Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\6qr4g3TReL.exe
|
"C:\Users\user\Desktop\6qr4g3TReL.exe"
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://www.google.com/webhp
|
unknown
|
||
http://www.google.com/webhpbcSeTcbPrivilege.exeSOFTWARE
|
unknown
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
406000
|
unkown
|
page readonly
|
||
560000
|
heap
|
page read and write
|
||
41D000
|
unkown
|
page execute and write copy
|
||
67C23EE000
|
unkown
|
page read and write
|
||
174B2560000
|
unkown
|
page readonly
|
||
174B2629000
|
unkown
|
page read and write
|
||
174B2800000
|
unkown
|
page readonly
|
||
405000
|
unkown
|
page write copy
|
||
500000
|
trusted library allocation
|
page read and write
|
||
174B2653000
|
unkown
|
page read and write
|
||
5E0000
|
direct allocation
|
page execute and read and write
|
||
30000
|
heap
|
page read and write
|
||
174B2B80000
|
unkown
|
page readonly
|
||
5C0000
|
direct allocation
|
page execute and read and write
|
||
67C267F000
|
unkown
|
page read and write
|
||
2280000
|
heap
|
page read and write
|
||
5AE000
|
stack
|
page read and write
|
||
423000
|
direct allocation
|
page execute and read and write
|
||
174B3FA0000
|
unkown
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
174B2B90000
|
unkown
|
page readonly
|
||
5D0000
|
heap
|
page read and write
|
||
174B2A00000
|
unkown
|
page readonly
|
||
400000
|
direct allocation
|
page execute and read and write
|
||
565000
|
heap
|
page read and write
|
||
41F000
|
unkown
|
page readonly
|
||
67C236D000
|
stack
|
page read and write
|
||
174B2500000
|
unkown
|
page write copy
|
||
174B264E000
|
unkown
|
page read and write
|
||
9C000
|
stack
|
page read and write
|
||
174B2609000
|
unkown
|
page read and write
|
||
174B2420000
|
heap
|
page read and write
|
||
174B23C0000
|
heap
|
page read and write
|
||
174B2600000
|
unkown
|
page read and write
|
||
174B23B0000
|
heap
|
page read and write
|
||
174B2550000
|
unkown
|
page readonly
|
||
21A0000
|
heap
|
page read and write
|
||
174B2613000
|
unkown
|
page read and write
|
||
84F000
|
stack
|
page read and write
|
||
67C26FE000
|
unkown
|
page read and write
|
||
174B261F000
|
unkown
|
page read and write
|
||
404000
|
unkown
|
page readonly
|
||
54E000
|
stack
|
page read and write
|
||
5C0000
|
direct allocation
|
page execute and read and write
|
||
65A000
|
heap
|
page read and write
|
||
650000
|
heap
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
5B0000
|
heap
|
page read and write
|
||
174B2702000
|
unkown
|
page read and write
|
||
19C000
|
stack
|
page read and write
|
||
174B2632000
|
unkown
|
page read and write
|
||
174B2602000
|
unkown
|
page read and write
|
||
94F000
|
stack
|
page read and write
|
There are 43 hidden memdumps, click here to show them.