Hancitor Malware | Grouped Behavior
Try VMRay Analyzer
Involved Hosts
Host Resolved to Country City Protocol
foandrenla.com
Monitored Processes
Behavior Information - Grouped by Category
Process #1: winword.exe
(Host: 4996, Network: 0)
+
Information Value
ID / OS PID #1 / 0x85c
OS Parent PID 0x454 (c:\windows\explorer.exe)
Initial Working Directory C:\Windows\system32
File Name c:\program files (x86)\microsoft office\root\office16\winword.exe
Command Line "C:\Program Files (x86)\Microsoft Office\Root\Office16\WINWORD.EXE"
Monitor Start Time: 00:00:12, Reason: Analysis Target
Unmonitor End Time: 00:02:22, Reason: Terminated by Timeout
Monitor Duration 00:02:10
OS Thread IDs
# 1
0x 8D4
# 2
0x 8D0
# 3
0x 8CC
# 4
0x 8C8
# 5
0x 8C4
# 6
0x 8C0
# 7
0x 8BC
# 8
0x 8B8
# 9
0x 8B4
# 10
0x 8A8
# 11
0x 8A0
# 12
0x 89C
# 13
0x 860
# 14
0x 8D8
# 15
0x 8E4
# 16
0x 8E8
# 17
0x 8EC
# 18
0x 8F0
# 19
0x 96C
# 21
0x 9A0
# 81
0x 808
# 82
0x 7F4
# 83
0x B64
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable False False False
pagefile_0x0000000000020000 0x00020000 0x00020fff Pagefile Backed Memory Readable False False False
pagefile_0x0000000000030000 0x00030000 0x00030fff Pagefile Backed Memory Readable False False False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000050000 0x00050000 0x00053fff Pagefile Backed Memory Readable False False False
pagefile_0x0000000000060000 0x00060000 0x00063fff Pagefile Backed Memory Readable False False False
private_0x0000000000070000 0x00070000 0x0007ffff Private Memory Readable, Writable False False False
private_0x0000000000080000 0x00080000 0x000bffff Private Memory Readable, Writable False False False
private_0x00000000000c0000 0x000c0000 0x000c0fff Private Memory Readable, Writable False False False
private_0x00000000000d0000 0x000d0000 0x000d0fff Private Memory Readable, Writable False False False
pagefile_0x00000000000e0000 0x000e0000 0x000e0fff Pagefile Backed Memory Readable, Writable False False False
private_0x00000000000f0000 0x000f0000 0x001effff Private Memory Readable, Writable False False False
locale.nls 0x001f0000 0x00256fff Memory Mapped File Readable False False False
pagefile_0x0000000000260000 0x00260000 0x00266fff Pagefile Backed Memory Readable False False False
pagefile_0x0000000000270000 0x00270000 0x00271fff Pagefile Backed Memory Readable, Writable False False False
private_0x0000000000280000 0x00280000 0x00280fff Private Memory Readable, Writable False False False
private_0x0000000000290000 0x00290000 0x00290fff Private Memory Readable, Writable False False False
pagefile_0x00000000002a0000 0x002a0000 0x002a1fff Pagefile Backed Memory Readable False False False
pagefile_0x00000000002b0000 0x002b0000 0x002b1fff Pagefile Backed Memory Readable False False False
private_0x00000000002c0000 0x002c0000 0x0033ffff Private Memory Readable, Writable False False False
pagefile_0x0000000000340000 0x00340000 0x00342fff Pagefile Backed Memory Readable False False False
private_0x0000000000350000 0x00350000 0x0035ffff Private Memory - False False False
pagefile_0x0000000000360000 0x00360000 0x00362fff Pagefile Backed Memory Readable False False False
pagefile_0x0000000000370000 0x00370000 0x00372fff Pagefile Backed Memory Readable False False False
pagefile_0x0000000000380000 0x00380000 0x00382fff Pagefile Backed Memory Readable False False False
pagefile_0x0000000000390000 0x00390000 0x00392fff Pagefile Backed Memory Readable False False False
private_0x00000000003a0000 0x003a0000 0x003bffff Private Memory Readable, Writable False False False
private_0x00000000003c0000 0x003c0000 0x003c0fff Private Memory Readable, Writable False False False
pagefile_0x00000000003d0000 0x003d0000 0x003d1fff Pagefile Backed Memory Readable False False False
private_0x00000000003e0000 0x003e0000 0x003effff Private Memory Readable, Writable False False False
private_0x00000000003f0000 0x003f0000 0x003f8fff Private Memory Readable, Writable False False False
pagefile_0x00000000003f0000 0x003f0000 0x003f0fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000400000 0x00400000 0x00408fff Private Memory Readable, Writable False False False
pagefile_0x0000000000400000 0x00400000 0x00401fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000410000 0x00410000 0x0050ffff Private Memory Readable, Writable False False False
pagefile_0x0000000000510000 0x00510000 0x00697fff Pagefile Backed Memory Readable False False False
pagefile_0x00000000006a0000 0x006a0000 0x00820fff Pagefile Backed Memory Readable False False False
SortDefault.nls 0x00830000 0x00afefff Memory Mapped File Readable False False False
private_0x0000000000b00000 0x00b00000 0x00bfffff Private Memory Readable, Writable False False False
pagefile_0x0000000000c00000 0x00c00000 0x00cdefff Pagefile Backed Memory Readable False False False
pagefile_0x0000000000ce0000 0x00ce0000 0x00ce1fff Pagefile Backed Memory Readable False False False
private_0x0000000000cf0000 0x00cf0000 0x00d2ffff Private Memory Readable, Writable False False False
private_0x0000000000d30000 0x00d30000 0x00d3efff Private Memory Readable, Writable True False False
pagefile_0x0000000000d30000 0x00d30000 0x00d31fff Pagefile Backed Memory Readable True False False
private_0x0000000000d40000 0x00d40000 0x00d40fff Private Memory Readable, Writable False False False
pagefile_0x0000000000d50000 0x00d50000 0x00d53fff Pagefile Backed Memory Readable, Writable False False False
WINWORD.EXE 0x00d60000 0x00f38fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000f40000 0x00f40000 0x0233ffff Pagefile Backed Memory Readable False False False
pagefile_0x0000000002340000 0x02340000 0x02732fff Pagefile Backed Memory Readable False False False
MSO.DLL 0x02740000 0x034f1fff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000003500000 0x03500000 0x03523fff Private Memory Readable, Writable False False False
private_0x0000000003500000 0x03500000 0x03511fff Private Memory Readable, Writable True False False
pagefile_0x0000000003520000 0x03520000 0x03521fff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000003530000 0x03530000 0x03530fff Pagefile Backed Memory Readable False False False
private_0x0000000003540000 0x03540000 0x0357ffff Private Memory Readable, Writable False False False
pagefile_0x0000000003580000 0x03580000 0x03580fff Pagefile Backed Memory Readable False False False
private_0x0000000003590000 0x03590000 0x035cffff Private Memory Readable, Writable False False False
KernelBase.dll.mui 0x035d0000 0x0368ffff Memory Mapped File Readable, Writable False False False
private_0x0000000003690000 0x03690000 0x036cffff Private Memory Readable, Writable False False False
private_0x00000000036d0000 0x036d0000 0x036f3fff Private Memory Readable, Writable False False False
private_0x00000000036d0000 0x036d0000 0x036e1fff Private Memory Readable, Writable True False False
oleaccrc.dll 0x036f0000 0x036f0fff Memory Mapped File Readable False False False
private_0x0000000003700000 0x03700000 0x0370efff Private Memory Readable, Writable True False False
private_0x0000000003700000 0x03700000 0x03701fff Private Memory Readable, Writable True False False
private_0x0000000003700000 0x03700000 0x03700fff Private Memory Readable, Writable True False False
private_0x0000000003710000 0x03710000 0x0371efff Private Memory Readable, Writable True False False
pagefile_0x0000000003710000 0x03710000 0x03710fff Pagefile Backed Memory Readable True False False
private_0x0000000003720000 0x03720000 0x03720fff Private Memory Readable, Writable True False False
private_0x0000000003730000 0x03730000 0x03730fff Private Memory Readable, Writable True False False
private_0x0000000003730000 0x03730000 0x03730fff Private Memory Readable, Writable True False False
private_0x0000000003740000 0x03740000 0x0377ffff Private Memory Readable, Writable False False False
private_0x0000000003780000 0x03780000 0x03780fff Private Memory Readable, Writable False False False
pagefile_0x0000000003790000 0x03790000 0x03791fff Pagefile Backed Memory Readable False False False
private_0x00000000037a0000 0x037a0000 0x0389ffff Private Memory Readable, Writable False False False
private_0x00000000038a0000 0x038a0000 0x0399ffff Private Memory Readable, Writable False False False
msxml6r.dll 0x039a0000 0x039a0fff Memory Mapped File Readable False False False
private_0x00000000039b0000 0x039b0000 0x03aaffff Private Memory Readable, Writable False False False
private_0x0000000003ab0000 0x03ab0000 0x03aeffff Private Memory Readable, Writable False False False
pagefile_0x0000000003af0000 0x03af0000 0x03af0fff Pagefile Backed Memory Readable, Writable False False False
private_0x0000000003b00000 0x03b00000 0x03bfffff Private Memory Readable, Writable False False False
private_0x0000000003c00000 0x03c00000 0x03c00fff Private Memory Readable, Writable False False False
pagefile_0x0000000003c10000 0x03c10000 0x03c11fff Pagefile Backed Memory Readable False False False
private_0x0000000003c20000 0x03c20000 0x03c5ffff Private Memory Readable, Writable False False False
C_1255.NLS 0x03c60000 0x03c70fff Memory Mapped File Readable False False False
private_0x0000000003c80000 0x03c80000 0x03d7ffff Private Memory Readable, Writable False False False
private_0x0000000003d80000 0x03d80000 0x03d80fff Private Memory Readable, Writable True False False
private_0x0000000003d90000 0x03d90000 0x03dcffff Private Memory Readable, Writable, Executable False False False
private_0x0000000003dd0000 0x03dd0000 0x03ddffff Private Memory Readable, Writable False False False
{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000004.db 0x03de0000 0x03e00fff Memory Mapped File Readable False False False
private_0x0000000003e10000 0x03e10000 0x03e12fff Private Memory Readable, Writable False False False
private_0x0000000003e10000 0x03e10000 0x03e1ffff Private Memory Readable, Writable True False False
private_0x0000000003e20000 0x03e20000 0x03e2ffff Private Memory Readable, Writable False False False
private_0x0000000003e30000 0x03e30000 0x03e6ffff Private Memory Readable, Writable False False False
private_0x0000000003e70000 0x03e70000 0x03e70fff Private Memory Readable, Writable True False False
private_0x0000000003e70000 0x03e70000 0x03e70fff Private Memory Readable, Writable True False False
private_0x0000000003e80000 0x03e80000 0x03e9ffff Private Memory - False False False
private_0x0000000003ea0000 0x03ea0000 0x03edffff Private Memory Readable, Writable False False False
private_0x0000000003ee0000 0x03ee0000 0x03fdffff Private Memory Readable, Writable False False False
private_0x0000000003fe0000 0x03fe0000 0x03ffefff Private Memory Readable, Writable False False False
private_0x0000000003fe0000 0x03fe0000 0x03fe1fff Private Memory Readable, Writable True False False
private_0x0000000003ff0000 0x03ff0000 0x03ff0fff Private Memory Readable, Writable True False False
private_0x0000000004000000 0x04000000 0x04000fff Private Memory Readable, Writable True False False
private_0x0000000004010000 0x04010000 0x0404ffff Private Memory Readable, Writable False False False
private_0x0000000004050000 0x04050000 0x04050fff Private Memory Readable, Writable True False False
private_0x0000000004050000 0x04050000 0x0406efff Private Memory Readable, Writable True False False
index.dat 0x04050000 0x0405bfff Memory Mapped File Readable, Writable True False False
index.dat 0x04060000 0x04067fff Memory Mapped File Readable, Writable True False False
private_0x0000000004070000 0x04070000 0x0416ffff Private Memory Readable, Writable False False False
pagefile_0x0000000004170000 0x04170000 0x0456ffff Pagefile Backed Memory Readable False False False
StaticCache.dat 0x04570000 0x04e9ffff Memory Mapped File Readable False False False
private_0x0000000004ea0000 0x04ea0000 0x04f1ffff Private Memory Readable, Writable False False False
private_0x0000000004f20000 0x04f20000 0x04f20fff Private Memory Readable, Writable True False False
pagefile_0x0000000004f20000 0x04f20000 0x04f22fff Pagefile Backed Memory Readable True False False
private_0x0000000004f30000 0x04f30000 0x04f6ffff Private Memory Readable, Writable False False False
segoeui.ttf 0x04f70000 0x04feefff Memory Mapped File Readable False False False
private_0x0000000004ff0000 0x04ff0000 0x04ffffff Private Memory - True False False
private_0x0000000005000000 0x05000000 0x0503ffff Private Memory Readable, Writable False False False
private_0x0000000005040000 0x05040000 0x05040fff Private Memory Readable, Writable True False False
private_0x0000000005040000 0x05040000 0x0505dfff Private Memory Readable, Writable True False False
index.dat 0x05040000 0x05047fff Memory Mapped File Readable, Writable True False False
private_0x0000000005060000 0x05060000 0x0515ffff Private Memory Readable, Writable False False False
private_0x0000000005160000 0x05160000 0x0517dfff Private Memory Readable, Writable True False False
private_0x0000000005170000 0x05170000 0x05170fff Private Memory Readable, Writable True False False
private_0x0000000005180000 0x05180000 0x051bffff Private Memory Readable, Writable False False False
private_0x00000000051c0000 0x051c0000 0x051defff Private Memory Readable, Writable True False False
private_0x00000000051c0000 0x051c0000 0x051cffff Private Memory Readable, Writable True False False
private_0x00000000051d0000 0x051d0000 0x051d0fff Private Memory Readable, Writable True False False
C_1251.NLS 0x051e0000 0x051f0fff Memory Mapped File Readable False False False
private_0x00000000051f0000 0x051f0000 0x051f0fff Private Memory Readable, Writable True False False
normnfd.nls 0x05200000 0x05209fff Memory Mapped File Readable False False False
private_0x0000000005210000 0x05210000 0x0530ffff Private Memory Readable, Writable False False False
private_0x0000000005310000 0x05310000 0x0540ffff Private Memory Readable, Writable False False False
private_0x0000000005410000 0x05410000 0x05410fff Private Memory Readable, Writable True False False
private_0x0000000005420000 0x05420000 0x05420fff Private Memory Readable, Writable True False False
private_0x0000000005420000 0x05420000 0x05420fff Private Memory Readable, Writable True False False
private_0x0000000005430000 0x05430000 0x0543ffff Private Memory Readable, Writable False False False
private_0x0000000005440000 0x05440000 0x0545efff Private Memory Readable, Writable True False False
C_932.NLS 0x05440000 0x05467fff Memory Mapped File Readable False False False
private_0x0000000005460000 0x05460000 0x0547efff Private Memory Readable, Writable True False False
private_0x0000000005470000 0x05470000 0x05470fff Private Memory Readable, Writable True False False
private_0x0000000005480000 0x05480000 0x05482fff Private Memory Readable, Writable True False False
private_0x0000000005490000 0x05490000 0x054cffff Private Memory Readable, Writable, Executable False False False
private_0x00000000054d0000 0x054d0000 0x054eefff Private Memory Readable, Writable True False False
private_0x00000000054f0000 0x054f0000 0x054f0fff Private Memory Readable, Writable True False False
private_0x00000000054f0000 0x054f0000 0x054f3fff Private Memory Readable, Writable True False False
private_0x0000000005500000 0x05500000 0x0550ffff Private Memory Readable, Writable False False False
private_0x0000000005510000 0x05510000 0x0552efff Private Memory Readable, Writable True False False
private_0x0000000005530000 0x05530000 0x05530fff Private Memory Readable, Writable True False False
private_0x0000000005540000 0x05540000 0x05540fff Private Memory Readable, Writable True False False
private_0x0000000005550000 0x05550000 0x05550fff Private Memory Readable, Writable True False False
private_0x0000000005560000 0x05560000 0x0559ffff Private Memory Readable, Writable False False False
private_0x00000000055a0000 0x055a0000 0x055befff Private Memory Readable, Writable True False False
private_0x00000000055c0000 0x055c0000 0x055c3fff Private Memory Readable, Writable True False False
private_0x00000000055d0000 0x055d0000 0x056cffff Private Memory Readable, Writable False False False
private_0x0000000005690000 0x05690000 0x056cffff Private Memory Readable, Writable True False False
pagefile_0x00000000056d0000 0x056d0000 0x05ecffff Pagefile Backed Memory Readable, Writable False False False
private_0x0000000005ed0000 0x05ed0000 0x060cffff Private Memory Readable, Writable False False False
private_0x00000000060d0000 0x060d0000 0x060f0fff Private Memory Readable, Writable True False False
private_0x0000000006100000 0x06100000 0x0613ffff Private Memory Readable, Writable False False False
SEGOEUISL.TTF 0x06140000 0x061d7fff Memory Mapped File Readable False False False
private_0x0000000006170000 0x06170000 0x06171fff Private Memory Readable, Writable True False False
private_0x0000000006190000 0x06190000 0x06191fff Private Memory Readable, Writable True False False
private_0x00000000061b0000 0x061b0000 0x061b1fff Private Memory Readable, Writable True False False
private_0x00000000061d0000 0x061d0000 0x061d1fff Private Memory Readable, Writable True False False
private_0x00000000061e0000 0x061e0000 0x061e2fff Private Memory Readable, Writable True False False
private_0x00000000061f0000 0x061f0000 0x0622ffff Private Memory Readable, Writable False False False
private_0x0000000006230000 0x06230000 0x0624efff Private Memory Readable, Writable True False False
private_0x0000000006250000 0x06250000 0x0628ffff Private Memory Readable, Writable False False False
MSForms.exd 0x06250000 0x06275fff Memory Mapped File Readable True True False
private_0x0000000006280000 0x06280000 0x0628ffff Private Memory - True False False
private_0x0000000006290000 0x06290000 0x062affff Private Memory Readable, Writable True False False
stdole2.tlb 0x062b0000 0x062b3fff Memory Mapped File Readable False False False
private_0x00000000062c0000 0x062c0000 0x063bffff Private Memory Readable, Writable False False False
pagefile_0x00000000063c0000 0x063c0000 0x067bffff Pagefile Backed Memory Readable, Writable False False False
private_0x00000000067c0000 0x067c0000 0x067fffff Private Memory Readable, Writable False False False
private_0x00000000067c0000 0x067c0000 0x067c0fff Private Memory Readable, Writable True False False
VBE6EXT.OLB 0x067d0000 0x067d9fff Memory Mapped File Readable False False False
private_0x00000000067e0000 0x067e0000 0x067e3fff Private Memory Readable, Writable True False False
private_0x00000000067f0000 0x067f0000 0x067f3fff Private Memory Readable, Writable True False False
private_0x0000000006800000 0x06800000 0x06847fff Private Memory Readable, Writable True False False
private_0x0000000006850000 0x06850000 0x0686ffff Private Memory Readable, Writable True False False
private_0x0000000006870000 0x06870000 0x068affff Private Memory Readable, Writable True False False
private_0x00000000068b0000 0x068b0000 0x068f7fff Private Memory Readable, Writable True False False
private_0x0000000006900000 0x06900000 0x0693ffff Private Memory Readable, Writable False False False
private_0x0000000006940000 0x06940000 0x0697ffff Private Memory Readable, Writable False False False
VBE7.DLL 0x06980000 0x06994fff Memory Mapped File Readable True False False
FM20.DLL 0x069a0000 0x069c7fff Memory Mapped File Readable False False False
private_0x00000000069d0000 0x069d0000 0x069d3fff Private Memory Readable, Writable True False False
private_0x00000000069e0000 0x069e0000 0x06adffff Private Memory Readable, Writable False False False
private_0x0000000006ae0000 0x06ae0000 0x06b1ffff Private Memory Readable, Writable False False False
private_0x0000000006b20000 0x06b20000 0x06f1ffff Private Memory Readable, Writable False False False
private_0x0000000006f20000 0x06f20000 0x0731ffff Private Memory Readable, Writable False False False
private_0x0000000007320000 0x07320000 0x07720fff Private Memory Readable, Writable False False False
private_0x0000000007730000 0x07730000 0x07b30fff Private Memory Readable, Writable False False False
private_0x0000000007b40000 0x07b40000 0x07f40fff Private Memory Readable, Writable False False False
private_0x0000000007f50000 0x07f50000 0x0814ffff Private Memory Readable, Writable False False False
private_0x0000000008150000 0x08150000 0x0860ffff Private Memory Readable, Writable False False False
private_0x00000000081a0000 0x081a0000 0x081dffff Private Memory Readable, Writable True False False
private_0x0000000008210000 0x08210000 0x0824ffff Private Memory Readable, Writable True False False
private_0x0000000008250000 0x08250000 0x08349fff Private Memory Readable, Writable True False False
private_0x0000000008450000 0x08450000 0x0854cfff Private Memory Readable, Writable True False False
pagefile_0x0000000008610000 0x08610000 0x086acfff Pagefile Backed Memory Readable, Writable True False False
private_0x00000000086b0000 0x086b0000 0x087affff Private Memory Readable, Writable False False False
private_0x00000000087b0000 0x087b0000 0x08faffff Private Memory Readable, Writable False False False
private_0x0000000008fb0000 0x08fb0000 0x093affff Private Memory Readable, Writable False False False
~DFB7A23E638F393D69.TMP 0x093b0000 0x0942ffff Memory Mapped File Readable, Writable True False False
private_0x0000000009430000 0x09430000 0x09433fff Private Memory Readable, Writable True False False
private_0x0000000009440000 0x09440000 0x09442fff Private Memory Readable, Writable True False False
private_0x0000000009450000 0x09450000 0x09453fff Private Memory Readable, Writable True False False
private_0x0000000009460000 0x09460000 0x0955ffff Private Memory Readable, Writable False False False
private_0x0000000009560000 0x09560000 0x0965ffff Private Memory Readable, Writable True False False
private_0x0000000009660000 0x09660000 0x09662fff Private Memory Readable, Writable True False False
private_0x0000000009670000 0x09670000 0x0976ffff Private Memory Readable, Writable False False False
~WRF{A051C2F5-8A1D-43FE-A642-C1E8191049BC}.tmp 0x09770000 0x097effff Memory Mapped File Readable, Writable True False False
private_0x00000000097f0000 0x097f0000 0x0980ffff Private Memory Readable, Writable True False False
VBE7.DLL 0x09810000 0x09815fff Memory Mapped File Readable True False False
private_0x0000000009820000 0x09820000 0x0991ffff Private Memory Readable, Writable False False False
~DF9964373722235E4A.TMP 0x09820000 0x0989ffff Memory Mapped File Readable, Writable True True False
~DF0D24DB035B883A83.TMP 0x098a0000 0x0991ffff Memory Mapped File Readable, Writable True True False
MSO.DLL 0x09920000 0x0999bfff Memory Mapped File Readable False False False
FM20.DLL 0x099a0000 0x099c3fff Memory Mapped File Readable False False False
private_0x00000000099d0000 0x099d0000 0x099dffff Private Memory Readable, Writable True False False
private_0x00000000099e0000 0x099e0000 0x09a1ffff Private Memory Readable, Writable, Executable True False False
private_0x0000000009a20000 0x09a20000 0x09a23fff Private Memory Readable, Writable True False False
private_0x0000000009a30000 0x09a30000 0x09a33fff Private Memory Readable, Writable True False False
private_0x0000000009a40000 0x09a40000 0x09b3ffff Private Memory Readable, Writable False False False
private_0x0000000009a40000 0x09a40000 0x09a43fff Private Memory Readable, Writable True False False
private_0x0000000009a50000 0x09a50000 0x09a53fff Private Memory Readable, Writable True False False
private_0x0000000009a60000 0x09a60000 0x09a63fff Private Memory Readable, Writable True False False
private_0x0000000009a70000 0x09a70000 0x09a72fff Private Memory Readable, Writable True False False
private_0x0000000009a80000 0x09a80000 0x09a83fff Private Memory Readable, Writable True False False
private_0x0000000009a90000 0x09a90000 0x09a93fff Private Memory Readable, Writable True False False
private_0x0000000009aa0000 0x09aa0000 0x09aa3fff Private Memory Readable, Writable True False False
private_0x0000000009ad0000 0x09ad0000 0x09ad1fff Private Memory Readable, Writable True False False
private_0x0000000009ae0000 0x09ae0000 0x09b1ffff Private Memory Readable, Writable True False False
private_0x0000000009b30000 0x09b30000 0x09b31fff Private Memory Readable, Writable True False False
private_0x0000000009b50000 0x09b50000 0x09b51fff Private Memory Readable, Writable True False False
private_0x0000000009b70000 0x09b70000 0x09c6ffff Private Memory Readable, Writable True False False
~DFFBE155C19A25B2E8.TMP 0x09c70000 0x09ceffff Memory Mapped File Readable, Writable True True False
private_0x0000000009cf0000 0x09cf0000 0x09cf1fff Private Memory Readable, Writable True False False
private_0x0000000009d10000 0x09d10000 0x09d11fff Private Memory Readable, Writable True False False
private_0x0000000009d20000 0x09d20000 0x09d5ffff Private Memory Readable, Writable True False False
pagefile_0x0000000009d60000 0x09d60000 0x0a55ffff Pagefile Backed Memory Readable, Writable True False False
times.ttf 0x0a560000 0x0a62bfff Memory Mapped File Readable False False False
private_0x000000000a630000 0x0a630000 0x0aae1fff Private Memory Readable, Writable True False False
private_0x000000000a630000 0x0a630000 0x0a9effff Private Memory Readable, Writable True False False
tahoma.ttf 0x0a9f0000 0x0aa9afff Memory Mapped File Readable False False False
MSWORD.OLB 0x0aaf0000 0x0abd0fff Memory Mapped File Readable False False False
pagefile_0x000000000abe0000 0x0abe0000 0x0afdffff Pagefile Backed Memory Readable, Writable True False False
private_0x000000000afe0000 0x0afe0000 0x0b0dffff Private Memory Readable, Writable, Executable True False False
private_0x000000000b0e0000 0x0b0e0000 0x0b1dffff Private Memory Readable, Writable True False False
private_0x000000000b1e0000 0x0b1e0000 0x0b21ffff Private Memory Readable, Writable True False False
private_0x000000000b240000 0x0b240000 0x0b33ffff Private Memory Readable, Writable True False False
pagefile_0x000000000b340000 0x0b340000 0x0b73ffff Pagefile Backed Memory Readable, Writable True False False
private_0x000000000b740000 0x0b740000 0x0bf3ffff Private Memory Readable, Writable True False False
timesi.ttf 0x0bf40000 0x0bfe1fff Memory Mapped File Readable False False False
private_0x000000000c070000 0x0c070000 0x0c16ffff Private Memory Readable, Writable True False False
timesbd.ttf 0x0c170000 0x0c23dfff Memory Mapped File Readable False False False
private_0x000000000c240000 0x0c240000 0x0c33ffff Private Memory Readable, Writable True False False
CalibriL.ttf 0x0c340000 0x0c3f9fff Memory Mapped File Readable False False False
private_0x000000000c400000 0x0c400000 0x0c4d8fff Private Memory Readable, Writable True False False
msmincho.ttc 0x0c4e0000 0x0ce77fff Memory Mapped File Readable False False False
pagefile_0x000000000ce80000 0x0ce80000 0x0d1c2fff Pagefile Backed Memory Readable True False False
private_0x000000000d2b0000 0x0d2b0000 0x0d2effff Private Memory Readable, Writable True False False
private_0x000000000d3e0000 0x0d3e0000 0x0d4dffff Private Memory Readable, Writable True False False
private_0x000000000d620000 0x0d620000 0x0d65ffff Private Memory Readable, Writable True False False
private_0x000000000d6b0000 0x0d6b0000 0x0d7affff Private Memory Readable, Writable True False False
private_0x000000000d820000 0x0d820000 0x0d91ffff Private Memory Readable, Writable True False False
private_0x0000000035e30000 0x35e30000 0x35e3ffff Private Memory Readable, Writable, Executable False False False
gpapi.dll 0x66330000 0x66345fff Memory Mapped File Readable, Writable, Executable False False False
webservices.dll 0x66350000 0x66411fff Memory Mapped File Readable, Writable, Executable False False False
ncrypt.dll 0x66cf0000 0x66d27fff Memory Mapped File Readable, Writable, Executable False False False
schannel.dll 0x66d30000 0x66d69fff Memory Mapped File Readable, Writable, Executable False False False
FWPUCLNT.DLL 0x67070000 0x670a7fff Memory Mapped File Readable, Writable, Executable False False False
winrnr.dll 0x670b0000 0x670b7fff Memory Mapped File Readable, Writable, Executable False False False
pnrpnsp.dll 0x670c0000 0x670d1fff Memory Mapped File Readable, Writable, Executable False False False
NapiNSP.dll 0x670e0000 0x670effff Memory Mapped File Readable, Writable, Executable False False False
rasadhlp.dll 0x670f0000 0x670f5fff Memory Mapped File Readable, Writable, Executable False False False
SensApi.dll 0x67100000 0x67105fff Memory Mapped File Readable, Writable, Executable False False False
rasman.dll 0x67110000 0x67124fff Memory Mapped File Readable, Writable, Executable False False False
winnsi.dll 0x671b0000 0x671b6fff Memory Mapped File Readable, Writable, Executable False False False
IPHLPAPI.DLL 0x671c0000 0x671dbfff Memory Mapped File Readable, Writable, Executable False False False
rasapi32.dll 0x67220000 0x67271fff Memory Mapped File Readable, Writable, Executable False False False
dnsapi.dll 0x67280000 0x672c3fff Memory Mapped File Readable, Writable, Executable False False False
mswsock.dll 0x672d0000 0x6730bfff Memory Mapped File Readable, Writable, Executable False False False
