
||
2A6DA570000
|
unkown
|
page read and write
|
||
1C2D47A0000
|
unkown
|
page read and write
|
||
7FF5FFFD0000
|
unkown image
|
page readonly
|
||
1C2D427D000
|
unkown
|
page read and write
|
||
2A6DEBD0000
|
unkown
|
page read and write
|
||
162B000
|
heap default
|
page read and write
|
||
20D3EFD0000
|
heap default
|
page read and write
|
||
7FF545ACE000
|
unkown image
|
page readonly
|
||
2A6D9F13000
|
unkown
|
page read and write
|
||
2A6DEC22000
|
unkown
|
page read and write
|
||
1C2D424D000
|
unkown
|
page read and write
|
||
2A6DED04000
|
unkown
|
page read and write
|
||
1055000
|
unkown image
|
page write copy
|
||
2A6D962A000
|
unkown
|
page read and write
|
||
2A6D9676000
|
unkown
|
page read and write
|
||
114E000
|
unkown image
|
page write copy
|
||
7FF579E62000
|
unkown image
|
page readonly
|
||
7FF5BB751000
|
unkown image
|
page readonly
|
||
2AF77780000
|
unkown image
|
page readonly
|
||
7FF5BB75C000
|
unkown image
|
page readonly
|
||
7FF57A1DC000
|
unkown image
|
page readonly
|
||
3C88000
|
unkown
|
page read and write
|
||
94BB1FB000
|
unkown
|
page read and write
|
||
180000
|
unkown
|
page read and write
|
||
7FF5BB667000
|
unkown image
|
page readonly
|
||
7FF5E8D6B000
|
unkown image
|
page readonly
|
||
1ED5387F000
|
unkown
|
page read and write
|
||
1626000
|
heap default
|
page read and write
|
||
7FF545D12000
|
unkown image
|
page readonly
|
||
65D2000
|
unkown
|
page read and write
|
||
7FF545B7E000
|
unkown image
|
page readonly
|
||
1910A2C0000
|
heap default
|
page read and write
|
||
1FEF8580000
|
unkown image
|
page readonly
|
||
59F137F000
|
unkown
|
page read and write
|
||
7FF5BB76C000
|
unkown image
|
page readonly
|