msproof7.dll 0x67310000 0x6734afff Memory Mapped File Readable, Writable, Executable False False False
rtutils.dll 0x675b0000 0x675bcfff Memory Mapped File Readable, Writable, Executable False False False
wship6.dll 0x675c0000 0x675c5fff Memory Mapped File Readable, Writable, Executable False False False
WSHTCPIP.DLL 0x675d0000 0x675d4fff Memory Mapped File Readable, Writable, Executable False False False
credssp.dll 0x675e0000 0x675e7fff Memory Mapped File Readable, Writable, Executable False False False
dhcpcsvc.dll 0x675f0000 0x67601fff Memory Mapped File Readable, Writable, Executable False False False
wmiutils.dll 0x67610000 0x67626fff Memory Mapped File Readable, Writable, Executable False False False
wbemdisp.dll 0x67630000 0x67660fff Memory Mapped File Readable, Writable, Executable True False False
FM20ENU.DLL 0x67670000 0x67677fff Memory Mapped File Readable, Writable, Executable False False False
VBEUIINTL.DLL 0x67680000 0x67887fff Memory Mapped File Readable, Writable, Executable True False False
VBEUIRES.DLL 0x67890000 0x67dbafff Memory Mapped File Readable, Writable, Executable True False False
FM20.DLL 0x67dc0000 0x67efdfff Memory Mapped File Readable, Writable, Executable False False False
VBE7INTL.DLL 0x67f00000 0x67f25fff Memory Mapped File Readable, Writable, Executable True False False
VBEUI.DLL 0x67f30000 0x68160fff Memory Mapped File Readable, Writable, Executable True False False
sxs.dll 0x68170000 0x681cefff Memory Mapped File Readable, Writable, Executable False False False
linkinfo.dll 0x681d0000 0x681d8fff Memory Mapped File Readable, Writable, Executable False False False
oleacc.dll 0x681e0000 0x6821bfff Memory Mapped File Readable, Writable, Executable False False False
UIAutomationCore.dll 0x68220000 0x682abfff Memory Mapped File Readable, Writable, Executable False False False
msvcr100.dll 0x682b0000 0x6836efff Memory Mapped File Readable, Writable, Executable False False False
GKWord.dll 0x68340000 0x685edfff Memory Mapped File Readable, Writable, Executable False False False
VBE7.DLL 0x68370000 0x685eefff Memory Mapped File Readable, Writable, Executable True False False
dhcpcsvc6.dll 0x685f0000 0x685fcfff Memory Mapped File Readable, Writable, Executable False False False
srvcli.dll 0x68600000 0x68618fff Memory Mapped File Readable, Writable, Executable False False False
ntshrui.dll 0x68620000 0x6868ffff Memory Mapped File Readable, Writable, Executable False False False
wbemsvc.dll 0x68690000 0x6869efff Memory Mapped File Readable, Writable, Executable False False False
apphelp.dll 0x686a0000 0x686ebfff Memory Mapped File Readable, Writable, Executable False False False
wbemcomn.dll 0x686f0000 0x6874bfff Memory Mapped File Readable, Writable, Executable False False False
wbemprox.dll 0x68750000 0x68759fff Memory Mapped File Readable, Writable, Executable False False False
MSOHEV.DLL 0x68760000 0x68776fff Memory Mapped File Readable, Writable, Executable False False False
bcryptprimitives.dll 0x68780000 0x687bcfff Memory Mapped File Readable, Writable, Executable False False False
bcrypt.dll 0x687c0000 0x687d6fff Memory Mapped File Readable, Writable, Executable False False False
powrprof.dll 0x687e0000 0x68804fff Memory Mapped File Readable, Writable, Executable False False False
CHART.DLL 0x68810000 0x69004fff Memory Mapped File Readable, Writable, Executable False False False
msxml6.dll 0x69010000 0x69167fff Memory Mapped File Readable, Writable, Executable False False False
mlang.dll 0x69170000 0x6919dfff Memory Mapped File Readable, Writable, Executable False False False
xmllite.dll 0x691a0000 0x691cefff Memory Mapped File Readable, Writable, Executable False False False
ntmarta.dll 0x691d0000 0x691f0fff Memory Mapped File Readable, Writable, Executable False False False
propsys.dll 0x69200000 0x692f4fff Memory Mapped File Readable, Writable, Executable False False False
winspool.drv 0x69300000 0x69350fff Memory Mapped File Readable, Writable, Executable False False False
OSPPC.DLL 0x69360000 0x6938cfff Memory Mapped File Readable, Writable, Executable False False False
npmproxy.dll 0x69390000 0x69397fff Memory Mapped File Readable, Writable, Executable False False False
RpcRtRemote.dll 0x693a0000 0x693adfff Memory Mapped File Readable, Writable, Executable False False False
rsaenh.dll 0x693b0000 0x693eafff Memory Mapped File Readable, Writable, Executable False False False
cryptsp.dll 0x693f0000 0x69405fff Memory Mapped File Readable, Writable, Executable False False False
nlaapi.dll 0x69410000 0x6941ffff Memory Mapped File Readable, Writable, Executable False False False
netprofm.dll 0x69420000 0x69479fff Memory Mapped File Readable, Writable, Executable False False False
secur32.dll 0x69480000 0x69487fff Memory Mapped File Readable, Writable, Executable False False False
RICHED20.DLL 0x69490000 0x69631fff Memory Mapped File Readable, Writable, Executable False False False
mscoreei.dll 0x69640000 0x696b9fff Memory Mapped File Readable, Writable, Executable False False False
mscoree.dll 0x696c0000 0x69709fff Memory Mapped File Readable, Writable, Executable False False False
WindowsCodecs.dll 0x69710000 0x6980afff Memory Mapped File Readable, Writable, Executable False False False
DWrite.dll 0x69810000 0x69919fff Memory Mapped File Readable, Writable, Executable False False False
d3d10warp.dll 0x69920000 0x69a4bfff Memory Mapped File Readable, Writable, Executable False False False
d3d10_1core.dll 0x69a50000 0x69a89fff Memory Mapped File Readable, Writable, Executable False False False
d3d10_1.dll 0x69a90000 0x69abbfff Memory Mapped File Readable, Writable, Executable False False False
MSPTLS.DLL 0x69ac0000 0x69bd7fff Memory Mapped File Readable, Writable, Executable False False False
MSOINTL.DLL 0x69be0000 0x69d54fff Memory Mapped File Readable, Writable, Executable False False False
msointl30.dll 0x69d60000 0x69d6efff Memory Mapped File Readable, Writable, Executable False False False
WWINTL.DLL 0x69d70000 0x69e18fff Memory Mapped File Readable, Writable, Executable False False False
MSORES.DLL 0x69e20000 0x6ec5efff Memory Mapped File Readable, Writable, Executable False False False
MSO99LRES.DLL 0x6ec60000 0x6f580fff Memory Mapped File Readable, Writable, Executable False False False
MSO40UIRES.DLL 0x6f590000 0x6f897fff Memory Mapped File Readable, Writable, Executable False False False
winsta.dll 0x6f8a0000 0x6f8c8fff Memory Mapped File Readable, Writable, Executable False False False
wtsapi32.dll 0x6f8d0000 0x6f8dcfff Memory Mapped File Readable, Writable, Executable False False False
uxtheme.dll 0x6f8e0000 0x6f95ffff Memory Mapped File Readable, Writable, Executable False False False
comctl32.dll 0x6f960000 0x6fafdfff Memory Mapped File Readable, Writable, Executable False False False
d2d1.dll 0x6fb00000 0x6fbb9fff Memory Mapped File Readable, Writable, Executable False False False
OFFICE.ODF 0x6fbc0000 0x6fd78fff Memory Mapped File Readable, Writable, Executable False False False
msi.dll 0x6fd80000 0x6ffbffff Memory Mapped File Readable, Writable, Executable False False False
private_0x000000006fff0000 0x6fff0000 0x6fffffff Private Memory Readable, Writable, Executable False False False
sppc.dll 0x70d80000 0x70da0fff Memory Mapped File Readable, Writable, Executable False False False
slc.dll 0x70db0000 0x70db9fff Memory Mapped File Readable, Writable, Executable False False False
msimg32.dll 0x70dc0000 0x70dc4fff Memory Mapped File Readable, Writable, Executable False False False
Mso99Lwin32client.dll 0x70dd0000 0x71367fff Memory Mapped File Readable, Writable, Executable False False False
Mso40UIwin32client.dll 0x71370000 0x71a84fff Memory Mapped File Readable, Writable, Executable False False False
Mso30win32client.dll 0x71a90000 0x71d91fff Memory Mapped File Readable, Writable, Executable False False False
Mso20win32client.dll 0x71da0000 0x71f74fff Memory Mapped File Readable, Writable, Executable False False False
OART.DLL 0x71f80000 0x72b71fff Memory Mapped File Readable, Writable, Executable False False False
api-ms-win-crt-utility-l1-1-0.dll 0x72b80000 0x72b82fff Memory Mapped File Readable, Writable, Executable False False False
api-ms-win-crt-environment-l1-1-0.dll 0x72b90000 0x72b92fff Memory Mapped File Readable, Writable, Executable False False False
api-ms-win-crt-filesystem-l1-1-0.dll 0x72ba0000 0x72ba2fff Memory Mapped File Readable, Writable, Executable False False False
api-ms-win-crt-time-l1-1-0.dll 0x72bb0000 0x72bb2fff Memory Mapped File Readable, Writable, Executable False False False
api-ms-win-crt-multibyte-l1-1-0.dll 0x72bc0000 0x72bc4fff Memory Mapped File Readable, Writable, Executable False False False
msvcp140.dll 0x72bd0000 0x72c3cfff Memory Mapped File Readable, Writable, Executable False False False
GdiPlus.dll 0x72c40000 0x72dcffff Memory Mapped File Readable, Writable, Executable False False False
dwmapi.dll 0x72dd0000 0x72de2fff Memory Mapped File Readable, Writable, Executable False False False
version.dll 0x72df0000 0x72df8fff Memory Mapped File Readable, Writable, Executable False False False
dxgi.dll 0x72e00000 0x72e82fff Memory Mapped File Readable, Writable, Executable False False False
d3d11.dll 0x72e90000 0x72f12fff Memory Mapped File Readable, Writable, Executable False False False
WWLIB.DLL 0x72f20000 0x74b81fff Memory Mapped File Readable, Writable, Executable False False False
api-ms-win-crt-locale-l1-1-0.dll 0x74b90000 0x74b92fff Memory Mapped File Readable, Writable, Executable False False False
api-ms-win-crt-math-l1-1-0.dll 0x74ba0000 0x74ba4fff Memory Mapped File Readable, Writable, Executable False False False
api-ms-win-crt-convert-l1-1-0.dll 0x74bb0000 0x74bb3fff Memory Mapped File Readable, Writable, Executable False False False
api-ms-win-crt-stdio-l1-1-0.dll 0x74bc0000 0x74bc3fff Memory Mapped File Readable, Writable, Executable False False False
api-ms-win-crt-heap-l1-1-0.dll 0x74bd0000 0x74bd2fff Memory Mapped File Readable, Writable, Executable False False False
api-ms-win-crt-string-l1-1-0.dll 0x74be0000 0x74be3fff Memory Mapped File Readable, Writable, Executable False False False
api-ms-win-core-file-l1-2-0.dll 0x74bf0000 0x74bf2fff Memory Mapped File Readable, Writable, Executable False False False
api-ms-win-core-processthreads-l1-1-1.dll 0x74c00000 0x74c02fff Memory Mapped File Readable, Writable, Executable False False False
api-ms-win-core-synch-l1-2-0.dll 0x74c10000 0x74c12fff Memory Mapped File Readable, Writable, Executable False False False
api-ms-win-core-localization-l1-2-0.dll 0x74c20000 0x74c22fff Memory Mapped File Readable, Writable, Executable False False False
api-ms-win-core-file-l2-1-0.dll 0x74c30000 0x74c32fff Memory Mapped File Readable, Writable, Executable False False False
api-ms-win-core-timezone-l1-1-0.dll 0x74c40000 0x74c42fff Memory Mapped File Readable, Writable, Executable False False False
ucrtbase.dll 0x74c50000 0x74d2bfff Memory Mapped File Readable, Writable, Executable False False False
api-ms-win-crt-runtime-l1-1-0.dll 0x74d30000 0x74d33fff Memory Mapped File Readable, Writable, Executable False False False
vcruntime140.dll 0x74d40000 0x74d54fff Memory Mapped File Readable, Writable, Executable False False False
profapi.dll 0x74d60000 0x74d6afff Memory Mapped File Readable, Writable, Executable False False False
userenv.dll 0x74d70000 0x74d86fff Memory Mapped File Readable, Writable, Executable False False False
C2R32.dll 0x74d90000 0x74e5afff Memory Mapped File Readable, Writable, Executable False False False
AppvIsvStream32.dll 0x74e60000 0x74ec4fff Memory Mapped File Readable, Writable, Executable False False False
AppvIsvSubsystems32.dll 0x74ed0000 0x75084fff Memory Mapped File Readable, Writable, Executable False False False
wow64win.dll 0x75090000 0x750ebfff Memory Mapped File Readable, Writable, Executable False False False
wow64.dll 0x750f0000 0x7512efff Memory Mapped File Readable, Writable, Executable False False False
cscapi.dll 0x75130000 0x7513afff Memory Mapped File Readable, Writable, Executable False False False
EhStorShell.dll 0x75140000 0x75170fff Memory Mapped File Readable, Writable, Executable False False False
webio.dll 0x75180000 0x751cefff Memory Mapped File Readable, Writable, Executable False False False
winhttp.dll 0x751d0000 0x75227fff Memory Mapped File Readable, Writable, Executable False False False
cabinet.dll 0x75230000 0x75244fff Memory Mapped File Readable, Writable, Executable False False False
wsock32.dll 0x75250000 0x75256fff Memory Mapped File Readable, Writable, Executable False False False
LoggingPlatform.dll 0x75260000 0x75279fff Memory Mapped File Readable, Writable, Executable False False False
Telemetry.dll 0x75280000 0x752f7fff Memory Mapped File Readable, Writable, Executable False False False
msvcr110.dll 0x75300000 0x753d1fff Memory Mapped File Readable, Writable, Executable False False False
msvcp110.dll 0x753e0000 0x75464fff Memory Mapped File Readable, Writable, Executable False False False
FileSyncShell.dll 0x75470000 0x754bffff Memory Mapped File Readable, Writable, Executable False False False
ntdsapi.dll 0x754c0000 0x754d7fff Memory Mapped File Readable, Writable, Executable False False False
fastprox.dll 0x754e0000 0x75575fff Memory Mapped File Readable, Writable, Executable False False False
wow64cpu.dll 0x75680000 0x75687fff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x756c0000 0x756cbfff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x756d0000 0x7572ffff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x75730000 0x7581ffff Memory Mapped File Readable, Writable, Executable False False False
ole32.dll 0x75880000 0x759dbfff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x759e0000 0x75a25fff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x75a30000 0x75accfff Memory Mapped File Readable, Writable, Executable False False False
cfgmgr32.dll 0x75ad0000 0x75af6fff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x75b00000 0x75b09fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75b10000 0x75bdbfff Memory Mapped File Readable, Writable, Executable False False False
iertutil.dll 0x75be0000 0x75ddafff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x75e10000 0x75f0ffff Memory Mapped File Readable, Writable, Executable False False False
crypt32.dll 0x75f10000 0x7602cfff Memory Mapped File Readable, Writable, Executable False False False
msasn1.dll 0x76030000 0x7603bfff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76040000 0x760ebfff Memory Mapped File Readable, Writable, Executable False False False
clbcatq.dll 0x760f0000 0x76172fff Memory Mapped File Readable, Writable, Executable False False False
devobj.dll 0x76200000 0x76211fff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x76220000 0x7627ffff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76280000 0x7630ffff Memory Mapped File Readable, Writable, Executable False False False
ws2_32.dll 0x763a0000 0x763d4fff Memory Mapped File Readable, Writable, Executable False False False
wintrust.dll 0x763e0000 0x7640cfff Memory Mapped File Readable, Writable, Executable False False False
shlwapi.dll 0x76410000 0x76466fff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76470000 0x7650ffff Memory Mapped File Readable, Writable, Executable False False False
nsi.dll 0x76510000 0x76515fff Memory Mapped File Readable, Writable, Executable False False False
normaliz.dll 0x76520000 0x76522fff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x76530000 0x7663ffff Memory Mapped File Readable, Writable, Executable False False False
setupapi.dll 0x76640000 0x767dcfff Memory Mapped File Readable, Writable, Executable False False False
wininet.dll 0x767e0000 0x768d4fff Memory Mapped File Readable, Writable, Executable False False False
oleaut32.dll 0x768e0000 0x7696efff Memory Mapped File Readable, Writable, Executable False False False
shell32.dll 0x76970000 0x775b9fff Memory Mapped File Readable, Writable, Executable False False False
Wldap32.dll 0x775c0000 0x77604fff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x77610000 0x77628fff Memory Mapped File Readable, Writable, Executable False False False
urlmon.dll 0x77630000 0x77765fff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000077770000 0x77770000 0x77869fff Private Memory Readable, Writable, Executable False False False
private_0x0000000077870000 0x77870000 0x7798efff Private Memory Readable, Writable, Executable False False False
ntdll.dll 0x77990000 0x77b38fff Memory Mapped File Readable, Writable, Executable False False False
psapi.dll 0x77b40000 0x77b44fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77b70000 0x77ceffff Memory Mapped File Readable, Writable, Executable False False False
private_0x000000007ef5e000 0x7ef5e000 0x7ef60fff Private Memory Readable, Writable True False False
private_0x000000007ef61000 0x7ef61000 0x7ef63fff Private Memory Readable, Writable True False False
private_0x000000007ef64000 0x7ef64000 0x7ef66fff Private Memory Readable, Writable False False False
private_0x000000007ef64000 0x7ef64000 0x7ef66fff Private Memory Readable, Writable True False False
private_0x000000007ef67000 0x7ef67000 0x7ef69fff Private Memory Readable, Writable False False False
private_0x000000007ef6a000 0x7ef6a000 0x7ef6cfff Private Memory Readable, Writable False False False
private_0x000000007ef6d000 0x7ef6d000 0x7ef6ffff Private Memory Readable, Writable False False False
private_0x000000007ef70000 0x7ef70000 0x7ef7ffff Private Memory - False False False
private_0x000000007ef80000 0x7ef80000 0x7ef8ffff Private Memory - False False False
private_0x000000007ef92000 0x7ef92000 0x7ef94fff Private Memory Readable, Writable False False False
private_0x000000007ef95000 0x7ef95000 0x7ef97fff Private Memory Readable, Writable False False False
private_0x000000007ef98000 0x7ef98000 0x7ef9afff Private Memory Readable, Writable False False False
private_0x000000007ef9b000 0x7ef9b000 0x7ef9dfff Private Memory Readable, Writable False False False
private_0x000000007ef9b000 0x7ef9b000 0x7ef9dfff Private Memory Readable, Writable True False False
private_0x000000007ef9e000 0x7ef9e000 0x7efa0fff Private Memory Readable, Writable False False False
private_0x000000007efa1000 0x7efa1000 0x7efa3fff Private Memory Readable, Writable False False False
private_0x000000007efa4000 0x7efa4000 0x7efa6fff Private Memory Readable, Writable False False False
private_0x000000007efa7000 0x7efa7000 0x7efa9fff Private Memory Readable, Writable False False False
private_0x000000007efaa000 0x7efaa000 0x7efacfff Private Memory Readable, Writable False False False
private_0x000000007efad000 0x7efad000 0x7efaffff Private Memory Readable, Writable False False False
pagefile_0x000000007efb0000 0x7efb0000 0x7efd2fff Pagefile Backed Memory Readable False False False
private_0x000000007efd5000 0x7efd5000 0x7efd7fff Private Memory Readable, Writable False False False
private_0x000000007efd5000 0x7efd5000 0x7efd7fff Private Memory Readable, Writable True False False
private_0x000000007efd8000 0x7efd8000 0x7efdafff Private Memory Readable, Writable False False False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable False False False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable False False False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable False False False
pagefile_0x000000007efe0000 0x7efe0000 0x7f0dffff Pagefile Backed Memory Readable False False False
private_0x000000007f0e0000 0x7f0e0000 0x7ffdffff Private Memory Readable False False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable False False False
private_0x000000007fff0000 0x7fff0000 0x7fffffeffff Private Memory Readable False False False
Created Files
+
Filename File Size Hash Values YARA Match Actions
c:\users\hjrd1k~1\appdata\local\temp\vbe\msforms.exd 148.49 KB (152056 bytes) MD5: 3216ec2560c6583449f44e7dd9549b4b
SHA1: ccc83c8644eec8cf1bb6c0950dfb868d4f46b42c
SHA256: 4851a74564adb270cbb68d67ab645ad18d1ba0921b2972372679352c09209192
False
c:\users\hjrd1koky ds8lujv\appdata\roaming\microsoft\forms\winword.box 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\hjrd1koky ds8lujv\appdata\roaming\convincingly.exe 73.00 KB (74752 bytes) MD5: eeef5204913a313f64a2e06dea22b936
SHA1: 74a5c8175391184a5fd7b32dfde7b9a27386aadf
SHA256: 927810b771a85383ab0679c559ef7544bb7666f60d84f8e180c405fda1659005
False
Host Behavior
File (2)
+
Operation Filename Additional Information Success Count Logfile
CREATE c:\users\hjrd1koky ds8lujv\appdata\roaming\convincingly.exe file_attributes = _O_RDWR, _O_CREAT, _O_EXCL True 1
Fn
WRITE c:\users\hjrd1koky ds8lujv\appdata\roaming\convincingly.exe size = 74752 True 1
Fn
Data
Process (1)
+
Operation Process Name Additional Information Success Count Logfile
CREATE C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\convincingly.exe True 1
Fn
Module (39)
+
Operation Module Additional Information Success Count Logfile
LOAD VBE7.DLL base_address = 0x68370000 True 18
Fn
LOAD C:\Windows\system32\advapi32.dll base_address = 0x76470000 True 1
Fn
GET_PROC_ADDRESS c:\program files (x86)\microsoft office\root\vfs\programfilescommonx86\microsoft shared\vba\vba7.1\vbeui.dll function = _MsoMultiByteToWideChar@24, address = 0x67f3c669 True 1
Fn
GET_PROC_ADDRESS c:\program files (x86)\microsoft office\root\office16\gkword.dll function = 528, address = 0x683f814d True 1
Fn
GET_PROC_ADDRESS c:\program files (x86)\microsoft office\root\office16\gkword.dll function = 617, address = 0x683f6997 True 1
Fn
GET_PROC_ADDRESS c:\program files (x86)\microsoft office\root\office16\gkword.dll function = 619, address = 0x683f6a57 True 1
Fn
GET_PROC_ADDRESS c:\program files (x86)\microsoft office\root\office16\gkword.dll function = 632, address = 0x683f63c4 True 1
Fn
GET_PROC_ADDRESS c:\program files (x86)\microsoft office\root\office16\gkword.dll function = 614, address = 0x68540137 True 1
Fn
GET_PROC_ADDRESS c:\program files (x86)\microsoft office\root\office16\gkword.dll function = 714, address = 0x68540476 True 1
Fn
GET_PROC_ADDRESS c:\program files (x86)\microsoft office\root\office16\gkword.dll function = 673, address = 0x6857da54 True 1
Fn
GET_PROC_ADDRESS c:\program files (x86)\microsoft office\root\office16\gkword.dll function = 713, address = 0x6857fe55 True 1
Fn
GET_PROC_ADDRESS c:\program files (x86)\microsoft office\root\office16\gkword.dll function = 518, address = 0x683f5dcb True 1
Fn
GET_PROC_ADDRESS c:\program files (x86)\microsoft office\root\office16\gkword.dll function = 582, address = 0x6854010c True 1
Fn
GET_PROC_ADDRESS c:\program files (x86)\microsoft office\root\office16\gkword.dll function = 648, address = 0x68379630 True 1
Fn
GET_PROC_ADDRESS c:\program files (x86)\microsoft office\root\office16\gkword.dll function = 583, address = 0x6853f896 True 1
Fn
GET_PROC_ADDRESS c:\program files (x86)\microsoft office\root\office16\gkword.dll function = 585, address = 0x6853f68d True 1
Fn
GET_PROC_ADDRESS c:\program files (x86)\microsoft office\root\office16\gkword.dll function = 666, address = 0x683a5bc6 True 1
Fn
GET_PROC_ADDRESS c:\program files (x86)\microsoft office\root\office16\gkword.dll function = 717, address = 0x6856f4a9 True 1
Fn
GET_PROC_ADDRESS c:\program files (x86)\microsoft office\root\office16\gkword.dll function = 616, address = 0x683f46c2 True 1
Fn
GET_PROC_ADDRESS c:\program files (x86)\microsoft office\root\office16\gkword.dll function = 587, address = 0x6853fc79 True 1
Fn
GET_PROC_ADDRESS c:\program files (x86)\microsoft office\root\office16\gkword.dll function = 626, address = 0x6856533a True 1
Fn
GET_PROC_ADDRESS c:\windows\syswow64\advapi32.dll function = DuplicateTokenEx, address = 0x7647ca24 True 1
Fn
Com (4903)
+
Operation Class Interface Additional Information Success Count Logfile
CREATE UserForm IClassFactory cls_context = CLSCTX_INPROC_SERVER, CLSCTX_INPROC_HANDLER True 1
Fn
CREATE {172BDDF8-CEEA-11D1-8B05-00600806D9B6} {0000011A-0000-0000-C000-000000000046} False 1
Fn
CREATE WinMGMTS IClassFactory True 1
Fn
CREATE WbemLocator IWbemLocator cls_context = CLSCTX_INPROC_SERVER True 1
Fn
CREATE WbemDefPath IWbemPath cls_context = CLSCTX_INPROC_SERVER True 5
Fn
QUERY ITypeLib new_interface = {CACC1E8A-622B-11D2-AA78-00C04F9901D2} False 4
Fn
QUERY ITypeLib new_interface = {CACC1E84-622B-11D2-AA78-00C04F9901D2} False 14
Fn
QUERY ICreateTypeLib2 new_interface = ITypeLib True 1
Fn
QUERY ITypeInfo new_interface = {CACC1E82-622B-11D2-AA78-00C04F9901D2} False 11
Fn
QUERY ITypeInfo new_interface = {CACC1E83-622B-11D2-AA78-00C04F9901D2} False 1
Fn
QUERY ITypeInfo new_interface = ITypeInfo2 True 1
Fn
QUERY ITypeInfo new_interface = {CACC1E88-622B-11D2-AA78-00C04F9901D2} False 3
Fn
QUERY ITypeInfo new_interface = {CACC1E82-622B-11D2-AA78-00C04F9901D2} False 10
Fn
QUERY ITypeInfo new_interface = {CACC1E83-622B-11D2-AA78-00C04F9901D2} False 9
Fn
QUERY ITypeInfo new_interface = ITypeInfo2 True 1
Fn
QUERY ITypeInfo new_interface = {CACC1E82-622B-11D2-AA78-00C04F9901D2} False 5
Fn
QUERY ITypeInfo new_interface = {CACC1E83-622B-11D2-AA78-00C04F9901D2} False 4
Fn
QUERY ITypeInfo new_interface = ITypeInfo2 True 20
Fn
QUERY ITypeInfo new_interface = {CACC1E82-622B-11D2-AA78-00C04F9901D2} False 145
Fn
QUERY ITypeInfo new_interface = {CACC1E83-622B-11D2-AA78-00C04F9901D2} False 126
Fn
QUERY UserForm IClassFactory new_interface = IUnknown, True 1
Fn
QUERY UserForm IUnknown new_interface = IDispatch True 3
Fn
QUERY UserForm IUnknown new_interface = {468CFB80-B4F9-11CF-80DD-00AA00614895} True 1
Fn
QUERY ITypeInfo new_interface = {CACC1E88-622B-11D2-AA78-00C04F9901D2} False 3
Fn
QUERY ITypeInfo new_interface = ITypeInfo2 True 2
Fn
QUERY ITypeInfo new_interface = {CACC1E89-622B-11D2-AA78-00C04F9901D2} False 2
Fn
QUERY ITypeInfo new_interface = {CACC1E88-622B-11D2-AA78-00C04F9901D2} False 2
Fn
QUERY ITypeInfo new_interface = {CACC1E89-622B-11D2-AA78-00C04F9901D2} False 1
Fn
QUERY WinMGMTS IClassFactory new_interface = IParseDisplayName, True 1
Fn
QUERY WbemLocator IWbemServices new_interface = IClientSecurity True 2
Fn
QUERY WbemLocator IUnknown new_interface = IClientSecurity True 3
Fn
QUERY WbemLocator IUnknown new_interface = IUnknown True 1
Fn
QUERY WbemDefPath IWbemPath new_interface = IUnknown True 1
Fn
QUERY UserForm IUnknown new_interface = {F27BE360-1B98-11CF-84FC-00AA00A71DCB} False 1
Fn
METHOD ITypeLib method = AddRef False 136
Fn
METHOD ITypeComp method = AddRef False 10
Fn
METHOD ICreateTypeLib2 method = SetGuid True 1
Fn
METHOD ICreateTypeLib2 method = SetLcid True 1
Fn
METHOD ICreateTypeLib2 method = SetLibFlags True 1
Fn
METHOD ICreateTypeLib2 method = SetVersion True 1
Fn
METHOD ICreateTypeLib2 method = SetName True 1
Fn
METHOD ICreateTypeLib2 method = SetDocString True 1
Fn
METHOD ICreateTypeLib2 method = SetHelpContext True 1
Fn
METHOD ICreateTypeLib2 method = SetHelpFileName True 1
Fn
METHOD ITypeLib method = RemoteGetTypeInfoCount False 1
Fn
METHOD ITypeLib new_interface = ITypeInfo, method = GetTypeInfo True 292
Fn
METHOD ITypeInfo method = RemoteGetTypeAttr True 284
Fn
METHOD ITypeInfo method = LocalReleaseTypeAttr False 284
Fn
METHOD ITypeInfo method = RemoteGetVarDesc True 199
Fn
METHOD ITypeInfo method = RemoteGetNames True 199
Fn
METHOD ITypeInfo method = GetMops True 199
Fn
METHOD ITypeInfo method = RemoteGetDocumentation True 199
Fn
METHOD ITypeInfo method = LocalReleaseVarDesc False 199
Fn
METHOD ITypeInfo method = GetImplTypeFlags True 112
Fn
METHOD ICreateTypeLib2 method = SaveAllChanges True 1
Fn
METHOD ITypeInfo method = GetRefTypeOfImplType True 14
Fn
METHOD ITypeInfo new_interface = ITypeInfo, method = GetRefTypeInfo True 15
Fn
METHOD ITypeInfo method = RemoteGetTypeAttr True 17
Fn
METHOD ITypeInfo method = LocalReleaseTypeAttr False 17
Fn
METHOD ITypeComp method = RemoteBind True 571
Fn
METHOD ITypeInfo method = AddRef False 15
Fn
METHOD ITypeInfo new_interface = ITypeComp, method = GetTypeComp True 1
Fn
METHOD ITypeComp method = AddRef False 7
Fn
METHOD ITypeComp new_interface = ITypeInfo, method = RemoteBind True 1
Fn
METHOD ITypeInfo method = GetFuncIndexOfMemId True 1
Fn
METHOD ITypeInfo method = GetFuncCustData True 1
Fn
METHOD ITypeInfo method = LocalReleaseFuncDesc False 1
Fn
METHOD ITypeComp new_interface = ITypeInfo, method = RemoteBind True 21
Fn
METHOD ITypeInfo new_interface = ITypeLib, method = RemoteGetContainingTypeLib True 3
Fn
METHOD ITypeLib method = RemoteGetLibAttr True 3
Fn
METHOD ITypeLib method = RemoteGetDocumentation True 3
Fn
METHOD ITypeLib method = AddRef False 1
Fn
METHOD ITypeLib method = LocalReleaseTLibAttr False 3
Fn
METHOD ITypeLib method = RemoteGetLibAttr True 1
Fn
METHOD ITypeLib method = RemoteGetDocumentation True 1
Fn
METHOD ITypeLib method = AddRef False 1
Fn
METHOD ITypeLib method = LocalReleaseTLibAttr False 1
Fn
METHOD ITypeInfo new_interface = ITypeComp, method = GetTypeComp True 1
Fn
METHOD ITypeComp method = AddRef False 148
Fn
METHOD ITypeComp new_interface = ITypeInfo, method = RemoteBind True 2
Fn
METHOD ITypeInfo method = RemoteGetTypeAttr True 2
Fn
METHOD ITypeInfo method = LocalReleaseTypeAttr False 2
Fn
METHOD ITypeInfo method = GetFuncIndexOfMemId True 1
Fn
METHOD ITypeInfo method = GetFuncCustData True 1
Fn
METHOD ITypeInfo method = LocalReleaseFuncDesc False 1
Fn
METHOD ITypeInfo method = RemoteGetTypeAttr True 21
Fn
METHOD ITypeInfo method = LocalReleaseTypeAttr False 21
Fn
METHOD ITypeInfo method = GetFuncIndexOfMemId True 20
Fn
METHOD ITypeInfo method = GetFuncCustData True 18
Fn
METHOD ITypeInfo method = LocalReleaseFuncDesc False 18
Fn
METHOD ITypeInfo new_interface = ITypeLib, method = RemoteGetContainingTypeLib True 87
Fn
METHOD ITypeInfo method = RemoteGetDllEntry True 255
Fn
METHOD UserForm IClassFactory new_interface = IUnknown, method = CreateInstance True 1
Fn
METHOD UserForm IUnknown method = AddRef True 3
Fn
METHOD ITypeComp method = RemoteBind True 6
Fn
METHOD ITypeInfo method = GetParamCustData True 2
Fn
METHOD ITypeInfo method = AddRef False 28
Fn
METHOD ITypeInfo method = GetFuncIndexOfMemId True 1
Fn
METHOD ITypeInfo method = GetFuncCustData True 1
Fn
METHOD ITypeInfo method = LocalReleaseFuncDesc False 1
Fn
METHOD ITypeInfo method = GetTypeKind True 1
Fn
METHOD ITypeInfo method = LocalReleaseVarDesc False 2
Fn
METHOD ITypeInfo new_interface = ITypeInfo, method = GetRefTypeInfo True 1
Fn
METHOD WinMGMTS IClassFactory new_interface = IParseDisplayName, method = CreateInstance True 1
Fn
METHOD WinMGMTS IParseDisplayName new_interface = IMoniker, method = ParseDisplayName True 1
Fn
METHOD WbemDefPath IWbemPath method = SetText True 4
Fn
METHOD WbemDefPath IWbemPath method = GetNamespaceCount True 2
Fn
METHOD WbemDefPath IWbemPath method = GetText True 4
Fn
METHOD WbemDefPath IWbemPath method = GetInfo True 4
Fn
METHOD WbemDefPath IWbemPath method = GetServer True 2
Fn
METHOD WbemDefPath IWbemPath method = SetServer True 1
Fn
METHOD WbemDefPath IWbemPath method = RemoveAllNamespaces True 1
Fn
METHOD WbemDefPath IWbemPath method = GetNamespaceAt True 4
Fn
METHOD WbemDefPath IWbemPath method = SetNamespaceAt True 2
Fn
METHOD WbemLocator IWbemLocator new_interface = IWbemServices, method = ConnectServer True 1
Fn
METHOD WbemLocator IClientSecurity method = QueryBlanket True 3
Fn
METHOD WbemLocator IClientSecurity new_interface = IUnknown, method = CopyProxy True 1
Fn
METHOD WbemLocator IClientSecurity method = SetBlanket True 1
Fn
METHOD WbemLocator IUnknown method = AddRef False 7
Fn
METHOD WbemDefPath IWbemPath method = AddRef False 1
Fn
METHOD ITypeLib new_interface = ITypeInfo, method = GetTypeInfoOfGuid True 7
Fn
METHOD ITypeInfo method = LocalInvoke True 4
Fn
METHOD WbemLocator IUnknown new_interface = IWbemClassObject, method = GetObject True 1
Fn
METHOD WbemLocator IWbemClassObject method = AddRef False 6
Fn
METHOD WbemLocator IWbemClassObject method = Get True 1
Fn
METHOD WbemLocator IWbemClassObject method = BeginMethodEnumeration True 1
Fn
METHOD WbemLocator IWbemClassObject method = NextMethod True 6
Fn
METHOD WbemLocator IWbemClassObject method = NextMethod False 1
Fn
METHOD WbemLocator IWbemClassObject method = EndMethodEnumeration True 1
Fn
METHOD WbemLocator IWbemClassObject method = GetMethod True 1
Fn
METHOD WbemLocator IWbemClassObject new_interface = IWbemClassObject, method = GetMethod True 1
Fn
METHOD WbemLocator IWbemClassObject method = AddRef False 2
Fn
METHOD WbemLocator IWbemClassObject new_interface = IWbemClassObject, method = SpawnInstance True 1
Fn
METHOD WbemLocator IWbemClassObject method = AddRef False 6
Fn
METHOD WbemLocator IWbemClassObject method = Get True 4
Fn
METHOD WbemLocator IWbemClassObject method = Put True 1
Fn
METHOD WbemLocator IWbemClassObject method = EndEnumeration True 1
Fn
METHOD ITypeInfo new_interface = IWbemClassObject, method = LocalInvoke True 1
Fn
METHOD WbemLocator IUnknown new_interface = IWbemClassObject, method = ExecMethod True 1
Fn
METHOD WbemLocator IWbemClassObject method = EndMethodEnumeration False 1
Fn
Registry (30)
+
Operation Key Additional Information Success Count Logfile
OPEN_KEY HKEY_CLASSES_ROOT\CLSID\{C62A69F0-16DC-11CE-9E98-00AA00574A4F}\DesignerFeatures False 1
Fn
OPEN_KEY HKEY_CLASSES_ROOT\Clsid\{C62A69F0-16DC-11CE-9E98-00AA00574A4F}\InprocServer32 True 1
Fn
OPEN_KEY HKEY_CLASSES_ROOT\Typelib True 1
Fn
OPEN_KEY HKEY_CLASSES_ROOT\Typelib\{0D452EE1-E08F-101A-852E-02608C4D0BB4} True 1
Fn
OPEN_KEY HKEY_CURRENT_USER\Software\Microsoft\VBA\7.1\Common True 21
Fn
OPEN_KEY HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Scripting True 1
Fn
READ_VALUE HKEY_CLASSES_ROOT\Clsid\{C62A69F0-16DC-11CE-9E98-00AA00574A4F}\InprocServer32 value_name = ThreadingModel, data_ident_out = 65 True 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\VBA\7.1\Common value_name = PropertiesWindow, data_ident_out = 90 False 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\VBA\7.1\Common value_name = MainWindow, data_ident_out = 116 False 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Scripting value_name = Default Impersonation Level, data_ident_out = 3 True 1
Fn
Window (3)
+
Operation Window Name Additional Information Success Count Logfile
SET_ATTRIBUTE True 2
Fn
SET_ATTRIBUTE True 1
Fn
Keyboard (17)
+
Operation Virtual Key Code Additional Information Success Count Logfile
READ VK_CANCEL result_out = 0 True 17
Fn
System (1)
+
Operation Information Success Count Logfile
SET_NAMED_PROPERTY named_property = C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\convincingly.exe True 1
Fn
Process #2: convincingly.exe
(Host: 24632, Network: 0)
+
Information Value
ID / OS PID #2 / 0x998
OS Parent PID 0x8f8 (c:\windows\system32\wbem\wmiprvse.exe)
Initial Working Directory C:\Windows\system32
File Name c:\users\hjrd1koky ds8lujv\appdata\roaming\convincingly.exe
Command Line "C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\convincingly.exe"
Monitor Start Time: 00:00:41, Reason: Modified File
Unmonitor End Time: 00:01:00, Reason: Terminated
Monitor Duration 00:00:19
OS Thread IDs
# 20
0x 99C
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000020000 0x00020000 0x0002ffff Private Memory Readable, Writable True False False
private_0x0000000000030000 0x00030000 0x00031fff Private Memory Readable, Writable True False False
private_0x0000000000030000 0x00030000 0x00030fff Private Memory Readable, Writable True False False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000000050000 0x00050000 0x0008ffff Private Memory Readable, Writable True False False
private_0x0000000000090000 0x00090000 0x0018ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000190000 0x00190000 0x00193fff Pagefile Backed Memory Readable True False False
locale.nls 0x001a0000 0x00206fff Memory Mapped File Readable False False False
private_0x0000000000210000 0x00210000 0x00210fff Private Memory Readable, Writable True False False
private_0x0000000000220000 0x00220000 0x00224fff Private Memory Readable, Writable, Executable True False False
private_0x00000000002c0000 0x002c0000 0x002cffff Private Memory Readable, Writable True False False
private_0x0000000000320000 0x00320000 0x0039ffff Private Memory Readable, Writable True False False
convincingly.exe 0x00400000 0x00415fff Memory Mapped File Readable, Writable, Executable True True False
private_0x00000000004e0000 0x004e0000 0x004effff Private Memory Readable, Writable True False False
private_0x00000000005a0000 0x005a0000 0x0069ffff Private Memory Readable, Writable True False False
pagefile_0x00000000006a0000 0x006a0000 0x00827fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000830000 0x00830000 0x009b0fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000009c0000 0x009c0000 0x01dbffff Pagefile Backed Memory Readable True False False
private_0x0000000001fa0000 0x01fa0000 0x01faffff Private Memory Readable, Writable True False False
comctl32.dll 0x67580000 0x67603fff Memory Mapped File Readable, Writable, Executable False False False
winspool.drv 0x69300000 0x69350fff Memory Mapped File Readable, Writable, Executable False False False
wow64win.dll 0x75090000 0x750ebfff Memory Mapped File Readable, Writable, Executable False False False
wow64.dll 0x750f0000 0x7512efff Memory Mapped File Readable, Writable, Executable False False False
wow64cpu.dll 0x75680000 0x75687fff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x756c0000 0x756cbfff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x756d0000 0x7572ffff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x75730000 0x7581ffff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x759e0000 0x75a25fff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x75a30000 0x75accfff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x75b00000 0x75b09fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75b10000 0x75bdbfff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x75e10000 0x75f0ffff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76040000 0x760ebfff Memory Mapped File Readable, Writable, Executable False False False
comdlg32.dll 0x76180000 0x761fafff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x76220000 0x7627ffff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76280000 0x7630ffff Memory Mapped File Readable, Writable, Executable False False False
shlwapi.dll 0x76410000 0x76466fff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76470000 0x7650ffff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x76530000 0x7663ffff Memory Mapped File Readable, Writable, Executable False False False
shell32.dll 0x76970000 0x775b9fff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x77610000 0x77628fff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000077770000 0x77770000 0x77869fff Private Memory Readable, Writable, Executable True False False
private_0x0000000077870000 0x77870000 0x7798efff Private Memory Readable, Writable, Executable True False False
ntdll.dll 0x77990000 0x77b38fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77b70000 0x77ceffff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007efb0000 0x7efb0000 0x7efd2fff Pagefile Backed Memory Readable True False False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable True False False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable True False False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable True False False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
pagefile_0x000000007efe0000 0x7efe0000 0x7f0dffff Pagefile Backed Memory Readable True False False
private_0x000000007f0e0000 0x7f0e0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True False False
private_0x000000007fff0000 0x7fff0000 0x7fffffeffff Private Memory Readable True False False
Host Behavior
File (4)
+
Operation Filename Additional Information Success Count Logfile
CREATE c:\windows\system32\&hdgf$w#gsrghregrw share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, create_disposition = OPEN_EXISTING False 1
Fn
OPEN STD_INPUT_HANDLE True 1
Fn
OPEN STD_OUTPUT_HANDLE True 1
Fn
OPEN STD_ERROR_HANDLE True 1
Fn
Process (1)
+
Operation Process Name Additional Information Success Count Logfile
CREATE C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\convincingly.exe os_tid = 0x9c8, os_pid = 0x9c4, creation_flags = CREATE_SUSPENDED, show_window = SW_HIDE True 1
Fn
Memory (4)
+
Operation Address Additional Information Success Count Logfile
ALLOC 0x400000 process_name = C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\convincingly.exe, os_pid = 0x9c4, size = 24576, allocation_type = MEM_COMMIT, MEM_RESERVE, protection = PAGE_EXECUTE_READWRITE True 1
Fn
WRITE 0x400000 process_name = C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\convincingly.exe, os_pid = 0x9c4, size = 512 True 1
Fn
Data
WRITE 0x401000 process_name = C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\convincingly.exe, os_pid = 0x9c4, size = 16384 True 1
Fn
Data
WRITE 0x405000 process_name = C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\convincingly.exe, os_pid = 0x9c4, size = 512 True 1
Fn
Data
Thread (3)
+
Operation Process Name Additional Information Success Count Logfile
RESUME c:\users\hjrd1koky ds8lujv\appdata\roaming\convincingly.exe os_tid = 0x9c8, os_pid = 0x9c4 True 1
Fn
GET_CONTEXT 0x9c8 True 1
Fn
SET_CONTEXT c:\users\hjrd1koky ds8lujv\appdata\roaming\convincingly.exe os_tid = 0x9c8, os_pid = 0x9c4 True 1
Fn
Module (1034)
+
Operation Module Additional Information Success Count Logfile
LOAD kernel32 base_address = 0x76530000 True 1
Fn
GET_HANDLE c:\windows\syswow64\kernel32.dll base_address = 0x76530000 True 11
Fn
GET_HANDLE c:\users\hjrd1koky ds8lujv\appdata\roaming\convincingly.exe base_address = 0x400000 True 999
Fn
GET_HANDLE c:\windows\syswow64\ntdll.dll base_address = 0x77b70000 True 1
Fn
UNMAP C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\convincingly.exe os_pid = 0x9c4, base_address = 0x400000 True 1
Fn
GET_FILENAME C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\convincingly.exe True 2
Fn
GET_PROC_ADDRESS c:\windows\syswow64\kernel32.dll function = FlsAlloc, address = 0x76544f2b True 1
Fn
GET_PROC_ADDRESS c:\windows\syswow64\kernel32.dll function = FlsGetValue, address = 0x76541252 True 1
Fn
GET_PROC_ADDRESS c:\windows\syswow64\kernel32.dll function = FlsSetValue, address = 0x76544208 True 1
Fn
GET_PROC_ADDRESS c:\windows\syswow64\kernel32.dll function = FlsFree, address = 0x7654359f True 1
Fn
GET_PROC_ADDRESS c:\windows\syswow64\kernel32.dll function = EncodePointer, address = 0x77bb0fcb True 8
Fn
GET_PROC_ADDRESS c:\windows\syswow64\kernel32.dll function = DecodePointer, address = 0x77ba9d35 True 3
Fn
GET_PROC_ADDRESS c:\windows\syswow64\kernel32.dll function = QueryPerformanceFrequency, address = 0x765441f0 True 1
Fn
GET_PROC_ADDRESS c:\windows\syswow64\kernel32.dll function = QueryPerformanceCounter, address = 0x76541725 True 1
Fn
GET_PROC_ADDRESS c:\windows\syswow64\kernel32.dll function = IsBadCodePtr, address = 0x76562b34 True 1
Fn
GET_PROC_ADDRESS c:\windows\syswow64\ntdll.dll function = NtUnmapViewOfSection, address = 0x77b8fc70 True 1
Fn
Driver (23586)
+
Operation Driver Additional Information Success Count Logfile
CONTROL control_code = 0x0 False 23586
Fn
Process #3: convincingly.exe
(Host: 13, Network: 0)
+
Information Value
ID / OS PID #3 / 0x9c4
OS Parent PID 0x998 (c:\users\hjrd1koky ds8lujv\appdata\roaming\convincingly.exe)
Initial Working Directory C:\Windows\system32
File Name c:\users\hjrd1koky ds8lujv\appdata\roaming\convincingly.exe
Command Line "C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\convincingly.exe"
Monitor Start Time: 00:00:59, Reason: Child Process
Unmonitor End Time: 00:01:00, Reason: Terminated
Monitor Duration 00:00:01
OS Thread IDs
# 22
0x 9C8
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000020000 0x00020000 0x00020fff Private Memory Readable, Writable True False False
private_0x0000000000030000 0x00030000 0x00031fff Private Memory Readable, Writable True False False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000000050000 0x00050000 0x0008ffff Private Memory Readable, Writable True False False
private_0x0000000000090000 0x00090000 0x0018ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000190000 0x00190000 0x00193fff Pagefile Backed Memory Readable True False False
locale.nls 0x001a0000 0x00206fff Memory Mapped File Readable False False False
private_0x0000000000330000 0x00330000 0x0033ffff Private Memory Readable, Writable True False False
private_0x0000000000360000 0x00360000 0x003dffff Private Memory Readable, Writable True False False
private_0x0000000000400000 0x00400000 0x00405fff Private Memory Readable, Writable, Executable True False False
private_0x00000000005d0000 0x005d0000 0x006cffff Private Memory Readable, Writable True False False
SortDefault.nls 0x006d0000 0x0099efff Memory Mapped File Readable False False False
wow64win.dll 0x75090000 0x750ebfff Memory Mapped File Readable, Writable, Executable False False False
wow64.dll 0x750f0000 0x7512efff Memory Mapped File Readable, Writable, Executable False False False
wow64cpu.dll 0x75680000 0x75687fff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x756c0000 0x756cbfff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x756d0000 0x7572ffff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x75730000 0x7581ffff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x759e0000 0x75a25fff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76040000 0x760ebfff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76470000 0x7650ffff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x76530000 0x7663ffff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x77610000 0x77628fff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000077770000 0x77770000 0x77869fff Private Memory Readable, Writable, Executable True False False
private_0x0000000077870000 0x77870000 0x7798efff Private Memory Readable, Writable, Executable True False False
ntdll.dll 0x77990000 0x77b38fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77b70000 0x77ceffff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007efb0000 0x7efb0000 0x7efd2fff Pagefile Backed Memory Readable True False False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable True False False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable True False False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable True False False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
pagefile_0x000000007efe0000 0x7efe0000 0x7f0dffff Pagefile Backed Memory Readable True False False
private_0x000000007f0e0000 0x7f0e0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True False False
private_0x000000007fff0000 0x7fff0000 0x7fffffeffff Private Memory Readable True False False
Injection Information
+
Injection Type Source Process Source Os Thread ID Injection Info Success Count Logfile
Modify Memory c:\users\hjrd1koky ds8lujv\appdata\roaming\convincingly.exe 0x99c address = 0x400000, size = 512 True 1
Fn
Data
Modify Memory c:\users\hjrd1koky ds8lujv\appdata\roaming\convincingly.exe 0x99c address = 0x401000, size = 16384 True 1
Fn
Data
Modify Memory c:\users\hjrd1koky ds8lujv\appdata\roaming\convincingly.exe 0x99c address = 0x405000, size = 512 True 1
Fn
Data
Modify Control Flow c:\users\hjrd1koky ds8lujv\appdata\roaming\convincingly.exe 0x99c os_thread_id = 0x9c8 True 1
Fn
Host Behavior
Process (3)
+
Operation Process Name Additional Information Success Count Logfile
CREATE C:\Windows\SysWOW64\explorer.exe os_tid = 0x9d4, os_pid = 0x9d0, creation_flags = CREATE_SUSPENDED, show_window = SW_HIDE True 1
Fn
OPEN_TOKEN c:\users\hjrd1koky ds8lujv\appdata\roaming\convincingly.exe os_pid = 0x9c4, desired_access = PROCESS_VM_OPERATION, desired_access = PROCESS_VM_OPERATION True 1
Fn
GET_INFO C:\Windows\SysWOW64\explorer.exe os_pid = 0x9d0 True 1
Fn
Memory (3)
+
Operation Address Additional Information Success Count Logfile
READ 0x7efde008 process_name = C:\Windows\SysWOW64\explorer.exe, os_pid = 0x9d0, size = 4 True 1
Fn
Data
READ 0x1a0000 process_name = C:\Windows\SysWOW64\explorer.exe, os_pid = 0x9d0, size = 1280 True 1
Fn
Data
READ 0x1a0000 process_name = C:\Windows\SysWOW64\explorer.exe, os_pid = 0x9d0, size = 2625536 True 1
Fn
Thread (1)
+
Operation Process Name Additional Information Success Count Logfile
RESUME c:\windows\syswow64\explorer.exe os_tid = 0x9d4, os_pid = 0x9d0 True 1
Fn
Module (6)
+
Operation Module Additional Information Success Count Logfile
LOAD advapi32.dll base_address = 0x76470000 True 1
Fn
CREATE_MAPPING module_name = Nameless FileMapping, maximum_size = 1638132, protection = PAGE_EXECUTE_READWRITE True 1
Fn
MAP c:\users\hjrd1koky ds8lujv\appdata\roaming\convincingly.exe os_pid = 0x9c4, address = 0xc30000 True 1
Fn
MAP C:\Windows\SysWOW64\explorer.exe os_pid = 0x9d0, address = 0x1a0000 True 1
Fn
UNMAP C:\Windows\SysWOW64\explorer.exe os_pid = 0x9d0, base_address = 0x1a0000 True 1
Fn
GET_FILENAME C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\convincingly.exe True 1
Fn
Process #4: explorer.exe
(Host: 28, Network: 0)
+
Information Value
ID / OS PID #4 / 0x9d0
OS Parent PID 0x9c4 (c:\users\hjrd1koky ds8lujv\appdata\roaming\convincingly.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\syswow64\explorer.exe
Command Line C:\Windows\SysWOW64\explorer.exe
Monitor Start Time: 00:01:00, Reason: Child Process
Unmonitor End Time: 00:01:07, Reason: Terminated
Monitor Duration 00:00:07
OS Thread IDs
# 23
0x 9D4
# 47
0x B3C
# 48
0x B40
# 49
0x B44
# 50
0x B48
# 51
0x B4C
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x00021fff Pagefile Backed Memory Readable True False False
private_0x0000000000030000 0x00030000 0x00031fff Private Memory Readable, Writable True False False
pagefile_0x0000000000030000 0x00030000 0x00036fff Pagefile Backed Memory Readable True False False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000050000 0x00050000 0x00053fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000060000 0x00060000 0x00061fff Pagefile Backed Memory Readable True False False
private_0x0000000000070000 0x00070000 0x000effff Private Memory Readable, Writable True False False
locale.nls 0x000f0000 0x00156fff Memory Mapped File Readable False False False
private_0x0000000000160000 0x00160000 0x0019ffff Private Memory Readable, Writable True False False
explorer.exe 0x001a0000 0x00420fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x00000000001a0000 0x001a0000 0x00420fff Pagefile Backed Memory Readable, Writable, Executable True False False
pagefile_0x0000000000430000 0x00430000 0x00431fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000440000 0x00440000 0x00440fff Private Memory Readable, Writable True False False
private_0x0000000000450000 0x00450000 0x00450fff Private Memory Readable, Writable True False False
private_0x0000000000460000 0x00460000 0x00463fff Private Memory Readable, Writable True False False
private_0x0000000000470000 0x00470000 0x004affff Private Memory Readable, Writable True False False
private_0x00000000004b0000 0x004b0000 0x005affff Private Memory Readable, Writable True False False
private_0x00000000005b0000 0x005b0000 0x005cffff Private Memory Readable, Writable True False False
private_0x00000000005d0000 0x005d0000 0x005d3fff Private Memory Readable, Writable True False False
private_0x00000000005e0000 0x005e0000 0x005e0fff Private Memory Readable, Writable True False False
private_0x00000000005f0000 0x005f0000 0x005f0fff Private Memory Readable, Writable True False False
private_0x00000000005f0000 0x005f0000 0x00602fff Private Memory Readable, Writable True False False
private_0x0000000000610000 0x00610000 0x00610fff Private Memory Readable, Writable True False False
private_0x0000000000620000 0x00620000 0x00620fff Private Memory Readable, Writable True False False
private_0x0000000000630000 0x00630000 0x00630fff Private Memory Readable, Writable True False False
private_0x0000000000640000 0x00640000 0x00640fff Private Memory Readable, Writable True False False
pagefile_0x0000000000650000 0x00650000 0x00650fff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000660000 0x00660000 0x00661fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000670000 0x00670000 0x00670fff Pagefile Backed Memory Readable True False False
private_0x0000000000680000 0x00680000 0x0068ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000690000 0x00690000 0x00817fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000820000 0x00820000 0x009a0fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000009b0000 0x009b0000 0x01daffff Pagefile Backed Memory Readable True False False
pagefile_0x0000000001db0000 0x01db0000 0x021a2fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000021b0000 0x021b0000 0x0228efff Pagefile Backed Memory Readable True False False
pagefile_0x0000000002290000 0x02290000 0x02291fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000022a0000 0x022a0000 0x022a0fff Pagefile Backed Memory Readable True False False
private_0x00000000022b0000 0x022b0000 0x022effff Private Memory Readable, Writable True False False
cversions.2.db 0x022f0000 0x022f3fff Memory Mapped File Readable True False False
{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000004.db 0x02300000 0x02320fff Memory Mapped File Readable True False False
pagefile_0x0000000002330000 0x02330000 0x02330fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000002340000 0x02340000 0x0237ffff Private Memory Readable, Writable True False False
private_0x0000000002380000 0x02380000 0x023bffff Private Memory Readable, Writable True False False
SortDefault.nls 0x023c0000 0x0268efff Memory Mapped File Readable False False False
{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x000000000000000e.db 0x02690000 0x026bffff Memory Mapped File Readable True False False
cversions.2.db 0x026c0000 0x026c3fff Memory Mapped File Readable True False False
pagefile_0x00000000026d0000 0x026d0000 0x026d0fff Pagefile Backed Memory Readable, Writable True False False
private_0x00000000026e0000 0x026e0000 0x0271ffff Private Memory Readable, Writable True False False
{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db 0x02720000 0x02785fff Memory Mapped File Readable True False False
private_0x00000000027e0000 0x027e0000 0x0281ffff Private Memory Readable, Writable True False False
private_0x0000000002820000 0x02820000 0x0285ffff Private Memory Readable, Writable True False False
private_0x0000000002880000 0x02880000 0x028bffff Private Memory Readable, Writable True False False
private_0x0000000002940000 0x02940000 0x0297ffff Private Memory Readable, Writable True False False
private_0x00000000029a0000 0x029a0000 0x029dffff Private Memory Readable, Writable True False False
private_0x00000000029f0000 0x029f0000 0x02a2ffff Private Memory Readable, Writable True False False
private_0x0000000002a30000 0x02a30000 0x02a6ffff Private Memory Readable, Writable True False False
private_0x0000000002ad0000 0x02ad0000 0x02b0ffff Private Memory Readable, Writable True False False
private_0x0000000002b10000 0x02b10000 0x02c0ffff Private Memory Readable, Writable True False False
private_0x0000000010000000 0x10000000 0x10014fff Private Memory Readable, Writable, Executable True False False
ExplorerFrame.dll 0x67030000 0x6719efff Memory Mapped File Readable, Writable, Executable False False False
dui70.dll 0x67250000 0x67301fff Memory Mapped File Readable, Writable, Executable False False False
duser.dll 0x675b0000 0x675defff Memory Mapped File Readable, Writable, Executable False False False
mpr.dll 0x675f0000 0x67601fff Memory Mapped File Readable, Writable, Executable False False False
powrprof.dll 0x687e0000 0x68804fff Memory Mapped File Readable, Writable, Executable False False False
ntmarta.dll 0x691d0000 0x691f0fff Memory Mapped File Readable, Writable, Executable False False False
propsys.dll 0x69200000 0x692f4fff Memory Mapped File Readable, Writable, Executable False False False
secur32.dll 0x69480000 0x69487fff Memory Mapped File Readable, Writable, Executable False False False
uxtheme.dll 0x6f8e0000 0x6f95ffff Memory Mapped File Readable, Writable, Executable False False False
comctl32.dll 0x6f960000 0x6fafdfff Memory Mapped File Readable, Writable, Executable False False False
slc.dll 0x70db0000 0x70db9fff Memory Mapped File Readable, Writable, Executable False False False
GdiPlus.dll 0x72c40000 0x72dcffff Memory Mapped File Readable, Writable, Executable False False False
dwmapi.dll 0x72dd0000 0x72de2fff Memory Mapped File Readable, Writable, Executable False False False
profapi.dll 0x74d60000 0x74d6afff Memory Mapped File Readable, Writable, Executable False False False
wow64win.dll 0x75090000 0x750ebfff Memory Mapped File Readable, Writable, Executable False False False
wow64.dll 0x750f0000 0x7512efff Memory Mapped File Readable, Writable, Executable False False False
wow64cpu.dll 0x75680000 0x75687fff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x756c0000 0x756cbfff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x756d0000 0x7572ffff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x75730000 0x7581ffff Memory Mapped File Readable, Writable, Executable False False False
ole32.dll 0x75880000 0x759dbfff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x759e0000 0x75a25fff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x75a30000 0x75accfff Memory Mapped File Readable, Writable, Executable False False False
cfgmgr32.dll 0x75ad0000 0x75af6fff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x75b00000 0x75b09fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75b10000 0x75bdbfff Memory Mapped File Readable, Writable, Executable False False False
iertutil.dll 0x75be0000 0x75ddafff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x75e10000 0x75f0ffff Memory Mapped File Readable, Writable, Executable False False False
crypt32.dll 0x75f10000 0x7602cfff Memory Mapped File Readable, Writable, Executable False False False
msasn1.dll 0x76030000 0x7603bfff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76040000 0x760ebfff Memory Mapped File Readable, Writable, Executable False False False
clbcatq.dll 0x760f0000 0x76172fff Memory Mapped File Readable, Writable, Executable False False False
devobj.dll 0x76200000 0x76211fff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x76220000 0x7627ffff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76280000 0x7630ffff Memory Mapped File Readable, Writable, Executable False False False
ws2_32.dll 0x763a0000 0x763d4fff Memory Mapped File Readable, Writable, Executable False False False
shlwapi.dll 0x76410000 0x76466fff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76470000 0x7650ffff Memory Mapped File Readable, Writable, Executable False False False
nsi.dll 0x76510000 0x76515fff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x76530000 0x7663ffff Memory Mapped File Readable, Writable, Executable False False False
setupapi.dll 0x76640000 0x767dcfff Memory Mapped File Readable, Writable, Executable False False False
wininet.dll 0x767e0000 0x768d4fff Memory Mapped File Readable, Writable, Executable False False False
oleaut32.dll 0x768e0000 0x7696efff Memory Mapped File Readable, Writable, Executable False False False
shell32.dll 0x76970000 0x775b9fff Memory Mapped File Readable, Writable, Executable False False False
Wldap32.dll 0x775c0000 0x77604fff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x77610000 0x77628fff Memory Mapped File Readable, Writable, Executable False False False
urlmon.dll 0x77630000 0x77765fff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000077770000 0x77770000 0x77869fff Private Memory Readable, Writable, Executable True False False
private_0x0000000077870000 0x77870000 0x7798efff Private Memory Readable, Writable, Executable True False False
ntdll.dll 0x77990000 0x77b38fff Memory Mapped File Readable, Writable, Executable False False False
psapi.dll 0x77b40000 0x77b44fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77b70000 0x77ceffff Memory Mapped File Readable, Writable, Executable False False False
private_0x000000007efa7000 0x7efa7000 0x7efa9fff Private Memory Readable, Writable True False False
private_0x000000007efaa000 0x7efaa000 0x7efacfff Private Memory Readable, Writable True False False
private_0x000000007efad000 0x7efad000 0x7efaffff Private Memory Readable, Writable True False False
pagefile_0x000000007efb0000 0x7efb0000 0x7efd2fff Pagefile Backed Memory Readable True False False
private_0x000000007efd5000 0x7efd5000 0x7efd7fff Private Memory Readable, Writable True False False
private_0x000000007efd8000 0x7efd8000 0x7efdafff Private Memory Readable, Writable True False False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable True False False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable True False False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable True False False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
pagefile_0x000000007efe0000 0x7efe0000 0x7f0dffff Pagefile Backed Memory Readable True False False
private_0x000000007f0e0000 0x7f0e0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True False False
private_0x000000007fff0000 0x7fff0000 0x7fffffeffff Private Memory Readable True False False
Injection Information
+
Injection Type Source Process Source Os Thread ID Injection Info Success Count Logfile
Modify Memory c:\users\hjrd1koky ds8lujv\appdata\roaming\convincingly.exe 0x9c8 address = 0x1a0000, size = 2625536 True 1
Fn
Data
Created Files
+
Filename File Size Hash Values YARA Match Actions
c:\users\hjrd1koky ds8lujv\appdata\roaming\dpx.dll 0.00 KB (0 bytes) MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
False
c:\users\hjrd1koky ds8lujv\appdata\roaming\dpx.dll 251.00 KB (257024 bytes) MD5: 0c0df0f05baea320fa301f34e256e08b
SHA1: 0af69a2dff3208af234b22f3b100363c0c29f9d7
SHA256: 9d6c3cc1138aabec66eabd13905c24170f7f1fe6d7aa5dd6bf51f1d3bf66f03d
False
c:\users\hjrd1koky ds8lujv\appdata\roaming\dpx.dll 251.00 KB (257024 bytes) MD5: 230c01bcc9b3ee3a62457f5273cb2659
SHA1: aea7dac045da8978dd72e80adfb6e50029eb5447
SHA256: 6edcf00bd139af3e079c4ec417af6d733bc7d55ae686fa77de2eb277c0ba7b55
False
Host Behavior
File (7)
+
Operation Filename Additional Information Success Count Logfile
CREATE c:\users\hjrd1koky ds8lujv\appdata\roaming\convincingly.exe desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTING True 1
Fn
CREATE c:\users\hjrd1koky ds8lujv\appdata\roaming\dpx.dll desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTING True 1
Fn
COPY c:\users\hjrd1koky ds8lujv\appdata\roaming\dpx.dll source_file_name = c:\windows\syswow64\dpx.dll, fail_if_exists = 0 True 1
Fn
READ c:\users\hjrd1koky ds8lujv\appdata\roaming\convincingly.exe size = 74752 True 1
Fn
Data
DELETE c:\users\hjrd1koky ds8lujv\appdata\roaming\cabfile.cab True 2
Fn
DELETE c:\users\hjrd1koky ds8lujv\appdata\roaming\dpx.dll True 1
Fn
Process (7)
+
Operation Process Name Additional Information Success Count Logfile
CREATE cmd.exe \c makecab "C:\Windows\SysWOW64\wusa.exe" "C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\cabfile.cab" os_tid = 0x9dc, os_pid = 0x9d8, startup_flags = STARTF_USESHOWWINDOW, show_window = SW_HIDE True 1
Fn
CREATE cmd.exe \c c:\windows\system32\wusa "C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\cabfile.cab" \extract:"C:\Windows\SysWOW64\drivers" os_tid = 0x9fc, os_pid = 0x9f8, startup_flags = STARTF_USESHOWWINDOW, show_window = SW_HIDE True 1
Fn
CREATE cmd.exe \c makecab "C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\dpx.dll" "C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\cabfile.cab" os_tid = 0xab0, os_pid = 0xaac, startup_flags = STARTF_USESHOWWINDOW, show_window = SW_HIDE True 1
Fn
CREATE cmd.exe \c c:\windows\system32\wusa "C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\cabfile.cab" \extract:"C:\Windows\SysWOW64\drivers" os_tid = 0xad0, os_pid = 0xacc, startup_flags = STARTF_USESHOWWINDOW, show_window = SW_HIDE True 1
Fn
CREATE C:\Windows\SysWOW64\drivers\wusa.exe operation = runas, show_window = SW_HIDE True 1
Fn
OPEN_TOKEN c:\users\hjrd1koky ds8lujv\appdata\roaming\convincingly.exe os_pid = 0x9c4, desired_access = PROCESS_VM_OPERATION, desired_access = PROCESS_VM_OPERATION True 2
Fn
Module (14)
+
Operation Module Additional Information Success Count Logfile
LOAD advapi32.dll base_address = 0x76470000 True 1
Fn
LOAD shell32.dll base_address = 0x76970000 True 1
Fn
LOAD user32.dll base_address = 0x75e10000 True 1
Fn
LOAD urlmon.dll base_address = 0x77630000 True 1
Fn
LOAD wininet.dll base_address = 0x767e0000 True 1
Fn
LOAD crypt32.dll base_address = 0x75f10000 True 1
Fn
LOAD mpr.dll base_address = 0x675f0000 True 1
Fn
LOAD ole32.dll base_address = 0x75880000 True 1
Fn
LOAD ws2_32.dll base_address = 0x763a0000 True 1
Fn
LOAD psapi.dll base_address = 0x77b40000 True 1
Fn
CREATE_MAPPING c:\users\hjrd1koky ds8lujv\appdata\roaming\dpx.dll module_name = Nameless FileMapping, maximum_size = 257024, protection = PAGE_READWRITE True 1
Fn
MAP c:\users\hjrd1koky ds8lujv\appdata\roaming\dpx.dll process_name = c:\windows\syswow64\explorer.exe, os_pid = 0x9d0, module_name = Nameless FileMapping, desired_access = FILE_MAP_WRITE, file_offset = 0, address = 0x21b0000 True 1
Fn
UNMAP c:\windows\syswow64\explorer.exe os_pid = 0x9d0, base_address = 0x21b0000 True 1
Fn
GET_FILENAME C:\Windows\SysWOW64\explorer.exe True 1
Fn
Process #5: cmd.exe
(Host: 35, Network: 0)
+
Information Value
ID / OS PID #5 / 0x9d8
OS Parent PID 0x9d0 (c:\windows\syswow64\explorer.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\syswow64\cmd.exe
Command Line cmd.exe /c makecab "C:\Windows\SysWOW64\wusa.exe" "C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\cabfile.cab"
Monitor Start Time: 00:01:00, Reason: Child Process
Unmonitor End Time: 00:01:01, Reason: Terminated
Monitor Duration 00:00:01
OS Thread IDs
# 24
0x 9DC
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000030000 0x00030000 0x00031fff Private Memory Readable, Writable True False False
pagefile_0x0000000000030000 0x00030000 0x00036fff Pagefile Backed Memory Readable True False False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000050000 0x00050000 0x00053fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000060000 0x00060000 0x00060fff Pagefile Backed Memory Readable True False False
locale.nls 0x00070000 0x000d6fff Memory Mapped File Readable False False False
pagefile_0x00000000000e0000 0x000e0000 0x000e1fff Pagefile Backed Memory Readable, Writable True False False
private_0x00000000000f0000 0x000f0000 0x000f0fff Private Memory Readable, Writable True False False
private_0x0000000000100000 0x00100000 0x00100fff Private Memory Readable, Writable True False False
private_0x0000000000190000 0x00190000 0x0019ffff Private Memory Readable, Writable True False False
private_0x00000000001a0000 0x001a0000 0x001dffff Private Memory Readable, Writable True False False
private_0x0000000000250000 0x00250000 0x0034ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000350000 0x00350000 0x004d7fff Pagefile Backed Memory Readable True False False
private_0x00000000004f0000 0x004f0000 0x0056ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000570000 0x00570000 0x006f0fff Pagefile Backed Memory Readable True False False
private_0x0000000000710000 0x00710000 0x0080ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000810000 0x00810000 0x01c0ffff Pagefile Backed Memory Readable True False False
pagefile_0x0000000001c10000 0x01c10000 0x01f52fff Pagefile Backed Memory Readable True False False
cmd.exe 0x4a500000 0x4a54bfff Memory Mapped File Readable, Writable, Executable True False False
winbrand.dll 0x675a0000 0x675a6fff Memory Mapped File Readable, Writable, Executable False False False
wow64win.dll 0x75090000 0x750ebfff Memory Mapped File Readable, Writable, Executable False False False
wow64.dll 0x750f0000 0x7512efff Memory Mapped File Readable, Writable, Executable False False False
wow64cpu.dll 0x75680000 0x75687fff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x756c0000 0x756cbfff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x756d0000 0x7572ffff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x75730000 0x7581ffff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x759e0000 0x75a25fff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x75a30000 0x75accfff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x75b00000 0x75b09fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75b10000 0x75bdbfff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x75e10000 0x75f0ffff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76040000 0x760ebfff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x76220000 0x7627ffff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76280000 0x7630ffff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76470000 0x7650ffff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x76530000 0x7663ffff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x77610000 0x77628fff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000077770000 0x77770000 0x77869fff Private Memory Readable, Writable, Executable True False False
private_0x0000000077870000 0x77870000 0x7798efff Private Memory Readable, Writable, Executable True False False
ntdll.dll 0x77990000 0x77b38fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77b70000 0x77ceffff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007efb0000 0x7efb0000 0x7efd2fff Pagefile Backed Memory Readable True False False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable True False False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable True False False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable True False False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
pagefile_0x000000007efe0000 0x7efe0000 0x7f0dffff Pagefile Backed Memory Readable True False False
private_0x000000007f0e0000 0x7f0e0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True False False
private_0x000000007fff0000 0x7fff0000 0x7fffffeffff Private Memory Readable True False False
Host Behavior
File (8)
+
Operation Filename Additional Information Success Count Logfile
OPEN STD_OUTPUT_HANDLE True 5
Fn
OPEN STD_INPUT_HANDLE True 3
Fn
Process (2)
+
Operation Process Name Additional Information Success Count Logfile
CREATE C:\Windows\system32\makecab.exe os_tid = 0x9f4, os_pid = 0x9f0, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, current_directory = C:\Windows\system32, show_window = SW_SHOWNORMAL True 1
Fn
SET_CURDIR c:\windows\syswow64\cmd.exe os_pid = 0x9d8, new_path_name = c:\windows\system32 True 1
Fn
Module (8)
+
Operation Module Additional Information Success Count Logfile
GET_HANDLE c:\windows\syswow64\cmd.exe base_address = 0x4a500000 True 1
Fn
GET_HANDLE c:\windows\syswow64\kernel32.dll base_address = 0x76530000 True 2
Fn
GET_FILENAME C:\Windows\SysWOW64\cmd.exe True 1
Fn
GET_PROC_ADDRESS c:\windows\syswow64\kernel32.dll function = SetThreadUILanguage, address = 0x7655a84f True 1
Fn
GET_PROC_ADDRESS c:\windows\syswow64\kernel32.dll function = CopyFileExW, address = 0x76563b92 True 1
Fn
GET_PROC_ADDRESS c:\windows\syswow64\kernel32.dll function = IsDebuggerPresent, address = 0x76544a5d True 1
Fn
GET_PROC_ADDRESS c:\windows\syswow64\kernel32.dll function = SetConsoleInputExeNameW, address = 0x7655a79d True 1
Fn
Registry (17)
+
Operation Key Additional Information Success Count Logfile
OPEN_KEY HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System False 1
Fn
OPEN_KEY HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor True 1
Fn
OPEN_KEY HKEY_CURRENT_USER\Software\Microsoft\Command Processor True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data_ident_out = 0 False 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = EnableExtensions, data_ident_out = 1 True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DelayedExpansion, data_ident_out = 1 False 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DefaultColor, data_ident_out = 0 True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = CompletionChar, data_ident_out = 64 True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = PathCompletionChar, data_ident_out = 64 True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = AutoRun, data_ident_out = 64 False 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data_ident_out = 64 False 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = EnableExtensions, data_ident_out = 1 True 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DelayedExpansion, data_ident_out = 1 False 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DefaultColor, data_ident_out = 0 True 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = CompletionChar, data_ident_out = 9 True 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = PathCompletionChar, data_ident_out = 9 True 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = AutoRun, data_ident_out = 9 False 1
Fn
Process #6: makecab.exe
+
Information Value
ID / OS PID #6 / 0x9f0
OS Parent PID 0x9d8 (c:\windows\syswow64\cmd.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\syswow64\makecab.exe
Command Line makecab "C:\Windows\SysWOW64\wusa.exe" "C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\cabfile.cab"
Monitor Start Time: 00:01:01, Reason: Child Process
Unmonitor End Time: 00:01:01, Reason: Terminated
Monitor Duration 00:00:00
OS Thread IDs
# 25
0x 9F4
Remarks No high level activity detected in monitored regions
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000030000 0x00030000 0x00031fff Private Memory Readable, Writable True False False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000050000 0x00050000 0x00053fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000060000 0x00060000 0x00061fff Pagefile Backed Memory Readable True False False
locale.nls 0x00070000 0x000d6fff Memory Mapped File Readable False False False
private_0x00000000000e0000 0x000e0000 0x0011ffff Private Memory Readable, Writable True False False
private_0x0000000000190000 0x00190000 0x0020ffff Private Memory Readable, Writable True False False
private_0x0000000000270000 0x00270000 0x002affff Private Memory Readable, Writable True False False
private_0x0000000000320000 0x00320000 0x0041ffff Private Memory Readable, Writable True False False
private_0x00000000004b0000 0x004b0000 0x004bffff Private Memory Readable, Writable True False False
pagefile_0x00000000004c0000 0x004c0000 0x00647fff Pagefile Backed Memory Readable True False False
makecab.exe 0x00750000 0x0076afff Memory Mapped File Readable, Writable, Executable False False False
version.dll 0x72df0000 0x72df8fff Memory Mapped File Readable, Writable, Executable False False False
wow64win.dll 0x75090000 0x750ebfff Memory Mapped File Readable, Writable, Executable False False False
wow64.dll 0x750f0000 0x7512efff Memory Mapped File Readable, Writable, Executable False False False
wow64cpu.dll 0x75680000 0x75687fff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x756c0000 0x756cbfff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x756d0000 0x7572ffff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x75730000 0x7581ffff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x759e0000 0x75a25fff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x75a30000 0x75accfff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x75b00000 0x75b09fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75b10000 0x75bdbfff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x75e10000 0x75f0ffff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76040000 0x760ebfff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x76220000 0x7627ffff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76280000 0x7630ffff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76470000 0x7650ffff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x76530000 0x7663ffff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x77610000 0x77628fff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000077770000 0x77770000 0x77869fff Private Memory Readable, Writable, Executable True False False
private_0x0000000077870000 0x77870000 0x7798efff Private Memory Readable, Writable, Executable True False False
ntdll.dll 0x77990000 0x77b38fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77b70000 0x77ceffff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007efb0000 0x7efb0000 0x7efd2fff Pagefile Backed Memory Readable True False False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable True False False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable True False False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable True False False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
pagefile_0x000000007efe0000 0x7efe0000 0x7f0dffff Pagefile Backed Memory Readable True False False
private_0x000000007f0e0000 0x7f0e0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True False False
private_0x000000007fff0000 0x7fff0000 0x7fffffeffff Private Memory Readable True False False
Process #7: cmd.exe
(Host: 38, Network: 0)
+
Information Value
ID / OS PID #7 / 0x9f8
OS Parent PID 0x9d0 (c:\windows\syswow64\explorer.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\syswow64\cmd.exe
Command Line cmd.exe /c c:\windows\system32\wusa "C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\cabfile.cab" /extract:"C:\Windows\SysWOW64\drivers"
Monitor Start Time: 00:01:01, Reason: Child Process
Unmonitor End Time: 00:01:04, Reason: Terminated
Monitor Duration 00:00:03
OS Thread IDs
# 26
0x 9FC
# 28
0x A18
# 29
0x A1C
# 31
0x A28
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000030000 0x00030000 0x00031fff Private Memory Readable, Writable True False False
pagefile_0x0000000000030000 0x00030000 0x00036fff Pagefile Backed Memory Readable True False False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000050000 0x00050000 0x00053fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000060000 0x00060000 0x00060fff Pagefile Backed Memory Readable True False False
locale.nls 0x00070000 0x000d6fff Memory Mapped File Readable False False False
pagefile_0x00000000000e0000 0x000e0000 0x000e1fff Pagefile Backed Memory Readable, Writable True False False
private_0x00000000000f0000 0x000f0000 0x000f0fff Private Memory Readable, Writable True False False
private_0x0000000000100000 0x00100000 0x0017ffff Private Memory Readable, Writable True False False
private_0x0000000000180000 0x00180000 0x00180fff Private Memory Readable, Writable True False False
pagefile_0x0000000000190000 0x00190000 0x00191fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000001a0000 0x001a0000 0x001a0fff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x00000000001b0000 0x001b0000 0x001b1fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000001c0000 0x001c0000 0x001c0fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000001d0000 0x001d0000 0x001d0fff Pagefile Backed Memory Readable True False False
cversions.2.db 0x001e0000 0x001e3fff Memory Mapped File Readable True False False
pagefile_0x00000000001f0000 0x001f0000 0x001f0fff Pagefile Backed Memory Readable, Writable True False False
cversions.2.db 0x00200000 0x00203fff Memory Mapped File Readable True False False
private_0x0000000000210000 0x00210000 0x0024ffff Private Memory Readable, Writable True False False
{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000004.db 0x00250000 0x00270fff Memory Mapped File Readable True False False
{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x000000000000000e.db 0x00280000 0x002affff Memory Mapped File Readable True False False
pagefile_0x00000000002b0000 0x002b0000 0x002b0fff Pagefile Backed Memory Readable, Writable True False False
private_0x00000000002e0000 0x002e0000 0x0031ffff Private Memory Readable, Writable True False False
private_0x0000000000360000 0x00360000 0x0045ffff Private Memory Readable, Writable True False False
{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db 0x00460000 0x004c5fff Memory Mapped File Readable True False False
private_0x00000000004f0000 0x004f0000 0x005effff Private Memory Readable, Writable True False False
pagefile_0x00000000005f0000 0x005f0000 0x006cefff Pagefile Backed Memory Readable True False False
private_0x0000000000770000 0x00770000 0x0077ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000780000 0x00780000 0x00907fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000910000 0x00910000 0x00a90fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000aa0000 0x00aa0000 0x01e9ffff Pagefile Backed Memory Readable True False False
pagefile_0x0000000001ea0000 0x01ea0000 0x021e2fff Pagefile Backed Memory Readable True False False
SortDefault.nls 0x021f0000 0x024befff Memory Mapped File Readable False False False
pagefile_0x00000000024c0000 0x024c0000 0x028b2fff Pagefile Backed Memory Readable True False False
private_0x00000000028c0000 0x028c0000 0x029bffff Private Memory Readable, Writable True False False
private_0x0000000002a00000 0x02a00000 0x02a3ffff Private Memory Readable, Writable True False False
private_0x0000000002a40000 0x02a40000 0x02a7ffff Private Memory Readable, Writable True False False
private_0x0000000002af0000 0x02af0000 0x02b2ffff Private Memory Readable, Writable True False False
private_0x0000000002be0000 0x02be0000 0x02cdffff Private Memory Readable, Writable True False False
private_0x0000000002da0000 0x02da0000 0x02e9ffff Private Memory Readable, Writable True False False
private_0x0000000003070000 0x03070000 0x0316ffff Private Memory Readable, Writable True False False
cmd.exe 0x49dc0000 0x49e0bfff Memory Mapped File Readable, Writable, Executable True False False
winbrand.dll 0x675a0000 0x675a6fff Memory Mapped File Readable, Writable, Executable False False False
mpr.dll 0x675f0000 0x67601fff Memory Mapped File Readable, Writable, Executable False False False
ntmarta.dll 0x691d0000 0x691f0fff Memory Mapped File Readable, Writable, Executable False False False
propsys.dll 0x69200000 0x692f4fff Memory Mapped File Readable, Writable, Executable False False False
uxtheme.dll 0x6f8e0000 0x6f95ffff Memory Mapped File Readable, Writable, Executable False False False
comctl32.dll 0x6f960000 0x6fafdfff Memory Mapped File Readable, Writable, Executable False False False
profapi.dll 0x74d60000 0x74d6afff Memory Mapped File Readable, Writable, Executable False False False
wow64win.dll 0x75090000 0x750ebfff Memory Mapped File Readable, Writable, Executable False False False
wow64.dll 0x750f0000 0x7512efff Memory Mapped File Readable, Writable, Executable False False False
wow64cpu.dll 0x75680000 0x75687fff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x756c0000 0x756cbfff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x756d0000 0x7572ffff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x75730000 0x7581ffff Memory Mapped File Readable, Writable, Executable False False False
ole32.dll 0x75880000 0x759dbfff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x759e0000 0x75a25fff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x75a30000 0x75accfff Memory Mapped File Readable, Writable, Executable False False False
cfgmgr32.dll 0x75ad0000 0x75af6fff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x75b00000 0x75b09fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75b10000 0x75bdbfff Memory Mapped File Readable, Writable, Executable False False False
iertutil.dll 0x75be0000 0x75ddafff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x75e10000 0x75f0ffff Memory Mapped File Readable, Writable, Executable False False False
crypt32.dll 0x75f10000 0x7602cfff Memory Mapped File Readable, Writable, Executable False False False
msasn1.dll 0x76030000 0x7603bfff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76040000 0x760ebfff Memory Mapped File Readable, Writable, Executable False False False
clbcatq.dll 0x760f0000 0x76172fff Memory Mapped File Readable, Writable, Executable False False False
devobj.dll 0x76200000 0x76211fff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x76220000 0x7627ffff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76280000 0x7630ffff Memory Mapped File Readable, Writable, Executable False False False
shlwapi.dll 0x76410000 0x76466fff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76470000 0x7650ffff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x76530000 0x7663ffff Memory Mapped File Readable, Writable, Executable False False False
setupapi.dll 0x76640000 0x767dcfff Memory Mapped File Readable, Writable, Executable False False False
wininet.dll 0x767e0000 0x768d4fff Memory Mapped File Readable, Writable, Executable False False False
oleaut32.dll 0x768e0000 0x7696efff Memory Mapped File Readable, Writable, Executable False False False
shell32.dll 0x76970000 0x775b9fff Memory Mapped File Readable, Writable, Executable False False False
Wldap32.dll 0x775c0000 0x77604fff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x77610000 0x77628fff Memory Mapped File Readable, Writable, Executable False False False
urlmon.dll 0x77630000 0x77765fff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000077770000 0x77770000 0x77869fff Private Memory Readable, Writable, Executable True False False
private_0x0000000077870000 0x77870000 0x7798efff Private Memory Readable, Writable, Executable True False False
ntdll.dll 0x77990000 0x77b38fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77b70000 0x77ceffff Memory Mapped File Readable, Writable, Executable False False False
private_0x000000007efad000 0x7efad000 0x7efaffff Private Memory Readable, Writable True False False
pagefile_0x000000007efb0000 0x7efb0000 0x7efd2fff Pagefile Backed Memory Readable True False False
private_0x000000007efd5000 0x7efd5000 0x7efd7fff Private Memory Readable, Writable True False False
private_0x000000007efd8000 0x7efd8000 0x7efdafff Private Memory Readable, Writable True False False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable True False False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable True False False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable True False False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
pagefile_0x000000007efe0000 0x7efe0000 0x7f0dffff Pagefile Backed Memory Readable True False False
private_0x000000007f0e0000 0x7f0e0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True False False
private_0x000000007fff0000 0x7fff0000 0x7fffffeffff Private Memory Readable True False False
Host Behavior
File (8)
+
Operation Filename Additional Information Success Count Logfile
OPEN STD_OUTPUT_HANDLE True 5
Fn
OPEN STD_INPUT_HANDLE True 3
Fn
Process (3)
+
Operation Process Name Additional Information Success Count Logfile
CREATE c:\windows\system32\wusa.exe os_tid = 0x0, os_pid = 0x0, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, current_directory = C:\Windows\system32, show_window = SW_SHOWNORMAL False 1
Fn
CREATE c:\windows\system32\wusa.exe current_directory = C:\Windows\system32, show_window = SW_SHOWNORMAL True 1
Fn
SET_CURDIR c:\windows\syswow64\cmd.exe os_pid = 0x9f8, new_path_name = c:\windows\system32 True 1
Fn
Module (10)
+
Operation Module Additional Information Success Count Logfile
LOAD SHELL32.dll base_address = 0x76970000 True 1
Fn
GET_HANDLE c:\windows\syswow64\cmd.exe base_address = 0x49dc0000 True 1
Fn
GET_HANDLE c:\windows\syswow64\kernel32.dll base_address = 0x76530000 True 2
Fn
GET_FILENAME C:\Windows\SysWOW64\cmd.exe True 1
Fn
GET_PROC_ADDRESS c:\windows\syswow64\kernel32.dll function = SetThreadUILanguage, address = 0x7655a84f True 1
Fn
GET_PROC_ADDRESS c:\windows\syswow64\kernel32.dll function = CopyFileExW, address = 0x76563b92 True 1
Fn
GET_PROC_ADDRESS c:\windows\syswow64\kernel32.dll function = IsDebuggerPresent, address = 0x76544a5d True 1
Fn
GET_PROC_ADDRESS c:\windows\syswow64\kernel32.dll function = SetConsoleInputExeNameW, address = 0x7655a79d True 1
Fn
GET_PROC_ADDRESS c:\windows\syswow64\shell32.dll function = ShellExecuteExW, address = 0x76991e46 True 1
Fn
Registry (17)
+
Operation Key Additional Information Success Count Logfile
OPEN_KEY HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System False 1
Fn
OPEN_KEY HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor True 1
Fn
OPEN_KEY HKEY_CURRENT_USER\Software\Microsoft\Command Processor True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data_ident_out = 0 False 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = EnableExtensions, data_ident_out = 1 True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DelayedExpansion, data_ident_out = 1 False 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DefaultColor, data_ident_out = 0 True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = CompletionChar, data_ident_out = 64 True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = PathCompletionChar, data_ident_out = 64 True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = AutoRun, data_ident_out = 64 False 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data_ident_out = 64 False 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = EnableExtensions, data_ident_out = 1 True 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DelayedExpansion, data_ident_out = 1 False 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DefaultColor, data_ident_out = 0 True 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = CompletionChar, data_ident_out = 9 True 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = PathCompletionChar, data_ident_out = 9 True 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = AutoRun, data_ident_out = 9 False 1
Fn
Process #8: wusa.exe
+
Information Value
ID / OS PID #8 / 0xa10
OS Parent PID 0x9f8 (c:\windows\syswow64\cmd.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\syswow64\wusa.exe
Command Line c:\windows\system32\wusa "C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\cabfile.cab" /extract:"C:\Windows\SysWOW64\drivers"
Monitor Start Time: 00:01:01, Reason: Child Process
Unmonitor End Time: 00:01:02, Reason: Terminated
Monitor Duration 00:00:01
OS Thread IDs
# 27
0x A14
Remarks No high level activity detected in monitored regions
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
private_0x0000000000030000 0x00030000 0x00031fff Private Memory Readable, Writable True False False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000050000 0x00050000 0x00053fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000060000 0x00060000 0x00062fff Pagefile Backed Memory Readable True False False
private_0x00000000000c0000 0x000c0000 0x000fffff Private Memory Readable, Writable True False False
private_0x0000000000140000 0x00140000 0x0017ffff Private Memory Readable, Writable True False False
wusa.exe 0x00f50000 0x00f9ffff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77990000 0x77b38fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77b70000 0x77ceffff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007efb0000 0x7efb0000 0x7efd2fff Pagefile Backed Memory Readable True False False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable True False False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable True False False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable True False False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True False False
private_0x000000007fff0000 0x7fff0000 0x7fffffeffff Private Memory Readable True False False
Process #9: wusa.exe
+
Information Value
ID / OS PID #9 / 0xa20
OS Parent PID 0x9f8 (c:\windows\syswow64\cmd.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\syswow64\wusa.exe
Command Line "C:\windows\system32\wusa.exe" "C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\cabfile.cab" /extract:"C:\Windows\SysWOW64\drivers"
Monitor Start Time: 00:01:02, Reason: Child Process
Unmonitor End Time: 00:01:02, Reason: Terminated
Monitor Duration 00:00:00
OS Thread IDs
# 30
0x A24
Remarks No high level activity detected in monitored regions
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
private_0x0000000000030000 0x00030000 0x00031fff Private Memory Readable, Writable True False False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000050000 0x00050000 0x00053fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000060000 0x00060000 0x00062fff Pagefile Backed Memory Readable True False False
private_0x00000000000d0000 0x000d0000 0x0010ffff Private Memory Readable, Writable True False False
private_0x0000000000200000 0x00200000 0x0023ffff Private Memory Readable, Writable True False False
wusa.exe 0x00e10000 0x00e5ffff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77990000 0x77b38fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77b70000 0x77ceffff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007efb0000 0x7efb0000 0x7efd2fff Pagefile Backed Memory Readable True False False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable True False False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable True False False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable True False False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True False False
private_0x000000007fff0000 0x7fff0000 0x7fffffeffff Private Memory Readable True False False
Process #10: wusa.exe
+
Information Value
ID / OS PID #10 / 0xa98
OS Parent PID 0x9f8 (c:\windows\syswow64\cmd.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\syswow64\wusa.exe
Command Line "C:\Windows\SysWOW64\wusa.exe" "C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\cabfile.cab" /extract:"C:\Windows\SysWOW64\drivers"
Monitor Start Time: 00:01:03, Reason: Child Process
Unmonitor End Time: 00:01:04, Reason: Terminated
Monitor Duration 00:00:01
OS Thread IDs
# 32
0x A9C
# 33
0x AA0
# 34
0x AA4
Remarks No high level activity detected in monitored regions
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x00026fff Pagefile Backed Memory Readable True False False
private_0x0000000000030000 0x00030000 0x00031fff Private Memory Readable, Writable True False False
pagefile_0x0000000000030000 0x00030000 0x00031fff Pagefile Backed Memory Readable, Writable True False False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000050000 0x00050000 0x00053fff Pagefile Backed Memory Readable True False False
private_0x0000000000060000 0x00060000 0x0009ffff Private Memory Readable, Writable True False False
pagefile_0x00000000000a0000 0x000a0000 0x000a2fff Pagefile Backed Memory Readable True False False
wusa.exe.mui 0x000b0000 0x000b2fff Memory Mapped File Readable, Writable False False False
private_0x00000000000c0000 0x000c0000 0x000c0fff Private Memory Readable, Writable True False False
private_0x00000000000d0000 0x000d0000 0x000d0fff Private Memory Readable, Writable True False False
private_0x00000000000e0000 0x000e0000 0x0015ffff Private Memory Readable, Writable True False False
locale.nls 0x00160000 0x001c6fff Memory Mapped File Readable False False False
pagefile_0x00000000001d0000 0x001d0000 0x001d0fff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x00000000001e0000 0x001e0000 0x001e1fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000001f0000 0x001f0000 0x001f7fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000200000 0x00200000 0x0020ffff Private Memory Readable, Writable True False False
private_0x0000000000220000 0x00220000 0x0022ffff Private Memory Readable, Writable True False False
private_0x0000000000260000 0x00260000 0x0029ffff Private Memory Readable, Writable True False False
pagefile_0x00000000002a0000 0x002a0000 0x0037efff Pagefile Backed Memory Readable True False False
wusa.exe 0x00390000 0x003dffff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000000410000 0x00410000 0x0050ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000510000 0x00510000 0x00697fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000006a0000 0x006a0000 0x00820fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000830000 0x00830000 0x01c2ffff Pagefile Backed Memory Readable True False False
private_0x0000000001c30000 0x01c30000 0x01c6ffff Private Memory Readable, Writable True False False
private_0x0000000001ca0000 0x01ca0000 0x01cdffff Private Memory Readable, Writable True False False
private_0x0000000001d30000 0x01d30000 0x01d6ffff Private Memory Readable, Writable True False False
private_0x0000000001d70000 0x01d70000 0x01daffff Private Memory Readable, Writable True False False
private_0x0000000001dd0000 0x01dd0000 0x01e0ffff Private Memory Readable, Writable True False False
SortDefault.nls 0x01e10000 0x020defff Memory Mapped File Readable False False False
StaticCache.dat 0x020e0000 0x02a0ffff Memory Mapped File Readable False False False
private_0x0000000002a10000 0x02a10000 0x02a8ffff Private Memory Readable, Writable True False False
private_0x0000000002b30000 0x02b30000 0x02b6ffff Private Memory Readable, Writable True False False
private_0x0000000002b90000 0x02b90000 0x02bcffff Private Memory Readable, Writable True False False
private_0x0000000002bd0000 0x02bd0000 0x02ccffff Private Memory Readable, Writable True False False
dbghelp.dll 0x66e50000 0x66f3afff Memory Mapped File Readable, Writable, Executable False False False
dpx.dll 0x671b0000 0x671f1fff Memory Mapped File Readable, Writable, Executable False False False
wdscore.dll 0x67210000 0x67241fff Memory Mapped File Readable, Writable, Executable False False False
rsaenh.dll 0x693b0000 0x693eafff Memory Mapped File Readable, Writable, Executable False False False
cryptsp.dll 0x693f0000 0x69405fff Memory Mapped File Readable, Writable, Executable False False False
wtsapi32.dll 0x6f8d0000 0x6f8dcfff Memory Mapped File Readable, Writable, Executable False False False
uxtheme.dll 0x6f8e0000 0x6f95ffff Memory Mapped File Readable, Writable, Executable False False False
comctl32.dll 0x6f960000 0x6fafdfff Memory Mapped File Readable, Writable, Executable False False False
dwmapi.dll 0x72dd0000 0x72de2fff Memory Mapped File Readable, Writable, Executable False False False
wow64win.dll 0x75090000 0x750ebfff Memory Mapped File Readable, Writable, Executable False False False
wow64.dll 0x750f0000 0x7512efff Memory Mapped File Readable, Writable, Executable False False False
cabinet.dll 0x75230000 0x75244fff Memory Mapped File Readable, Writable, Executable False False False
wow64cpu.dll 0x75680000 0x75687fff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x756c0000 0x756cbfff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x756d0000 0x7572ffff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x75730000 0x7581ffff Memory Mapped File Readable, Writable, Executable False False False
ole32.dll 0x75880000 0x759dbfff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x759e0000 0x75a25fff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x75a30000 0x75accfff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x75b00000 0x75b09fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75b10000 0x75bdbfff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x75e10000 0x75f0ffff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76040000 0x760ebfff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x76220000 0x7627ffff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76280000 0x7630ffff Memory Mapped File Readable, Writable, Executable False False False
shlwapi.dll 0x76410000 0x76466fff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76470000 0x7650ffff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x76530000 0x7663ffff Memory Mapped File Readable, Writable, Executable False False False
oleaut32.dll 0x768e0000 0x7696efff Memory Mapped File Readable, Writable, Executable False False False
shell32.dll 0x76970000 0x775b9fff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x77610000 0x77628fff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000077770000 0x77770000 0x77869fff Private Memory Readable, Writable, Executable True False False
private_0x0000000077870000 0x77870000 0x7798efff Private Memory Readable, Writable, Executable True False False
ntdll.dll 0x77990000 0x77b38fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77b70000 0x77ceffff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007efb0000 0x7efb0000 0x7efd2fff Pagefile Backed Memory Readable True False False
private_0x000000007efd5000 0x7efd5000 0x7efd7fff Private Memory Readable, Writable True False False
private_0x000000007efd8000 0x7efd8000 0x7efdafff Private Memory Readable, Writable True False False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable True False False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable True False False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable True False False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
pagefile_0x000000007efe0000 0x7efe0000 0x7f0dffff Pagefile Backed Memory Readable True False False
private_0x000000007f0e0000 0x7f0e0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True False False
private_0x000000007fff0000 0x7fff0000 0x7fffffeffff Private Memory Readable True False False
Process #11: cmd.exe
(Host: 35, Network: 0)
+
Information Value
ID / OS PID #11 / 0xaac
OS Parent PID 0x9d0 (c:\windows\syswow64\explorer.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\syswow64\cmd.exe
Command Line cmd.exe /c makecab "C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\dpx.dll" "C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\cabfile.cab"
Monitor Start Time: 00:01:04, Reason: Child Process
Unmonitor End Time: 00:01:05, Reason: Terminated
Monitor Duration 00:00:01
OS Thread IDs
# 35
0x AB0
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000030000 0x00030000 0x00031fff Private Memory Readable, Writable True False False
pagefile_0x0000000000030000 0x00030000 0x00036fff Pagefile Backed Memory Readable True False False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000050000 0x00050000 0x00053fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000060000 0x00060000 0x00060fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000070000 0x00070000 0x00071fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000080000 0x00080000 0x00080fff Private Memory Readable, Writable True False False
private_0x0000000000090000 0x00090000 0x00090fff Private Memory Readable, Writable True False False
private_0x00000000000a0000 0x000a0000 0x000dffff Private Memory Readable, Writable True False False
private_0x0000000000100000 0x00100000 0x001fffff Private Memory Readable, Writable True False False
private_0x0000000000230000 0x00230000 0x002affff Private Memory Readable, Writable True False False
private_0x00000000002e0000 0x002e0000 0x003dffff Private Memory Readable, Writable True False False
locale.nls 0x003e0000 0x00446fff Memory Mapped File Readable False False False
pagefile_0x0000000000450000 0x00450000 0x005d7fff Pagefile Backed Memory Readable True False False
private_0x00000000005e0000 0x005e0000 0x005effff Private Memory Readable, Writable True False False
pagefile_0x00000000005f0000 0x005f0000 0x00770fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000780000 0x00780000 0x01b7ffff Pagefile Backed Memory Readable True False False
pagefile_0x0000000001b80000 0x01b80000 0x01ec2fff Pagefile Backed Memory Readable True False False
cmd.exe 0x4aae0000 0x4ab2bfff Memory Mapped File Readable, Writable, Executable True False False
winbrand.dll 0x675a0000 0x675a6fff Memory Mapped File Readable, Writable, Executable False False False
wow64win.dll 0x75090000 0x750ebfff Memory Mapped File Readable, Writable, Executable False False False
wow64.dll 0x750f0000 0x7512efff Memory Mapped File Readable, Writable, Executable False False False
wow64cpu.dll 0x75680000 0x75687fff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x756c0000 0x756cbfff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x756d0000 0x7572ffff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x75730000 0x7581ffff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x759e0000 0x75a25fff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x75a30000 0x75accfff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x75b00000 0x75b09fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75b10000 0x75bdbfff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x75e10000 0x75f0ffff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76040000 0x760ebfff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x76220000 0x7627ffff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76280000 0x7630ffff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76470000 0x7650ffff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x76530000 0x7663ffff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x77610000 0x77628fff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000077770000 0x77770000 0x77869fff Private Memory Readable, Writable, Executable True False False
private_0x0000000077870000 0x77870000 0x7798efff Private Memory Readable, Writable, Executable True False False
ntdll.dll 0x77990000 0x77b38fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77b70000 0x77ceffff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007efb0000 0x7efb0000 0x7efd2fff Pagefile Backed Memory Readable True False False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable True False False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable True False False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable True False False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
pagefile_0x000000007efe0000 0x7efe0000 0x7f0dffff Pagefile Backed Memory Readable True False False
private_0x000000007f0e0000 0x7f0e0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True False False
private_0x000000007fff0000 0x7fff0000 0x7fffffeffff Private Memory Readable True False False
Host Behavior
File (8)
+
Operation Filename Additional Information Success Count Logfile
OPEN STD_OUTPUT_HANDLE True 5
Fn
OPEN STD_INPUT_HANDLE True 3
Fn
Process (2)
+
Operation Process Name Additional Information Success Count Logfile
CREATE C:\Windows\system32\makecab.exe os_tid = 0xac8, os_pid = 0xac4, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, current_directory = C:\Windows\system32, show_window = SW_SHOWNORMAL True 1
Fn
SET_CURDIR c:\windows\syswow64\cmd.exe os_pid = 0xaac, new_path_name = c:\windows\system32 True 1
Fn
Module (8)
+
Operation Module Additional Information Success Count Logfile
GET_HANDLE c:\windows\syswow64\cmd.exe base_address = 0x4aae0000 True 1
Fn
GET_HANDLE c:\windows\syswow64\kernel32.dll base_address = 0x76530000 True 2
Fn
GET_FILENAME C:\Windows\SysWOW64\cmd.exe True 1
Fn
GET_PROC_ADDRESS c:\windows\syswow64\kernel32.dll function = SetThreadUILanguage, address = 0x7655a84f True 1
Fn
GET_PROC_ADDRESS c:\windows\syswow64\kernel32.dll function = CopyFileExW, address = 0x76563b92 True 1
Fn
GET_PROC_ADDRESS c:\windows\syswow64\kernel32.dll function = IsDebuggerPresent, address = 0x76544a5d True 1
Fn
GET_PROC_ADDRESS c:\windows\syswow64\kernel32.dll function = SetConsoleInputExeNameW, address = 0x7655a79d True 1
Fn
Registry (17)
+
Operation Key Additional Information Success Count Logfile
OPEN_KEY HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System False 1
Fn
OPEN_KEY HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor True 1
Fn
OPEN_KEY HKEY_CURRENT_USER\Software\Microsoft\Command Processor True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data_ident_out = 0 False 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = EnableExtensions, data_ident_out = 1 True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DelayedExpansion, data_ident_out = 1 False 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DefaultColor, data_ident_out = 0 True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = CompletionChar, data_ident_out = 64 True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = PathCompletionChar, data_ident_out = 64 True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = AutoRun, data_ident_out = 64 False 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data_ident_out = 64 False 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = EnableExtensions, data_ident_out = 1 True 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DelayedExpansion, data_ident_out = 1 False 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DefaultColor, data_ident_out = 0 True 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = CompletionChar, data_ident_out = 9 True 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = PathCompletionChar, data_ident_out = 9 True 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = AutoRun, data_ident_out = 9 False 1
Fn
Process #12: makecab.exe
+
Information Value
ID / OS PID #12 / 0xac4
OS Parent PID 0xaac (c:\windows\syswow64\cmd.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\syswow64\makecab.exe
Command Line makecab "C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\dpx.dll" "C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\cabfile.cab"
Monitor Start Time: 00:01:04, Reason: Child Process
Unmonitor End Time: 00:01:05, Reason: Terminated
Monitor Duration 00:00:01
OS Thread IDs
# 36
0x AC8
Remarks No high level activity detected in monitored regions
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000030000 0x00030000 0x00031fff Private Memory Readable, Writable True False False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000050000 0x00050000 0x00053fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000060000 0x00060000 0x00061fff Pagefile Backed Memory Readable True False False
private_0x00000000000b0000 0x000b0000 0x000effff Private Memory Readable, Writable True False False
locale.nls 0x000f0000 0x00156fff Memory Mapped File Readable False False False
private_0x00000000001e0000 0x001e0000 0x0021ffff Private Memory Readable, Writable True False False
private_0x00000000002c0000 0x002c0000 0x002cffff Private Memory Readable, Writable True False False
private_0x0000000000320000 0x00320000 0x0039ffff Private Memory Readable, Writable True False False
private_0x00000000004a0000 0x004a0000 0x0059ffff Private Memory Readable, Writable True False False
pagefile_0x00000000005a0000 0x005a0000 0x00727fff Pagefile Backed Memory Readable True False False
makecab.exe 0x00fe0000 0x00ffafff Memory Mapped File Readable, Writable, Executable False False False
version.dll 0x72df0000 0x72df8fff Memory Mapped File Readable, Writable, Executable False False False
wow64win.dll 0x75090000 0x750ebfff Memory Mapped File Readable, Writable, Executable False False False
wow64.dll 0x750f0000 0x7512efff Memory Mapped File Readable, Writable, Executable False False False
wow64cpu.dll 0x75680000 0x75687fff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x756c0000 0x756cbfff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x756d0000 0x7572ffff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x75730000 0x7581ffff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x759e0000 0x75a25fff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x75a30000 0x75accfff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x75b00000 0x75b09fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75b10000 0x75bdbfff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x75e10000 0x75f0ffff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76040000 0x760ebfff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x76220000 0x7627ffff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76280000 0x7630ffff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76470000 0x7650ffff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x76530000 0x7663ffff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x77610000 0x77628fff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000077770000 0x77770000 0x77869fff Private Memory Readable, Writable, Executable True False False
private_0x0000000077870000 0x77870000 0x7798efff Private Memory Readable, Writable, Executable True False False
ntdll.dll 0x77990000 0x77b38fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77b70000 0x77ceffff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007efb0000 0x7efb0000 0x7efd2fff Pagefile Backed Memory Readable True False False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable True False False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable True False False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable True False False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
pagefile_0x000000007efe0000 0x7efe0000 0x7f0dffff Pagefile Backed Memory Readable True False False
private_0x000000007f0e0000 0x7f0e0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True False False
private_0x000000007fff0000 0x7fff0000 0x7fffffeffff Private Memory Readable True False False
Process #13: cmd.exe
(Host: 38, Network: 0)
+
Information Value
ID / OS PID #13 / 0xacc
OS Parent PID 0x9d0 (c:\windows\syswow64\explorer.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\syswow64\cmd.exe
Command Line cmd.exe /c c:\windows\system32\wusa "C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\cabfile.cab" /extract:"C:\Windows\SysWOW64\drivers"
Monitor Start Time: 00:01:05, Reason: Child Process
Unmonitor End Time: 00:01:06, Reason: Terminated
Monitor Duration 00:00:01
OS Thread IDs
# 37
0x AD0
# 39
0x AEC
# 40
0x AF0
# 42
0x AFC
# 43
0x B00
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000030000 0x00030000 0x00031fff Private Memory Readable, Writable True False False
pagefile_0x0000000000030000 0x00030000 0x00036fff Pagefile Backed Memory Readable True False False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000050000 0x00050000 0x00053fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000060000 0x00060000 0x00060fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000070000 0x00070000 0x00071fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000080000 0x00080000 0x000fffff Private Memory Readable, Writable True False False
private_0x0000000000100000 0x00100000 0x00100fff Private Memory Readable, Writable True False False
private_0x0000000000110000 0x00110000 0x00110fff Private Memory Readable, Writable True False False
pagefile_0x0000000000120000 0x00120000 0x00121fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000130000 0x00130000 0x00130fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000140000 0x00140000 0x0014ffff Private Memory Readable, Writable True False False
private_0x0000000000150000 0x00150000 0x0018ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000190000 0x00190000 0x00191fff Pagefile Backed Memory Readable True False False
private_0x00000000001a0000 0x001a0000 0x0029ffff Private Memory Readable, Writable True False False
locale.nls 0x002a0000 0x00306fff Memory Mapped File Readable False False False
pagefile_0x0000000000310000 0x00310000 0x00310fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000320000 0x00320000 0x00320fff Pagefile Backed Memory Readable True False False
cversions.2.db 0x00330000 0x00333fff Memory Mapped File Readable True False False
{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000004.db 0x00340000 0x00360fff Memory Mapped File Readable True False False
private_0x0000000000370000 0x00370000 0x0046ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000470000 0x00470000 0x005f7fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000600000 0x00600000 0x00780fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000790000 0x00790000 0x01b8ffff Pagefile Backed Memory Readable True False False
pagefile_0x0000000001b90000 0x01b90000 0x01ed2fff Pagefile Backed Memory Readable True False False
SortDefault.nls 0x01ee0000 0x021aefff Memory Mapped File Readable False False False
pagefile_0x00000000021b0000 0x021b0000 0x0228efff Pagefile Backed Memory Readable True False False
pagefile_0x0000000002290000 0x02290000 0x02290fff Pagefile Backed Memory Readable, Writable True False False
private_0x00000000022a0000 0x022a0000 0x022dffff Private Memory Readable, Writable True False False
{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x000000000000000e.db 0x022e0000 0x0230ffff Memory Mapped File Readable True False False
cversions.2.db 0x02310000 0x02313fff Memory Mapped File Readable True False False
{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db 0x02320000 0x02385fff Memory Mapped File Readable True False False
pagefile_0x0000000002390000 0x02390000 0x02782fff Pagefile Backed Memory Readable True False False
private_0x0000000002790000 0x02790000 0x0288ffff Private Memory Readable, Writable True False False
pagefile_0x0000000002890000 0x02890000 0x02890fff Pagefile Backed Memory Readable, Writable True False False
private_0x00000000028c0000 0x028c0000 0x028fffff Private Memory Readable, Writable True False False
private_0x0000000002950000 0x02950000 0x0298ffff Private Memory Readable, Writable True False False
private_0x0000000002990000 0x02990000 0x029cffff Private Memory Readable, Writable True False False
private_0x0000000002a70000 0x02a70000 0x02b6ffff Private Memory Readable, Writable True False False
private_0x0000000002bd0000 0x02bd0000 0x02c0ffff Private Memory Readable, Writable True False False
private_0x0000000002ca0000 0x02ca0000 0x02d9ffff Private Memory Readable, Writable True False False
private_0x0000000002dd0000 0x02dd0000 0x02ecffff Private Memory Readable, Writable True False False
private_0x00000000030a0000 0x030a0000 0x0319ffff Private Memory Readable, Writable True False False
cmd.exe 0x4a9f0000 0x4aa3bfff Memory Mapped File Readable, Writable, Executable True False False
winbrand.dll 0x675a0000 0x675a6fff Memory Mapped File Readable, Writable, Executable False False False
mpr.dll 0x675f0000 0x67601fff Memory Mapped File Readable, Writable, Executable False False False
ntmarta.dll 0x691d0000 0x691f0fff Memory Mapped File Readable, Writable, Executable False False False
propsys.dll 0x69200000 0x692f4fff Memory Mapped File Readable, Writable, Executable False False False
uxtheme.dll 0x6f8e0000 0x6f95ffff Memory Mapped File Readable, Writable, Executable False False False
comctl32.dll 0x6f960000 0x6fafdfff Memory Mapped File Readable, Writable, Executable False False False
profapi.dll 0x74d60000 0x74d6afff Memory Mapped File Readable, Writable, Executable False False False
wow64win.dll 0x75090000 0x750ebfff Memory Mapped File Readable, Writable, Executable False False False
wow64.dll 0x750f0000 0x7512efff Memory Mapped File Readable, Writable, Executable False False False
wow64cpu.dll 0x75680000 0x75687fff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x756c0000 0x756cbfff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x756d0000 0x7572ffff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x75730000 0x7581ffff Memory Mapped File Readable, Writable, Executable False False False
ole32.dll 0x75880000 0x759dbfff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x759e0000 0x75a25fff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x75a30000 0x75accfff Memory Mapped File Readable, Writable, Executable False False False
cfgmgr32.dll 0x75ad0000 0x75af6fff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x75b00000 0x75b09fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75b10000 0x75bdbfff Memory Mapped File Readable, Writable, Executable False False False
iertutil.dll 0x75be0000 0x75ddafff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x75e10000 0x75f0ffff Memory Mapped File Readable, Writable, Executable False False False
crypt32.dll 0x75f10000 0x7602cfff Memory Mapped File Readable, Writable, Executable False False False
msasn1.dll 0x76030000 0x7603bfff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76040000 0x760ebfff Memory Mapped File Readable, Writable, Executable False False False
clbcatq.dll 0x760f0000 0x76172fff Memory Mapped File Readable, Writable, Executable False False False
devobj.dll 0x76200000 0x76211fff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x76220000 0x7627ffff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76280000 0x7630ffff Memory Mapped File Readable, Writable, Executable False False False
shlwapi.dll 0x76410000 0x76466fff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76470000 0x7650ffff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x76530000 0x7663ffff Memory Mapped File Readable, Writable, Executable False False False
setupapi.dll 0x76640000 0x767dcfff Memory Mapped File Readable, Writable, Executable False False False
wininet.dll 0x767e0000 0x768d4fff Memory Mapped File Readable, Writable, Executable False False False
oleaut32.dll 0x768e0000 0x7696efff Memory Mapped File Readable, Writable, Executable False False False
shell32.dll 0x76970000 0x775b9fff Memory Mapped File Readable, Writable, Executable False False False
Wldap32.dll 0x775c0000 0x77604fff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x77610000 0x77628fff Memory Mapped File Readable, Writable, Executable False False False
urlmon.dll 0x77630000 0x77765fff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000077770000 0x77770000 0x77869fff Private Memory Readable, Writable, Executable True False False
private_0x0000000077870000 0x77870000 0x7798efff Private Memory Readable, Writable, Executable True False False
ntdll.dll 0x77990000 0x77b38fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77b70000 0x77ceffff Memory Mapped File Readable, Writable, Executable False False False
private_0x000000007efaa000 0x7efaa000 0x7efacfff Private Memory Readable, Writable True False False
private_0x000000007efad000 0x7efad000 0x7efaffff Private Memory Readable, Writable True False False
pagefile_0x000000007efb0000 0x7efb0000 0x7efd2fff Pagefile Backed Memory Readable True False False
private_0x000000007efd5000 0x7efd5000 0x7efd7fff Private Memory Readable, Writable True False False
private_0x000000007efd8000 0x7efd8000 0x7efdafff Private Memory Readable, Writable True False False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable True False False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable True False False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable True False False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
pagefile_0x000000007efe0000 0x7efe0000 0x7f0dffff Pagefile Backed Memory Readable True False False
private_0x000000007f0e0000 0x7f0e0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True False False
private_0x000000007fff0000 0x7fff0000 0x7fffffeffff Private Memory Readable True False False
Host Behavior
File (8)
+
Operation Filename Additional Information Success Count Logfile
OPEN STD_OUTPUT_HANDLE True 5
Fn
OPEN STD_INPUT_HANDLE True 3
Fn
Process (3)
+
Operation Process Name Additional Information Success Count Logfile
CREATE c:\windows\system32\wusa.exe os_tid = 0x0, os_pid = 0x0, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, current_directory = C:\Windows\system32, show_window = SW_SHOWNORMAL False 1
Fn
CREATE c:\windows\system32\wusa.exe current_directory = C:\Windows\system32, show_window = SW_SHOWNORMAL True 1
Fn
SET_CURDIR c:\windows\syswow64\cmd.exe os_pid = 0xacc, new_path_name = c:\windows\system32 True 1
Fn
Module (10)
+
Operation Module Additional Information Success Count Logfile
LOAD SHELL32.dll base_address = 0x76970000 True 1
Fn
GET_HANDLE c:\windows\syswow64\cmd.exe base_address = 0x4a9f0000 True 1
Fn
GET_HANDLE c:\windows\syswow64\kernel32.dll base_address = 0x76530000 True 2
Fn
GET_FILENAME C:\Windows\SysWOW64\cmd.exe True 1
Fn
GET_PROC_ADDRESS c:\windows\syswow64\kernel32.dll function = SetThreadUILanguage, address = 0x7655a84f True 1
Fn
GET_PROC_ADDRESS c:\windows\syswow64\kernel32.dll function = CopyFileExW, address = 0x76563b92 True 1
Fn
GET_PROC_ADDRESS c:\windows\syswow64\kernel32.dll function = IsDebuggerPresent, address = 0x76544a5d True 1
Fn
GET_PROC_ADDRESS c:\windows\syswow64\kernel32.dll function = SetConsoleInputExeNameW, address = 0x7655a79d True 1
Fn
GET_PROC_ADDRESS c:\windows\syswow64\shell32.dll function = ShellExecuteExW, address = 0x76991e46 True 1
Fn
Registry (17)
+
Operation Key Additional Information Success Count Logfile
OPEN_KEY HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System False 1
Fn
OPEN_KEY HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor True 1
Fn
OPEN_KEY HKEY_CURRENT_USER\Software\Microsoft\Command Processor True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data_ident_out = 0 False 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = EnableExtensions, data_ident_out = 1 True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DelayedExpansion, data_ident_out = 1 False 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DefaultColor, data_ident_out = 0 True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = CompletionChar, data_ident_out = 64 True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = PathCompletionChar, data_ident_out = 64 True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = AutoRun, data_ident_out = 64 False 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data_ident_out = 64 False 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = EnableExtensions, data_ident_out = 1 True 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DelayedExpansion, data_ident_out = 1 False 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DefaultColor, data_ident_out = 0 True 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = CompletionChar, data_ident_out = 9 True 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = PathCompletionChar, data_ident_out = 9 True 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = AutoRun, data_ident_out = 9 False 1
Fn
Process #14: wusa.exe
+
Information Value
ID / OS PID #14 / 0xae4
OS Parent PID 0xacc (c:\windows\syswow64\cmd.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\syswow64\wusa.exe
Command Line c:\windows\system32\wusa "C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\cabfile.cab" /extract:"C:\Windows\SysWOW64\drivers"
Monitor Start Time: 00:01:05, Reason: Child Process
Unmonitor End Time: 00:01:05, Reason: Terminated
Monitor Duration 00:00:00
OS Thread IDs
# 38
0x AE8
Remarks No high level activity detected in monitored regions
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
private_0x0000000000030000 0x00030000 0x00031fff Private Memory Readable, Writable True False False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000050000 0x00050000 0x00053fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000060000 0x00060000 0x00062fff Pagefile Backed Memory Readable True False False
private_0x0000000000100000 0x00100000 0x0013ffff Private Memory Readable, Writable True False False
private_0x0000000000170000 0x00170000 0x001affff Private Memory Readable, Writable True False False
wusa.exe 0x00a60000 0x00aaffff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77990000 0x77b38fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77b70000 0x77ceffff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007efb0000 0x7efb0000 0x7efd2fff Pagefile Backed Memory Readable True False False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable True False False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable True False False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable True False False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True False False
private_0x000000007fff0000 0x7fff0000 0x7fffffeffff Private Memory Readable True False False
Process #15: wusa.exe
+
Information Value
ID / OS PID #15 / 0xaf4
OS Parent PID 0xacc (c:\windows\syswow64\cmd.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\syswow64\wusa.exe
Command Line "C:\windows\system32\wusa.exe" "C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\cabfile.cab" /extract:"C:\Windows\SysWOW64\drivers"
Monitor Start Time: 00:01:05, Reason: Child Process
Unmonitor End Time: 00:01:05, Reason: Terminated
Monitor Duration 00:00:00
OS Thread IDs
# 41
0x AF8
Remarks No high level activity detected in monitored regions
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
private_0x0000000000030000 0x00030000 0x00031fff Private Memory Readable, Writable True False False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000050000 0x00050000 0x00053fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000060000 0x00060000 0x00062fff Pagefile Backed Memory Readable True False False
private_0x0000000000080000 0x00080000 0x000bffff Private Memory Readable, Writable True False False
private_0x00000000001f0000 0x001f0000 0x0022ffff Private Memory Readable, Writable True False False
wusa.exe 0x00720000 0x0076ffff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77990000 0x77b38fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77b70000 0x77ceffff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007efb0000 0x7efb0000 0x7efd2fff Pagefile Backed Memory Readable True False False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable True False False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable True False False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable True False False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True False False
private_0x000000007fff0000 0x7fff0000 0x7fffffeffff Private Memory Readable True False False
Process #16: wusa.exe
+
Information Value
ID / OS PID #16 / 0xb28
OS Parent PID 0xacc (c:\windows\syswow64\cmd.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\syswow64\wusa.exe
Command Line "C:\Windows\SysWOW64\wusa.exe" "C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\cabfile.cab" /extract:"C:\Windows\SysWOW64\drivers"
Monitor Start Time: 00:01:06, Reason: Child Process
Unmonitor End Time: 00:01:06, Reason: Terminated
Monitor Duration 00:00:00
OS Thread IDs
# 44
0x B2C
# 45
0x B30
# 46
0x B34
Remarks No high level activity detected in monitored regions
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x00026fff Pagefile Backed Memory Readable True False False
private_0x0000000000030000 0x00030000 0x00031fff Private Memory Readable, Writable True False False
pagefile_0x0000000000030000 0x00030000 0x00031fff Pagefile Backed Memory Readable, Writable True False False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000050000 0x00050000 0x00053fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000060000 0x00060000 0x00062fff Pagefile Backed Memory Readable True False False
locale.nls 0x00070000 0x000d6fff Memory Mapped File Readable False False False
wusa.exe.mui 0x000e0000 0x000e2fff Memory Mapped File Readable, Writable False False False
private_0x00000000000f0000 0x000f0000 0x0012ffff Private Memory Readable, Writable True False False
private_0x0000000000130000 0x00130000 0x00130fff Private Memory Readable, Writable True False False
private_0x0000000000140000 0x00140000 0x00140fff Private Memory Readable, Writable True False False
pagefile_0x0000000000150000 0x00150000 0x00150fff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000160000 0x00160000 0x00161fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000170000 0x00170000 0x00177fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000190000 0x00190000 0x001cffff Private Memory Readable, Writable True False False
private_0x00000000001f0000 0x001f0000 0x0026ffff Private Memory Readable, Writable True False False
private_0x0000000000290000 0x00290000 0x0038ffff Private Memory Readable, Writable True False False
private_0x0000000000390000 0x00390000 0x003cffff Private Memory Readable, Writable True False False
private_0x00000000003d0000 0x003d0000 0x0044ffff Private Memory Readable, Writable True False False
private_0x0000000000480000 0x00480000 0x0048ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000490000 0x00490000 0x00617fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000620000 0x00620000 0x007a0fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000007b0000 0x007b0000 0x0088efff Pagefile Backed Memory Readable True False False
private_0x00000000008b0000 0x008b0000 0x008effff Private Memory Readable, Writable True False False
private_0x0000000000930000 0x00930000 0x0096ffff Private Memory Readable, Writable True False False
private_0x0000000000980000 0x00980000 0x009bffff Private Memory Readable, Writable True False False
wusa.exe 0x009d0000 0x00a1ffff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000a20000 0x00a20000 0x01e1ffff Pagefile Backed Memory Readable True False False
SortDefault.nls 0x01e20000 0x020eefff Memory Mapped File Readable False False False
private_0x00000000020f0000 0x020f0000 0x021effff Private Memory Readable, Writable True False False
private_0x00000000021f0000 0x021f0000 0x021fffff Private Memory Readable, Writable True False False
private_0x00000000022a0000 0x022a0000 0x022dffff Private Memory Readable, Writable True False False
StaticCache.dat 0x022e0000 0x02c0ffff Memory Mapped File Readable False False False
private_0x0000000002c20000 0x02c20000 0x02c5ffff Private Memory Readable, Writable True False False
private_0x0000000002d90000 0x02d90000 0x02dcffff Private Memory Readable, Writable True False False
dbghelp.dll 0x66f00000 0x66feafff Memory Mapped File Readable, Writable, Executable False False False
wdscore.dll 0x66ff0000 0x67021fff Memory Mapped File Readable, Writable, Executable False False False
dpx.dll 0x671b0000 0x671f1fff Memory Mapped File Readable, Writable, Executable False False False
rsaenh.dll 0x693b0000 0x693eafff Memory Mapped File Readable, Writable, Executable False False False
cryptsp.dll 0x693f0000 0x69405fff Memory Mapped File Readable, Writable, Executable False False False
wtsapi32.dll 0x6f8d0000 0x6f8dcfff Memory Mapped File Readable, Writable, Executable False False False
uxtheme.dll 0x6f8e0000 0x6f95ffff Memory Mapped File Readable, Writable, Executable False False False
comctl32.dll 0x6f960000 0x6fafdfff Memory Mapped File Readable, Writable, Executable False False False
dwmapi.dll 0x72dd0000 0x72de2fff Memory Mapped File Readable, Writable, Executable False False False
wow64win.dll 0x75090000 0x750ebfff Memory Mapped File Readable, Writable, Executable False False False
wow64.dll 0x750f0000 0x7512efff Memory Mapped File Readable, Writable, Executable False False False
cabinet.dll 0x75230000 0x75244fff Memory Mapped File Readable, Writable, Executable False False False
wow64cpu.dll 0x75680000 0x75687fff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x756c0000 0x756cbfff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x756d0000 0x7572ffff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x75730000 0x7581ffff Memory Mapped File Readable, Writable, Executable False False False
ole32.dll 0x75880000 0x759dbfff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x759e0000 0x75a25fff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x75a30000 0x75accfff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x75b00000 0x75b09fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75b10000 0x75bdbfff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x75e10000 0x75f0ffff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76040000 0x760ebfff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x76220000 0x7627ffff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76280000 0x7630ffff Memory Mapped File Readable, Writable, Executable False False False
shlwapi.dll 0x76410000 0x76466fff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76470000 0x7650ffff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x76530000 0x7663ffff Memory Mapped File Readable, Writable, Executable False False False
oleaut32.dll 0x768e0000 0x7696efff Memory Mapped File Readable, Writable, Executable False False False
shell32.dll 0x76970000 0x775b9fff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x77610000 0x77628fff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000077770000 0x77770000 0x77869fff Private Memory Readable, Writable, Executable True False False
private_0x0000000077870000 0x77870000 0x7798efff Private Memory Readable, Writable, Executable True False False
ntdll.dll 0x77990000 0x77b38fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77b70000 0x77ceffff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007efb0000 0x7efb0000 0x7efd2fff Pagefile Backed Memory Readable True False False
private_0x000000007efd5000 0x7efd5000 0x7efd7fff Private Memory Readable, Writable True False False
private_0x000000007efd8000 0x7efd8000 0x7efdafff Private Memory Readable, Writable True False False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable True False False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable True False False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable True False False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
pagefile_0x000000007efe0000 0x7efe0000 0x7f0dffff Pagefile Backed Memory Readable True False False
private_0x000000007f0e0000 0x7f0e0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True False False
private_0x000000007fff0000 0x7fff0000 0x7fffffeffff Private Memory Readable True False False
Process #17: wusa.exe
+
Information Value
ID / OS PID #17 / 0xb70
OS Parent PID 0x9d0 (c:\windows\syswow64\explorer.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\syswow64\drivers\wusa.exe
Command Line "C:\Windows\SysWOW64\drivers\wusa.exe"
Monitor Start Time: 00:01:06, Reason: Child Process
Unmonitor End Time: 00:01:14, Reason: Terminated
Monitor Duration 00:00:08
OS Thread IDs
# 52
0x B74
# 55
0x B8C
Remarks No high level activity detected in monitored regions
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000030000 0x00030000 0x00031fff Private Memory Readable, Writable True False False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000050000 0x00050000 0x00053fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000060000 0x00060000 0x00062fff Pagefile Backed Memory Readable True False False
private_0x00000000000a0000 0x000a0000 0x000dffff Private Memory Readable, Writable True False False
wusa.exe 0x00140000 0x0018ffff Memory Mapped File Readable, Writable, Executable False False False
locale.nls 0x00190000 0x001f6fff Memory Mapped File Readable False False False
private_0x0000000000310000 0x00310000 0x0034ffff Private Memory Readable, Writable True False False
private_0x0000000000460000 0x00460000 0x004dffff Private Memory Readable, Writable True False False
private_0x00000000005f0000 0x005f0000 0x006effff Private Memory Readable, Writable True False False
private_0x0000000000830000 0x00830000 0x0083ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000840000 0x00840000 0x009c7fff Pagefile Backed Memory Readable True False False
dpx.dll 0x67200000 0x67241fff Memory Mapped File Readable, Writable, Executable False False False
wtsapi32.dll 0x6f8d0000 0x6f8dcfff Memory Mapped File Readable, Writable, Executable False False False
comctl32.dll 0x6f960000 0x6fafdfff Memory Mapped File Readable, Writable, Executable False False False
wow64win.dll 0x75090000 0x750ebfff Memory Mapped File Readable, Writable, Executable False False False
wow64.dll 0x750f0000 0x7512efff Memory Mapped File Readable, Writable, Executable False False False
wow64cpu.dll 0x75680000 0x75687fff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x756c0000 0x756cbfff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x756d0000 0x7572ffff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x75730000 0x7581ffff Memory Mapped File Readable, Writable, Executable False False False
ole32.dll 0x75880000 0x759dbfff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x759e0000 0x75a25fff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x75a30000 0x75accfff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x75b00000 0x75b09fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75b10000 0x75bdbfff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x75e10000 0x75f0ffff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76040000 0x760ebfff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x76220000 0x7627ffff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76280000 0x7630ffff Memory Mapped File Readable, Writable, Executable False False False
shlwapi.dll 0x76410000 0x76466fff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76470000 0x7650ffff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x76530000 0x7663ffff Memory Mapped File Readable, Writable, Executable False False False
oleaut32.dll 0x768e0000 0x7696efff Memory Mapped File Readable, Writable, Executable False False False
shell32.dll 0x76970000 0x775b9fff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x77610000 0x77628fff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000077770000 0x77770000 0x77869fff Private Memory Readable, Writable, Executable True False False
private_0x0000000077870000 0x77870000 0x7798efff Private Memory Readable, Writable, Executable True False False
ntdll.dll 0x77990000 0x77b38fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77b70000 0x77ceffff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007efb0000 0x7efb0000 0x7efd2fff Pagefile Backed Memory Readable True False False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable True False False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable True False False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable True False False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
pagefile_0x000000007efe0000 0x7efe0000 0x7f0dffff Pagefile Backed Memory Readable True False False
private_0x000000007f0e0000 0x7f0e0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True False False
private_0x000000007fff0000 0x7fff0000 0x7fffffeffff Private Memory Readable True False False
Process #18: convin~1.exe
(Host: 4846, Network: 0)
+
Information Value
ID / OS PID #18 / 0xb7c
OS Parent PID 0xb70 (c:\windows\syswow64\drivers\wusa.exe)
Initial Working Directory C:\Windows\system32
File Name c:\users\hjrd1k~1\appdata\roaming\convin~1.exe
Command Line C:\Users\HJRD1K~1\AppData\Roaming\CONVIN~1.EXE
Monitor Start Time: 00:01:07, Reason: Child Process
Unmonitor End Time: 00:01:14, Reason: Terminated
Monitor Duration 00:00:07
OS Thread IDs
# 53
0x B80
# 54
0x B88
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000020000 0x00020000 0x00020fff Private Memory Readable, Writable True False False
private_0x0000000000030000 0x00030000 0x00031fff Private Memory Readable, Writable True False False
private_0x0000000000030000 0x00030000 0x00030fff Private Memory Readable, Writable True False False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000000050000 0x00050000 0x0008ffff Private Memory Readable, Writable True False False
private_0x0000000000090000 0x00090000 0x0018ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000190000 0x00190000 0x00193fff Pagefile Backed Memory Readable True False False
locale.nls 0x001a0000 0x00206fff Memory Mapped File Readable False False False
private_0x0000000000210000 0x00210000 0x00214fff Private Memory Readable, Writable, Executable True False False
private_0x0000000000240000 0x00240000 0x0024ffff Private Memory Readable, Writable True False False
private_0x0000000000250000 0x00250000 0x0028ffff Private Memory Readable, Writable True False False
private_0x00000000002d0000 0x002d0000 0x0034ffff Private Memory Readable, Writable True False False
convincingly.exe 0x00400000 0x00415fff Memory Mapped File Readable, Writable, Executable True True False
private_0x00000000004f0000 0x004f0000 0x004fffff Private Memory Readable, Writable True False False
private_0x0000000000540000 0x00540000 0x0054ffff Private Memory Readable, Writable True False False
private_0x0000000000550000 0x00550000 0x0064ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000650000 0x00650000 0x007d7fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000007e0000 0x007e0000 0x00960fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000970000 0x00970000 0x01d6ffff Pagefile Backed Memory Readable True False False
private_0x0000000001d70000 0x01d70000 0x01e6ffff Private Memory Readable, Writable True False False
private_0x0000000001ed0000 0x01ed0000 0x01edffff Private Memory Readable, Writable True False False
comctl32.dll 0x67280000 0x67303fff Memory Mapped File Readable, Writable, Executable False False False
winspool.drv 0x69300000 0x69350fff Memory Mapped File Readable, Writable, Executable False False False
wow64win.dll 0x75090000 0x750ebfff Memory Mapped File Readable, Writable, Executable False False False
wow64.dll 0x750f0000 0x7512efff Memory Mapped File Readable, Writable, Executable False False False
wow64cpu.dll 0x75680000 0x75687fff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x756c0000 0x756cbfff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x756d0000 0x7572ffff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x75730000 0x7581ffff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x759e0000 0x75a25fff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x75a30000 0x75accfff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x75b00000 0x75b09fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75b10000 0x75bdbfff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x75e10000 0x75f0ffff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76040000 0x760ebfff Memory Mapped File Readable, Writable, Executable False False False
comdlg32.dll 0x76180000 0x761fafff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x76220000 0x7627ffff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76280000 0x7630ffff Memory Mapped File Readable, Writable, Executable False False False
shlwapi.dll 0x76410000 0x76466fff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76470000 0x7650ffff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x76530000 0x7663ffff Memory Mapped File Readable, Writable, Executable False False False
shell32.dll 0x76970000 0x775b9fff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x77610000 0x77628fff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000077770000 0x77770000 0x77869fff Private Memory Readable, Writable, Executable True False False
private_0x0000000077870000 0x77870000 0x7798efff Private Memory Readable, Writable, Executable True False False
ntdll.dll 0x77990000 0x77b38fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77b70000 0x77ceffff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007efb0000 0x7efb0000 0x7efd2fff Pagefile Backed Memory Readable True False False
private_0x000000007efd8000 0x7efd8000 0x7efdafff Private Memory Readable, Writable True False False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable True False False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable True False False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable True False False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
pagefile_0x000000007efe0000 0x7efe0000 0x7f0dffff Pagefile Backed Memory Readable True False False
private_0x000000007f0e0000 0x7f0e0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True False False
private_0x000000007fff0000 0x7fff0000 0x7fffffeffff Private Memory Readable True False False
Host Behavior
File (4)
+
Operation Filename Additional Information Success Count Logfile
CREATE c:\windows\system32\&hdgf$w#gsrghregrw share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, create_disposition = OPEN_EXISTING False 1
Fn
OPEN STD_INPUT_HANDLE True 1
Fn
OPEN STD_OUTPUT_HANDLE True 1
Fn
OPEN STD_ERROR_HANDLE True 1
Fn
Process (1)
+
Operation Process Name Additional Information Success Count Logfile
CREATE C:\Users\HJRD1K~1\AppData\Roaming\CONVIN~1.EXE os_tid = 0xbd4, os_pid = 0xbd0, creation_flags = CREATE_SUSPENDED, show_window = SW_HIDE True 1
Fn
Memory (4)
+
Operation Address Additional Information Success Count Logfile
ALLOC 0x400000 process_name = C:\Users\HJRD1K~1\AppData\Roaming\CONVIN~1.EXE, os_pid = 0xbd0, size = 24576, allocation_type = MEM_COMMIT, MEM_RESERVE, protection = PAGE_EXECUTE_READWRITE True 1
Fn
WRITE 0x400000 process_name = C:\Users\HJRD1K~1\AppData\Roaming\CONVIN~1.EXE, os_pid = 0xbd0, size = 512 True 1
Fn
Data
WRITE 0x401000 process_name = C:\Users\HJRD1K~1\AppData\Roaming\CONVIN~1.EXE, os_pid = 0xbd0, size = 16384 True 1
Fn
Data
WRITE 0x405000 process_name = C:\Users\HJRD1K~1\AppData\Roaming\CONVIN~1.EXE, os_pid = 0xbd0, size = 512 True 1
Fn
Data
Thread (3)
+
Operation Process Name Additional Information Success Count Logfile
RESUME c:\users\hjrd1k~1\appdata\roaming\convin~1.exe os_tid = 0xbd4, os_pid = 0xbd0 True 1
Fn
GET_CONTEXT c:\users\hjrd1k~1\appdata\roaming\convin~1.exe os_tid = 0xbd4, os_pid = 0xbd0 True 1
Fn
SET_CONTEXT c:\users\hjrd1k~1\appdata\roaming\convin~1.exe os_tid = 0xbd4, os_pid = 0xbd0 True 1
Fn
Module (2034)
+
Operation Module Additional Information Success Count Logfile
LOAD kernel32 base_address = 0x76530000 True 1
Fn
GET_HANDLE c:\windows\syswow64\kernel32.dll base_address = 0x76530000 True 11
Fn
GET_HANDLE c:\users\hjrd1koky ds8lujv\appdata\roaming\convincingly.exe base_address = 0x400000 True 1999
Fn
GET_HANDLE c:\windows\syswow64\ntdll.dll base_address = 0x77b70000 True 1
Fn
UNMAP C:\Users\HJRD1K~1\AppData\Roaming\CONVIN~1.EXE os_pid = 0xbd0, base_address = 0x400000 True 1
Fn
GET_FILENAME C:\Users\HJRD1K~1\AppData\Roaming\CONVIN~1.EXE True 2
Fn
GET_PROC_ADDRESS c:\windows\syswow64\kernel32.dll function = FlsAlloc, address = 0x76544f2b True 1
Fn
GET_PROC_ADDRESS c:\windows\syswow64\kernel32.dll function = FlsGetValue, address = 0x76541252 True 1
Fn
GET_PROC_ADDRESS c:\windows\syswow64\kernel32.dll function = FlsSetValue, address = 0x76544208 True 1
Fn
GET_PROC_ADDRESS c:\windows\syswow64\kernel32.dll function = FlsFree, address = 0x7654359f True 1
Fn
GET_PROC_ADDRESS c:\windows\syswow64\kernel32.dll function = EncodePointer, address = 0x77bb0fcb True 8
Fn
GET_PROC_ADDRESS c:\windows\syswow64\kernel32.dll function = DecodePointer, address = 0x77ba9d35 True 3
Fn
GET_PROC_ADDRESS c:\windows\syswow64\kernel32.dll function = QueryPerformanceFrequency, address = 0x765441f0 True 1
Fn
GET_PROC_ADDRESS c:\windows\syswow64\kernel32.dll function = QueryPerformanceCounter, address = 0x76541725 True 1
Fn
GET_PROC_ADDRESS c:\windows\syswow64\kernel32.dll function = IsBadCodePtr, address = 0x76562b34 True 1
Fn
GET_PROC_ADDRESS c:\windows\syswow64\ntdll.dll function = NtUnmapViewOfSection, address = 0x77b8fc70 True 1
Fn
Driver (2800)
+
Operation Driver Additional Information Success Count Logfile
CONTROL control_code = 0x0 False 2800
Fn
Process #19: convin~1.exe
(Host: 13, Network: 0)
+
Information Value
ID / OS PID #19 / 0xbd0
OS Parent PID 0xb7c (c:\users\hjrd1k~1\appdata\roaming\convin~1.exe)
Initial Working Directory C:\Windows\system32
File Name c:\users\hjrd1k~1\appdata\roaming\convin~1.exe
Command Line C:\Users\HJRD1K~1\AppData\Roaming\CONVIN~1.EXE
Monitor Start Time: 00:01:14, Reason: Child Process
Unmonitor End Time: 00:01:14, Reason: Terminated
Monitor Duration 00:00:00
OS Thread IDs
# 56
0x BD4
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000020000 0x00020000 0x00020fff Private Memory Readable, Writable True False False
private_0x0000000000030000 0x00030000 0x00031fff Private Memory Readable, Writable True False False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000000050000 0x00050000 0x0008ffff Private Memory Readable, Writable True False False
private_0x0000000000090000 0x00090000 0x0018ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000190000 0x00190000 0x00193fff Pagefile Backed Memory Readable True False False
private_0x00000000001e0000 0x001e0000 0x0025ffff Private Memory Readable, Writable True False False
private_0x00000000002a0000 0x002a0000 0x0039ffff Private Memory Readable, Writable True False False
private_0x00000000003e0000 0x003e0000 0x003effff Private Memory Readable, Writable True False False
private_0x0000000000400000 0x00400000 0x00405fff Private Memory Readable, Writable, Executable True False False
locale.nls 0x00410000 0x00476fff Memory Mapped File Readable False False False
SortDefault.nls 0x00480000 0x0074efff Memory Mapped File Readable False False False
wow64win.dll 0x75090000 0x750ebfff Memory Mapped File Readable, Writable, Executable False False False
wow64.dll 0x750f0000 0x7512efff Memory Mapped File Readable, Writable, Executable False False False
wow64cpu.dll 0x75680000 0x75687fff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x756c0000 0x756cbfff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x756d0000 0x7572ffff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x75730000 0x7581ffff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x759e0000 0x75a25fff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76040000 0x760ebfff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76470000 0x7650ffff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x76530000 0x7663ffff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x77610000 0x77628fff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000077770000 0x77770000 0x77869fff Private Memory Readable, Writable, Executable True False False
private_0x0000000077870000 0x77870000 0x7798efff Private Memory Readable, Writable, Executable True False False
ntdll.dll 0x77990000 0x77b38fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77b70000 0x77ceffff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007efb0000 0x7efb0000 0x7efd2fff Pagefile Backed Memory Readable True False False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable True False False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable True False False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable True False False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
pagefile_0x000000007efe0000 0x7efe0000 0x7f0dffff Pagefile Backed Memory Readable True False False
private_0x000000007f0e0000 0x7f0e0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True False False
private_0x000000007fff0000 0x7fff0000 0x7fffffeffff Private Memory Readable True False False
Injection Information
+
Injection Type Source Process Source Os Thread ID Injection Info Success Count Logfile
Modify Memory c:\users\hjrd1k~1\appdata\roaming\convin~1.exe 0xb80 address = 0x400000, size = 512 True 1
Fn
Data
Modify Memory c:\users\hjrd1k~1\appdata\roaming\convin~1.exe 0xb80 address = 0x401000, size = 16384 True 1
Fn
Data
Modify Memory c:\users\hjrd1k~1\appdata\roaming\convin~1.exe 0xb80 address = 0x405000, size = 512 True 1
Fn
Data
Modify Control Flow c:\users\hjrd1k~1\appdata\roaming\convin~1.exe 0xb80 os_thread_id = 0xbd4 True 1
Fn
Host Behavior
Process (3)
+
Operation Process Name Additional Information Success Count Logfile
CREATE C:\Windows\SysWOW64\explorer.exe os_tid = 0xbdc, os_pid = 0xbd8, creation_flags = CREATE_SUSPENDED, show_window = SW_HIDE True 1
Fn
OPEN_TOKEN c:\users\hjrd1koky ds8lujv\appdata\roaming\convincingly.exe os_pid = 0x9c4, desired_access = PROCESS_VM_OPERATION, desired_access = PROCESS_VM_OPERATION True 1
Fn
GET_INFO C:\Windows\SysWOW64\explorer.exe os_pid = 0xbd8 True 1
Fn
Memory (3)
+
Operation Address Additional Information Success Count Logfile
READ 0x7efde008 process_name = C:\Windows\SysWOW64\explorer.exe, os_pid = 0xbd8, size = 4 True 1
Fn
Data
READ 0xef0000 process_name = C:\Windows\SysWOW64\explorer.exe, os_pid = 0xbd8, size = 1280 True 1
Fn
Data
READ 0xef0000 process_name = C:\Windows\SysWOW64\explorer.exe, os_pid = 0xbd8, size = 2625536 True 1
Fn
Thread (1)
+
Operation Process Name Additional Information Success Count Logfile
RESUME c:\windows\syswow64\explorer.exe os_tid = 0xbdc, os_pid = 0xbd8 True 1
Fn
Module (6)
+
Operation Module Additional Information Success Count Logfile
LOAD advapi32.dll base_address = 0x76470000 True 1
Fn
CREATE_MAPPING module_name = Nameless FileMapping, maximum_size = 1638132, protection = PAGE_EXECUTE_READWRITE True 1
Fn
MAP c:\users\hjrd1koky ds8lujv\appdata\roaming\convincingly.exe os_pid = 0x9c4, address = 0x9e0000 True 1
Fn
MAP C:\Windows\SysWOW64\explorer.exe os_pid = 0xbd8, address = 0xef0000 True 1
Fn
UNMAP C:\Windows\SysWOW64\explorer.exe os_pid = 0xbd8, base_address = 0xef0000 True 1
Fn
GET_FILENAME C:\Users\HJRD1K~1\AppData\Roaming\CONVIN~1.EXE True 1
Fn
Process #20: explorer.exe
(Host: 43, Network: 0)
+
Information Value
ID / OS PID #20 / 0xbd8
OS Parent PID 0xbd0 (c:\users\hjrd1k~1\appdata\roaming\convin~1.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\syswow64\explorer.exe
Command Line C:\Windows\SysWOW64\explorer.exe
Monitor Start Time: 00:01:14, Reason: Child Process
Unmonitor End Time: 00:01:17, Reason: Terminated
Monitor Duration 00:00:03
OS Thread IDs
# 57
0x BDC
# 60
0x BF0
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x00021fff Pagefile Backed Memory Readable True False False
private_0x0000000000030000 0x00030000 0x00031fff Private Memory Readable, Writable True False False
pagefile_0x0000000000030000 0x00030000 0x00036fff Pagefile Backed Memory Readable True False False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000050000 0x00050000 0x00053fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000060000 0x00060000 0x00061fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000070000 0x00070000 0x00071fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000080000 0x00080000 0x00080fff Private Memory Readable, Writable True False False
private_0x0000000000090000 0x00090000 0x00090fff Private Memory Readable, Writable True False False
private_0x00000000000a0000 0x000a0000 0x000dffff Private Memory Readable, Writable True False False
locale.nls 0x000e0000 0x00146fff Memory Mapped File Readable False False False
private_0x0000000000150000 0x00150000 0x0016ffff Private Memory Readable, Writable True False False
private_0x0000000000170000 0x00170000 0x00173fff Private Memory Readable, Writable True False False
private_0x0000000000180000 0x00180000 0x00183fff Private Memory Readable, Writable True False False
private_0x0000000000190000 0x00190000 0x001cffff Private Memory Readable, Writable True False False
private_0x00000000001d0000 0x001d0000 0x001d0fff Private Memory Readable, Writable True False False
private_0x00000000001e0000 0x001e0000 0x001e0fff Private Memory Readable, Writable True False False
private_0x00000000001e0000 0x001e0000 0x001e3fff Private Memory Readable, Writable True False False
private_0x00000000001e0000 0x001e0000 0x001e0fff Private Memory Readable, Writable True False False
private_0x00000000001f0000 0x001f0000 0x0026ffff Private Memory Readable, Writable True False False
private_0x0000000000270000 0x00270000 0x00282fff Private Memory Readable, Writable True False False
private_0x0000000000270000 0x00270000 0x00270fff Private Memory Readable, Writable True False False
private_0x00000000002a0000 0x002a0000 0x002dffff Private Memory Readable, Writable True False False
private_0x0000000000360000 0x00360000 0x0039ffff Private Memory Readable, Writable True False False
private_0x00000000003f0000 0x003f0000 0x004effff Private Memory Readable, Writable True False False
pagefile_0x00000000004f0000 0x004f0000 0x00677fff Pagefile Backed Memory Readable True False False
private_0x00000000006c0000 0x006c0000 0x006cffff Private Memory Readable, Writable True False False
pagefile_0x00000000006d0000 0x006d0000 0x00850fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000860000 0x00860000 0x00c52fff Pagefile Backed Memory Readable True False False
private_0x0000000000d40000 0x00d40000 0x00d7ffff Private Memory Readable, Writable True False False
private_0x0000000000e30000 0x00e30000 0x00e6ffff Private Memory Readable, Writable True False False
explorer.exe 0x00ef0000 0x01170fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000ef0000 0x00ef0000 0x01170fff Pagefile Backed Memory Readable, Writable, Executable True False False
pagefile_0x0000000001180000 0x01180000 0x0257ffff Pagefile Backed Memory Readable True False False
SortDefault.nls 0x02580000 0x0284efff Memory Mapped File Readable False False False
private_0x0000000010000000 0x10000000 0x10014fff Private Memory Readable, Writable, Executable True False False
ExplorerFrame.dll 0x66f20000 0x6708efff Memory Mapped File Readable, Writable, Executable False False False
davhlpr.dll 0x67220000 0x67227fff Memory Mapped File Readable, Writable, Executable False False False
davclnt.dll 0x67230000 0x67246fff Memory Mapped File Readable, Writable, Executable False False False
dui70.dll 0x67250000 0x67301fff Memory Mapped File Readable, Writable, Executable False False False
mpr.dll 0x67590000 0x675a1fff Memory Mapped File Readable, Writable, Executable False False False
duser.dll 0x675b0000 0x675defff Memory Mapped File Readable, Writable, Executable False False False
ntlanman.dll 0x675e0000 0x675f3fff Memory Mapped File Readable, Writable, Executable False False False
drprov.dll 0x67600000 0x67607fff Memory Mapped File Readable, Writable, Executable False False False
powrprof.dll 0x687e0000 0x68804fff Memory Mapped File Readable, Writable, Executable False False False
propsys.dll 0x69200000 0x692f4fff Memory Mapped File Readable, Writable, Executable False False False
secur32.dll 0x69480000 0x69487fff Memory Mapped File Readable, Writable, Executable False False False
winsta.dll 0x6f8a0000 0x6f8c8fff Memory Mapped File Readable, Writable, Executable False False False
uxtheme.dll 0x6f8e0000 0x6f95ffff Memory Mapped File Readable, Writable, Executable False False False
slc.dll 0x70db0000 0x70db9fff Memory Mapped File Readable, Writable, Executable False False False
GdiPlus.dll 0x72c40000 0x72dcffff Memory Mapped File Readable, Writable, Executable False False False
dwmapi.dll 0x72dd0000 0x72de2fff Memory Mapped File Readable, Writable, Executable False False False
wow64win.dll 0x75090000 0x750ebfff Memory Mapped File Readable, Writable, Executable False False False
wow64.dll 0x750f0000 0x7512efff Memory Mapped File Readable, Writable, Executable False False False
wow64cpu.dll 0x75680000 0x75687fff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x756c0000 0x756cbfff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x756d0000 0x7572ffff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x75730000 0x7581ffff Memory Mapped File Readable, Writable, Executable False False False
ole32.dll 0x75880000 0x759dbfff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x759e0000 0x75a25fff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x75a30000 0x75accfff Memory Mapped File Readable, Writable, Executable False False False
cfgmgr32.dll 0x75ad0000 0x75af6fff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x75b00000 0x75b09fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75b10000 0x75bdbfff Memory Mapped File Readable, Writable, Executable False False False
iertutil.dll 0x75be0000 0x75ddafff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x75e10000 0x75f0ffff Memory Mapped File Readable, Writable, Executable False False False
crypt32.dll 0x75f10000 0x7602cfff Memory Mapped File Readable, Writable, Executable False False False
msasn1.dll 0x76030000 0x7603bfff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76040000 0x760ebfff Memory Mapped File Readable, Writable, Executable False False False
devobj.dll 0x76200000 0x76211fff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x76220000 0x7627ffff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76280000 0x7630ffff Memory Mapped File Readable, Writable, Executable False False False
ws2_32.dll 0x763a0000 0x763d4fff Memory Mapped File Readable, Writable, Executable False False False
shlwapi.dll 0x76410000 0x76466fff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76470000 0x7650ffff Memory Mapped File Readable, Writable, Executable False False False
nsi.dll 0x76510000 0x76515fff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x76530000 0x7663ffff Memory Mapped File Readable, Writable, Executable False False False
setupapi.dll 0x76640000 0x767dcfff Memory Mapped File Readable, Writable, Executable False False False
wininet.dll 0x767e0000 0x768d4fff Memory Mapped File Readable, Writable, Executable False False False
oleaut32.dll 0x768e0000 0x7696efff Memory Mapped File Readable, Writable, Executable False False False
shell32.dll 0x76970000 0x775b9fff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x77610000 0x77628fff Memory Mapped File Readable, Writable, Executable False False False
urlmon.dll 0x77630000 0x77765fff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000077770000 0x77770000 0x77869fff Private Memory Readable, Writable, Executable True False False
private_0x0000000077870000 0x77870000 0x7798efff Private Memory Readable, Writable, Executable True False False
ntdll.dll 0x77990000 0x77b38fff Memory Mapped File Readable, Writable, Executable False False False
psapi.dll 0x77b40000 0x77b44fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77b70000 0x77ceffff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007efb0000 0x7efb0000 0x7efd2fff Pagefile Backed Memory Readable True False False
private_0x000000007efd8000 0x7efd8000 0x7efdafff Private Memory Readable, Writable True False False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable True False False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable True False False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable True False False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
pagefile_0x000000007efe0000 0x7efe0000 0x7f0dffff Pagefile Backed Memory Readable True False False
private_0x000000007f0e0000 0x7f0e0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True False False
private_0x000000007fff0000 0x7fff0000 0x7fffffeffff Private Memory Readable True False False
Injection Information
+
Injection Type Source Process Source Os Thread ID Injection Info Success Count Logfile
Modify Memory c:\users\hjrd1k~1\appdata\roaming\convin~1.exe 0xbd4 address = 0xef0000, size = 2625536 True 1
Fn
Data
Host Behavior
File (4)
+
Operation Filename Additional Information Success Count Logfile
CREATE c:\users\hjrd1k~1\appdata\roaming\convin~1.exe desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTING True 1
Fn
CREATE c:\windows\syswow64\ntdll.dll desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTING True 1
Fn
READ c:\users\hjrd1k~1\appdata\roaming\convin~1.exe size = 74752 True 1
Fn
Data
DELETE c:\users\hjrd1k~1\appdata\roaming\convin~1.exe True 1
Fn
Process (5)
+
Operation Process Name Additional Information Success Count Logfile
CREATE cmd.exe \c net stop MpsSvc os_tid = 0xbe4, os_pid = 0xbe0, startup_flags = STARTF_USESHOWWINDOW, show_window = SW_HIDE True 1
Fn
CREATE cmd.exe \c sc config MpsSvc start= disabled os_tid = 0xbec, os_pid = 0xbe8, startup_flags = STARTF_USESHOWWINDOW, show_window = SW_HIDE True 1
Fn
CREATE "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome os_tid = 0x830, os_pid = 0x834, creation_flags = CREATE_SUSPENDED, show_window = SW_HIDE True 1
Fn
OPEN_TOKEN c:\users\hjrd1koky ds8lujv\appdata\roaming\convincingly.exe os_pid = 0x9c4, desired_access = PROCESS_VM_OPERATION, desired_access = PROCESS_VM_OPERATION True 1
Fn
GET_INFO "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome os_pid = 0x834 True 1
Fn
Memory (3)
+
Operation Address Additional Information Success Count Logfile
READ 0x7efde008 process_name = "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome, os_pid = 0x834, size = 4 True 1
Fn
Data
READ 0xd30000 process_name = "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome, os_pid = 0x834, size = 1280 True 1
Fn
Data
READ 0xd30000 process_name = "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome, os_pid = 0x834, size = 679936 True 1
Fn
Data
Thread (1)
+
Operation Process Name Additional Information Success Count Logfile
RESUME c:\program files (x86)\internet explorer\iexplore.exe os_tid = 0x830, os_pid = 0x834 True 1
Fn
Module (20)
+
Operation Module Additional Information Success Count Logfile
LOAD advapi32.dll base_address = 0x76470000 True 1
Fn
LOAD shell32.dll base_address = 0x76970000 True 1
Fn
LOAD user32.dll base_address = 0x75e10000 True 1
Fn
LOAD urlmon.dll base_address = 0x77630000 True 1
Fn
LOAD wininet.dll base_address = 0x767e0000 True 1
Fn
LOAD crypt32.dll base_address = 0x75f10000 True 1
Fn
LOAD mpr.dll base_address = 0x67590000 True 1
Fn
LOAD ole32.dll base_address = 0x75880000 True 1
Fn
LOAD ws2_32.dll base_address = 0x763a0000 True 1
Fn
LOAD psapi.dll base_address = 0x77b40000 True 1
Fn
CREATE_MAPPING module_name = kmkzdbqzhkjrnegx, maximum_size = 12765, protection = PAGE_READWRITE True 1
Fn
CREATE_MAPPING module_name = Nameless FileMapping, maximum_size = 3013696, protection = PAGE_EXECUTE_READWRITE True 1
Fn
MAP c:\windows\syswow64\explorer.exe os_pid = 0xbd8, module_name = kmkzdbqzhkjrnegx, desired_access = FILE_MAP_WRITE, FILE_MAP_READ, file_offset = 0, address = 0x280000 True 1
Fn
MAP c:\users\hjrd1koky ds8lujv\appdata\roaming\convincingly.exe os_pid = 0x9c4, address = 0xd80000 True 1
Fn
MAP "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome os_pid = 0x834, address = 0xd30000 True 1
Fn
UNMAP c:\windows\syswow64\explorer.exe os_pid = 0xbd8, base_address = 0x280000 True 1
Fn
UNMAP "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome os_pid = 0x834, base_address = 0xd30000 True 1
Fn
GET_FILENAME C:\Windows\SysWOW64\explorer.exe True 1
Fn
GET_FILENAME C:\Windows\SysWOW64\ntdll.dll True 2
Fn
Service (3)
+
Operation Service Additional Information Success Count Logfile
OPEN_MGR SERVICES_ACTIVE_DATABASE host = Localhost, desired_access = GENERIC_READ True 1
Fn
ENUMERATE SERVICES_ACTIVE_DATABASE False 1
Fn
ENUMERATE SERVICES_ACTIVE_DATABASE True 1
Fn
Registry (6)
+
Operation Key Additional Information Success Count Logfile
OPEN_KEY HKEY_CURRENT_USER\Software\Microsoft\Windows True 1
Fn
OPEN_KEY HKEY_CURRENT_USER\Software\Classes\http\shell\open\command False 1
Fn
OPEN_KEY HKEY_LOCAL_MACHINE\Software\Classes\http\shell\open\command True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Classes\http\shell\open\command True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Classes\http\shell\open\command data_ident_out = 34 True 1
Fn
WRITE_VALUE HKEY_CURRENT_USER\Software\Microsoft\Windows data = 0 True 1
Fn
System (1)
+
Operation Information Success Count Logfile
SLEEP duration = 512 milliseconds (0.512 seconds) True 1
Fn
Process #21: cmd.exe
(Host: 35, Network: 0)
+
Information Value
ID / OS PID #21 / 0xbe0
OS Parent PID 0xbd8 (c:\windows\syswow64\explorer.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\syswow64\cmd.exe
Command Line cmd.exe /c net stop MpsSvc
Monitor Start Time: 00:01:15, Reason: Child Process
Unmonitor End Time: 00:01:31, Reason: Terminated
Monitor Duration 00:00:16
OS Thread IDs
# 58
0x BE4
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000030000 0x00030000 0x00031fff Private Memory Readable, Writable True False False
pagefile_0x0000000000030000 0x00030000 0x00036fff Pagefile Backed Memory Readable True False False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000050000 0x00050000 0x00053fff Pagefile Backed Memory Readable True False False
private_0x0000000000060000 0x00060000 0x0015ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000160000 0x00160000 0x00160fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000170000 0x00170000 0x00171fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000180000 0x00180000 0x0018ffff Private Memory Readable, Writable True False False
private_0x0000000000190000 0x00190000 0x00190fff Private Memory Readable, Writable True False False
private_0x00000000001a0000 0x001a0000 0x001a0fff Private Memory Readable, Writable True False False
private_0x00000000001d0000 0x001d0000 0x0020ffff Private Memory Readable, Writable True False False
locale.nls 0x00210000 0x00276fff Memory Mapped File Readable False False False
private_0x00000000003c0000 0x003c0000 0x0043ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000440000 0x00440000 0x005c7fff Pagefile Backed Memory Readable True False False
private_0x00000000005f0000 0x005f0000 0x006effff Private Memory Readable, Writable True False False
pagefile_0x00000000006f0000 0x006f0000 0x00870fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000880000 0x00880000 0x01c7ffff Pagefile Backed Memory Readable True False False
pagefile_0x0000000001c80000 0x01c80000 0x01fc2fff Pagefile Backed Memory Readable True False False
cmd.exe 0x4a040000 0x4a08bfff Memory Mapped File Readable, Writable, Executable True False False
winbrand.dll 0x67580000 0x67586fff Memory Mapped File Readable, Writable, Executable False False False
wow64win.dll 0x75090000 0x750ebfff Memory Mapped File Readable, Writable, Executable False False False
wow64.dll 0x750f0000 0x7512efff Memory Mapped File Readable, Writable, Executable False False False
wow64cpu.dll 0x75680000 0x75687fff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x756c0000 0x756cbfff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x756d0000 0x7572ffff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x75730000 0x7581ffff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x759e0000 0x75a25fff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x75a30000 0x75accfff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x75b00000 0x75b09fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75b10000 0x75bdbfff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x75e10000 0x75f0ffff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76040000 0x760ebfff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x76220000 0x7627ffff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76280000 0x7630ffff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76470000 0x7650ffff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x76530000 0x7663ffff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x77610000 0x77628fff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000077770000 0x77770000 0x77869fff Private Memory Readable, Writable, Executable True False False
private_0x0000000077870000 0x77870000 0x7798efff Private Memory Readable, Writable, Executable True False False
ntdll.dll 0x77990000 0x77b38fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77b70000 0x77ceffff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007efb0000 0x7efb0000 0x7efd2fff Pagefile Backed Memory Readable True False False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable True False False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable True False False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable True False False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
pagefile_0x000000007efe0000 0x7efe0000 0x7f0dffff Pagefile Backed Memory Readable True False False
private_0x000000007f0e0000 0x7f0e0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True False False
private_0x000000007fff0000 0x7fff0000 0x7fffffeffff Private Memory Readable True False False
Host Behavior
File (8)
+
Operation Filename Additional Information Success Count Logfile
OPEN STD_OUTPUT_HANDLE True 5
Fn
OPEN STD_INPUT_HANDLE True 3
Fn
Process (2)
+
Operation Process Name Additional Information Success Count Logfile
CREATE C:\Windows\system32\net.exe os_tid = 0x84c, os_pid = 0x844, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, current_directory = C:\Windows\system32, show_window = SW_SHOWNORMAL True 1
Fn
SET_CURDIR c:\windows\syswow64\cmd.exe os_pid = 0xbe0, new_path_name = c:\windows\system32 True 1
Fn
Module (8)
+
Operation Module Additional Information Success Count Logfile
GET_HANDLE c:\windows\syswow64\cmd.exe base_address = 0x4a040000 True 1
Fn
GET_HANDLE c:\windows\syswow64\kernel32.dll base_address = 0x76530000 True 2
Fn
GET_FILENAME C:\Windows\SysWOW64\cmd.exe True 1
Fn
GET_PROC_ADDRESS c:\windows\syswow64\kernel32.dll function = SetThreadUILanguage, address = 0x7655a84f True 1
Fn
GET_PROC_ADDRESS c:\windows\syswow64\kernel32.dll function = CopyFileExW, address = 0x76563b92 True 1
Fn
GET_PROC_ADDRESS c:\windows\syswow64\kernel32.dll function = IsDebuggerPresent, address = 0x76544a5d True 1
Fn
GET_PROC_ADDRESS c:\windows\syswow64\kernel32.dll function = SetConsoleInputExeNameW, address = 0x7655a79d True 1
Fn
Registry (17)
+
Operation Key Additional Information Success Count Logfile
OPEN_KEY HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System False 1
Fn
OPEN_KEY HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor True 1
Fn
OPEN_KEY HKEY_CURRENT_USER\Software\Microsoft\Command Processor True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data_ident_out = 50 False 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = EnableExtensions, data_ident_out = 1 True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DelayedExpansion, data_ident_out = 1 False 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DefaultColor, data_ident_out = 0 True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = CompletionChar, data_ident_out = 64 True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = PathCompletionChar, data_ident_out = 64 True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = AutoRun, data_ident_out = 64 False 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data_ident_out = 64 False 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = EnableExtensions, data_ident_out = 1 True 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DelayedExpansion, data_ident_out = 1 False 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DefaultColor, data_ident_out = 0 True 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = CompletionChar, data_ident_out = 9 True 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = PathCompletionChar, data_ident_out = 9 True 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = AutoRun, data_ident_out = 9 False 1
Fn
Process #22: cmd.exe
(Host: 35, Network: 0)
+
Information Value
ID / OS PID #22 / 0xbe8
OS Parent PID 0xbd8 (c:\windows\syswow64\explorer.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\syswow64\cmd.exe
Command Line cmd.exe /c sc config MpsSvc start= disabled
Monitor Start Time: 00:01:15, Reason: Child Process
Unmonitor End Time: 00:01:16, Reason: Terminated
Monitor Duration 00:00:01
OS Thread IDs
# 59
0x BEC
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000030000 0x00030000 0x00031fff Private Memory Readable, Writable True False False
private_0x0000000000030000 0x00030000 0x0003ffff Private Memory Readable, Writable True False False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000050000 0x00050000 0x00053fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000060000 0x00060000 0x00060fff Pagefile Backed Memory Readable True False False
locale.nls 0x00070000 0x000d6fff Memory Mapped File Readable False False False
pagefile_0x00000000000e0000 0x000e0000 0x000e6fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000000f0000 0x000f0000 0x000f1fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000100000 0x00100000 0x00100fff Private Memory Readable, Writable True False False
private_0x0000000000110000 0x00110000 0x00110fff Private Memory Readable, Writable True False False
private_0x0000000000140000 0x00140000 0x0017ffff Private Memory Readable, Writable True False False
private_0x00000000001a0000 0x001a0000 0x0029ffff Private Memory Readable, Writable True False False
private_0x0000000000370000 0x00370000 0x003effff Private Memory Readable, Writable True False False
private_0x00000000004c0000 0x004c0000 0x005bffff Private Memory Readable, Writable True False False
pagefile_0x00000000005c0000 0x005c0000 0x00747fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000750000 0x00750000 0x008d0fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000008e0000 0x008e0000 0x01cdffff Pagefile Backed Memory Readable True False False
pagefile_0x0000000001ce0000 0x01ce0000 0x02022fff Pagefile Backed Memory Readable True False False
cmd.exe 0x4a040000 0x4a08bfff Memory Mapped File Readable, Writable, Executable True False False
winbrand.dll 0x67580000 0x67586fff Memory Mapped File Readable, Writable, Executable False False False
wow64win.dll 0x75090000 0x750ebfff Memory Mapped File Readable, Writable, Executable False False False
wow64.dll 0x750f0000 0x7512efff Memory Mapped File Readable, Writable, Executable False False False
wow64cpu.dll 0x75680000 0x75687fff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x756c0000 0x756cbfff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x756d0000 0x7572ffff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x75730000 0x7581ffff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x759e0000 0x75a25fff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x75a30000 0x75accfff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x75b00000 0x75b09fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75b10000 0x75bdbfff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x75e10000 0x75f0ffff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76040000 0x760ebfff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x76220000 0x7627ffff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76280000 0x7630ffff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76470000 0x7650ffff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x76530000 0x7663ffff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x77610000 0x77628fff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000077770000 0x77770000 0x77869fff Private Memory Readable, Writable, Executable True False False
private_0x0000000077870000 0x77870000 0x7798efff Private Memory Readable, Writable, Executable True False False
ntdll.dll 0x77990000 0x77b38fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77b70000 0x77ceffff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007efb0000 0x7efb0000 0x7efd2fff Pagefile Backed Memory Readable True False False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable True False False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable True False False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable True False False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
pagefile_0x000000007efe0000 0x7efe0000 0x7f0dffff Pagefile Backed Memory Readable True False False
private_0x000000007f0e0000 0x7f0e0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True False False
private_0x000000007fff0000 0x7fff0000 0x7fffffeffff Private Memory Readable True False False
Host Behavior
File (8)
+
Operation Filename Additional Information Success Count Logfile
OPEN STD_OUTPUT_HANDLE True 5
Fn
OPEN STD_INPUT_HANDLE True 3
Fn
Process (2)
+
Operation Process Name Additional Information Success Count Logfile
CREATE C:\Windows\system32\sc.exe os_tid = 0x848, os_pid = 0x854, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, current_directory = C:\Windows\system32, show_window = SW_SHOWNORMAL True 1
Fn
SET_CURDIR c:\windows\syswow64\cmd.exe os_pid = 0xbe8, new_path_name = c:\windows\system32 True 1
Fn
Module (8)
+
Operation Module Additional Information Success Count Logfile
GET_HANDLE c:\windows\syswow64\cmd.exe base_address = 0x4a040000 True 1
Fn
GET_HANDLE c:\windows\syswow64\kernel32.dll base_address = 0x76530000 True 2
Fn
GET_FILENAME C:\Windows\SysWOW64\cmd.exe True 1
Fn
GET_PROC_ADDRESS c:\windows\syswow64\kernel32.dll function = SetThreadUILanguage, address = 0x7655a84f True 1
Fn
GET_PROC_ADDRESS c:\windows\syswow64\kernel32.dll function = CopyFileExW, address = 0x76563b92 True 1
Fn
GET_PROC_ADDRESS c:\windows\syswow64\kernel32.dll function = IsDebuggerPresent, address = 0x76544a5d True 1
Fn
GET_PROC_ADDRESS c:\windows\syswow64\kernel32.dll function = SetConsoleInputExeNameW, address = 0x7655a79d True 1
Fn
Registry (17)
+
Operation Key Additional Information Success Count Logfile
OPEN_KEY HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System False 1
Fn
OPEN_KEY HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor True 1
Fn
OPEN_KEY HKEY_CURRENT_USER\Software\Microsoft\Command Processor True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data_ident_out = 0 False 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = EnableExtensions, data_ident_out = 1 True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DelayedExpansion, data_ident_out = 1 False 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = DefaultColor, data_ident_out = 0 True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = CompletionChar, data_ident_out = 64 True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = PathCompletionChar, data_ident_out = 64 True 1
Fn
READ_VALUE HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor value_name = AutoRun, data_ident_out = 64 False 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DisableUNCCheck, data_ident_out = 64 False 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = EnableExtensions, data_ident_out = 1 True 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DelayedExpansion, data_ident_out = 1 False 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = DefaultColor, data_ident_out = 0 True 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = CompletionChar, data_ident_out = 9 True 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = PathCompletionChar, data_ident_out = 9 True 1
Fn
READ_VALUE HKEY_CURRENT_USER\Software\Microsoft\Command Processor value_name = AutoRun, data_ident_out = 9 False 1
Fn
Process #23: net.exe
+
Information Value
ID / OS PID #23 / 0x844
OS Parent PID 0xbe0 (c:\windows\syswow64\cmd.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\syswow64\net.exe
Command Line net stop MpsSvc
Monitor Start Time: 00:01:15, Reason: Child Process
Unmonitor End Time: 00:01:31, Reason: Terminated
Monitor Duration 00:00:16
OS Thread IDs
# 61
0x 84C
Remarks No high level activity detected in monitored regions
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000030000 0x00030000 0x00031fff Private Memory Readable, Writable True False False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000050000 0x00050000 0x00053fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000060000 0x00060000 0x00060fff Pagefile Backed Memory Readable True False False
private_0x00000000000a0000 0x000a0000 0x000dffff Private Memory Readable, Writable True False False
locale.nls 0x000e0000 0x00146fff Memory Mapped File Readable False False False
private_0x00000000001d0000 0x001d0000 0x0024ffff Private Memory Readable, Writable True False False
net.exe 0x00270000 0x00287fff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000000290000 0x00290000 0x0030ffff Private Memory Readable, Writable True False False
private_0x00000000003e0000 0x003e0000 0x003effff Private Memory Readable, Writable True False False
private_0x0000000000400000 0x00400000 0x004fffff Private Memory Readable, Writable True False False
winnsi.dll 0x671b0000 0x671b6fff Memory Mapped File Readable, Writable, Executable False False False
IPHLPAPI.DLL 0x671c0000 0x671dbfff Memory Mapped File Readable, Writable, Executable False False False
wkscli.dll 0x671e0000 0x671eefff Memory Mapped File Readable, Writable, Executable False False False
samcli.dll 0x671f0000 0x671fefff Memory Mapped File Readable, Writable, Executable False False False
browcli.dll 0x67200000 0x6720cfff Memory Mapped File Readable, Writable, Executable False False False
netutils.dll 0x67210000 0x67218fff Memory Mapped File Readable, Writable, Executable False False False
mpr.dll 0x67590000 0x675a1fff Memory Mapped File Readable, Writable, Executable False False False
srvcli.dll 0x68600000 0x68618fff Memory Mapped File Readable, Writable, Executable False False False
wow64win.dll 0x75090000 0x750ebfff Memory Mapped File Readable, Writable, Executable False False False
wow64.dll 0x750f0000 0x7512efff Memory Mapped File Readable, Writable, Executable False False False
wow64cpu.dll 0x75680000 0x75687fff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x756c0000 0x756cbfff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x756d0000 0x7572ffff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x75730000 0x7581ffff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x759e0000 0x75a25fff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76040000 0x760ebfff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76470000 0x7650ffff Memory Mapped File Readable, Writable, Executable False False False
nsi.dll 0x76510000 0x76515fff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x76530000 0x7663ffff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x77610000 0x77628fff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000077770000 0x77770000 0x77869fff Private Memory Readable, Writable, Executable True False False
private_0x0000000077870000 0x77870000 0x7798efff Private Memory Readable, Writable, Executable True False False
ntdll.dll 0x77990000 0x77b38fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77b70000 0x77ceffff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007efb0000 0x7efb0000 0x7efd2fff Pagefile Backed Memory Readable True False False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable True False False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable True False False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable True False False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
pagefile_0x000000007efe0000 0x7efe0000 0x7f0dffff Pagefile Backed Memory Readable True False False
private_0x000000007f0e0000 0x7f0e0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True False False
private_0x000000007fff0000 0x7fff0000 0x7fffffeffff Private Memory Readable True False False
Process #24: sc.exe
(Host: 7, Network: 0)
+
Information Value
ID / OS PID #24 / 0x854
OS Parent PID 0xbe8 (c:\windows\syswow64\cmd.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\syswow64\sc.exe
Command Line sc config MpsSvc start= disabled
Monitor Start Time: 00:01:15, Reason: Child Process
Unmonitor End Time: 00:01:16, Reason: Terminated
Monitor Duration 00:00:01
OS Thread IDs
# 62
0x 848
# 63
0x 840
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000030000 0x00030000 0x00031fff Private Memory Readable, Writable True False False
private_0x0000000000030000 0x00030000 0x0003ffff Private Memory Readable, Writable True False False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000050000 0x00050000 0x00053fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000060000 0x00060000 0x00060fff Pagefile Backed Memory Readable True False False
private_0x0000000000080000 0x00080000 0x000bffff Private Memory Readable, Writable True False False
private_0x00000000000c0000 0x000c0000 0x000fffff Private Memory Readable, Writable True False False
private_0x0000000000160000 0x00160000 0x001dffff Private Memory Readable, Writable True False False
private_0x0000000000240000 0x00240000 0x0033ffff Private Memory Readable, Writable True False False
locale.nls 0x00340000 0x003a6fff Memory Mapped File Readable False False False
sc.exe 0x00910000 0x0091bfff Memory Mapped File Readable, Writable, Executable True False False
wow64win.dll 0x75090000 0x750ebfff Memory Mapped File Readable, Writable, Executable False False False
wow64.dll 0x750f0000 0x7512efff Memory Mapped File Readable, Writable, Executable False False False
wow64cpu.dll 0x75680000 0x75687fff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x756c0000 0x756cbfff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x756d0000 0x7572ffff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x75730000 0x7581ffff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x759e0000 0x75a25fff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76040000 0x760ebfff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76470000 0x7650ffff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x76530000 0x7663ffff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x77610000 0x77628fff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000077770000 0x77770000 0x77869fff Private Memory Readable, Writable, Executable True False False
private_0x0000000077870000 0x77870000 0x7798efff Private Memory Readable, Writable, Executable True False False
ntdll.dll 0x77990000 0x77b38fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77b70000 0x77ceffff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007efb0000 0x7efb0000 0x7efd2fff Pagefile Backed Memory Readable True False False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable True False False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable True False False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable True False False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
pagefile_0x000000007efe0000 0x7efe0000 0x7f0dffff Pagefile Backed Memory Readable True False False
private_0x000000007f0e0000 0x7f0e0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True False False
private_0x000000007fff0000 0x7fff0000 0x7fffffeffff Private Memory Readable True False False
Host Behavior
File (2)
+
Operation Filename Additional Information Success Count Logfile
OPEN STD_OUTPUT_HANDLE True 1
Fn
WRITE STD_OUTPUT_HANDLE size = 34 True 1
Fn
Data
Module (1)
+
Operation Module Additional Information Success Count Logfile
GET_HANDLE c:\windows\syswow64\sc.exe base_address = 0x910000 True 1
Fn
Service (4)
+
Operation Service Additional Information Success Count Logfile
OPEN_MGR SERVICES_ACTIVE_DATABASE host = Localhost, desired_access = SC_MANAGER_CONNECT True 1
Fn
OPEN MpsSvc database_name = SERVICES_ACTIVE_DATABASE, desired_access = SERVICE_QUERY_CONFIG, SERVICE_CHANGE_CONFIG True 1
Fn
GET_INFO MpsSvc type = SERVICE_CONFIG_DELAYED_AUTO_START_INFO True 1
Fn
SET_CONFIG MpsSvc new_service_type = SERVICE_NO_CHANGE, new_start_type = SERVICE_DISABLED True 1
Fn
Process #25: net1.exe
(Host: 18, Network: 0)
+
Information Value
ID / OS PID #25 / 0x83c
OS Parent PID 0x844 (c:\windows\syswow64\net.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\syswow64\net1.exe
Command Line C:\Windows\system32\net1 stop MpsSvc
Monitor Start Time: 00:01:16, Reason: Child Process
Unmonitor End Time: 00:01:31, Reason: Terminated
Monitor Duration 00:00:15
OS Thread IDs
# 64
0x 838
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000030000 0x00030000 0x00031fff Private Memory Readable, Writable True False False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000050000 0x00050000 0x00053fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000060000 0x00060000 0x00060fff Pagefile Backed Memory Readable True False False
locale.nls 0x00070000 0x000d6fff Memory Mapped File Readable False False False
private_0x0000000000120000 0x00120000 0x0012ffff Private Memory Readable, Writable True False False
private_0x0000000000130000 0x00130000 0x001affff Private Memory Readable, Writable True False False
private_0x0000000000240000 0x00240000 0x0027ffff Private Memory Readable, Writable True False False
private_0x00000000003e0000 0x003e0000 0x0045ffff Private Memory Readable, Writable True False False
private_0x00000000005c0000 0x005c0000 0x006bffff Private Memory Readable, Writable True False False
net1.exe 0x00770000 0x00799fff Memory Mapped File Readable, Writable, Executable True False False
netmsg.dll 0x67060000 0x67061fff Memory Mapped File Readable, Writable, Executable False False False
samlib.dll 0x67130000 0x67141fff Memory Mapped File Readable, Writable, Executable False False False
netapi32.dll 0x67150000 0x67160fff Memory Mapped File Readable, Writable, Executable False False False
logoncli.dll 0x67170000 0x67191fff Memory Mapped File Readable, Writable, Executable False False False
dsrole.dll 0x671a0000 0x671a8fff Memory Mapped File Readable, Writable, Executable False False False
wkscli.dll 0x671e0000 0x671eefff Memory Mapped File Readable, Writable, Executable False False False
samcli.dll 0x671f0000 0x671fefff Memory Mapped File Readable, Writable, Executable False False False
browcli.dll 0x67200000 0x6720cfff Memory Mapped File Readable, Writable, Executable False False False
netutils.dll 0x67210000 0x67218fff Memory Mapped File Readable, Writable, Executable False False False
srvcli.dll 0x68600000 0x68618fff Memory Mapped File Readable, Writable, Executable False False False
wow64win.dll 0x75090000 0x750ebfff Memory Mapped File Readable, Writable, Executable False False False
wow64.dll 0x750f0000 0x7512efff Memory Mapped File Readable, Writable, Executable False False False
ntdsapi.dll 0x754c0000 0x754d7fff Memory Mapped File Readable, Writable, Executable False False False
wow64cpu.dll 0x75680000 0x75687fff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x756c0000 0x756cbfff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x756d0000 0x7572ffff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x75730000 0x7581ffff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x759e0000 0x75a25fff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76040000 0x760ebfff Memory Mapped File Readable, Writable, Executable False False False
ws2_32.dll 0x763a0000 0x763d4fff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76470000 0x7650ffff Memory Mapped File Readable, Writable, Executable False False False
nsi.dll 0x76510000 0x76515fff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x76530000 0x7663ffff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x77610000 0x77628fff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000077770000 0x77770000 0x77869fff Private Memory Readable, Writable, Executable True False False
private_0x0000000077870000 0x77870000 0x7798efff Private Memory Readable, Writable, Executable True False False
ntdll.dll 0x77990000 0x77b38fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77b70000 0x77ceffff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007efb0000 0x7efb0000 0x7efd2fff Pagefile Backed Memory Readable True False False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable True False False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable True False False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable True False False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
pagefile_0x000000007efe0000 0x7efe0000 0x7f0dffff Pagefile Backed Memory Readable True False False
private_0x000000007f0e0000 0x7f0e0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True False False
private_0x000000007fff0000 0x7fff0000 0x7fffffeffff Private Memory Readable True False False
Host Behavior
File (7)
+
Operation Filename Additional Information Success Count Logfile
OPEN STD_OUTPUT_HANDLE True 1
Fn
OPEN STD_ERROR_HANDLE True 1
Fn
WRITE STD_OUTPUT_HANDLE size = 40 True 1
Fn
Data
WRITE STD_OUTPUT_HANDLE size = 1 True 1
Fn
Data
WRITE STD_OUTPUT_HANDLE size = 2 True 2
Fn
Data
WRITE STD_OUTPUT_HANDLE size = 56 True 1
Fn
Data
Module (3)
+
Operation Module Additional Information Success Count Logfile
LOAD NETMSG base_address = 0x67060000 True 1
Fn
GET_HANDLE c:\windows\syswow64\net1.exe base_address = 0x770000 True 1
Fn
GET_FILENAME C:\Windows\SysWOW64\net1.exe True 1
Fn
Service (7)
+
Operation Service Additional Information Success Count Logfile
OPEN_MGR SERVICES_ACTIVE_DATABASE host = Localhost, desired_access = GENERIC_READ True 1
Fn
OPEN MPSSVC database_name = SERVICES_ACTIVE_DATABASE, desired_access = SERVICE_QUERY_STATUS, SERVICE_ENUMERATE_DEPENDENTS True 1
Fn
GET_INFO MPSSVC type = Status True 1
Fn
GET_INFO MPSSVC type = DependentServices True 1
Fn
GET_DISPLAY_NAME SERVICES_ACTIVE_DATABASE service_name = MPSSVC, display_name_out = Windows Firewall True 2
Fn
GET_SERVICE_NAME SERVICES_ACTIVE_DATABASE display_name = MPSSVC, service_name_out = False 1
Fn
System (1)
+
Operation Information Success Count Logfile
SLEEP duration = 2500 milliseconds (2.500 seconds) True 1
Fn
Process #26: iexplore.exe
(Host: 17, Network: 1)
+
Information Value
ID / OS PID #26 / 0x834
OS Parent PID 0xbd8 (c:\windows\syswow64\explorer.exe)
Initial Working Directory C:\Windows\system32
File Name c:\program files (x86)\internet explorer\iexplore.exe
Command Line "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome
Monitor Start Time: 00:01:16, Reason: Child Process
Unmonitor End Time: 00:01:19, Reason: Terminated
Monitor Duration 00:00:03
OS Thread IDs
# 65
0x 830
# 66
0x 82C
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x00026fff Pagefile Backed Memory Readable True False False
private_0x0000000000030000 0x00030000 0x00031fff Private Memory Readable, Writable True False False
pagefile_0x0000000000030000 0x00030000 0x00031fff Pagefile Backed Memory Readable, Writable True False False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000050000 0x00050000 0x00053fff Pagefile Backed Memory Readable True False False
iexplore.exe.mui 0x00060000 0x00061fff Memory Mapped File Readable, Writable False False False
private_0x0000000000070000 0x00070000 0x00070fff Private Memory Readable, Writable True False False
private_0x0000000000080000 0x00080000 0x00080fff Private Memory Readable, Writable True False False
pagefile_0x0000000000090000 0x00090000 0x00093fff Pagefile Backed Memory Readable, Writable True False False
private_0x00000000000a0000 0x000a0000 0x000a3fff Private Memory Readable, Writable True False False
private_0x00000000000b0000 0x000b0000 0x000b3fff Private Memory Readable, Writable True False False
private_0x00000000000c0000 0x000c0000 0x000fffff Private Memory Readable, Writable True False False
locale.nls 0x00100000 0x00166fff Memory Mapped File Readable False False False
pagefile_0x0000000000170000 0x00170000 0x00184fff Pagefile Backed Memory Readable, Writable, Executable True False False
private_0x0000000000190000 0x00190000 0x00193fff Private Memory Readable, Writable True False False
private_0x00000000001a0000 0x001a0000 0x0029ffff Private Memory Readable, Writable True False False
private_0x00000000002a0000 0x002a0000 0x002a0fff Private Memory Readable, Writable True False False
private_0x00000000002b0000 0x002b0000 0x002b0fff Private Memory Readable, Writable True False False
private_0x00000000002c0000 0x002c0000 0x002c0fff Private Memory Readable, Writable True False False
private_0x0000000000300000 0x00300000 0x0037ffff Private Memory Readable, Writable True False False
private_0x00000000003e0000 0x003e0000 0x004dffff Private Memory Readable, Writable True False False
private_0x0000000000510000 0x00510000 0x0054ffff Private Memory Readable, Writable True False False
private_0x00000000005c0000 0x005c0000 0x005cffff Private Memory Readable, Writable True False False
private_0x00000000005f0000 0x005f0000 0x0062ffff Private Memory Readable, Writable True False False
private_0x0000000000630000 0x00630000 0x0063ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000640000 0x00640000 0x007c7fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000007d0000 0x007d0000 0x00950fff Pagefile Backed Memory Readable True False False
SortDefault.nls 0x00960000 0x00c2efff Memory Mapped File Readable False False False
iexplore.exe 0x00d30000 0x00dd5fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000d30000 0x00d30000 0x00dd5fff Pagefile Backed Memory Readable, Writable, Executable True False False
pagefile_0x0000000000de0000 0x00de0000 0x021dffff Pagefile Backed Memory Readable True False False
private_0x00000000022d0000 0x022d0000 0x0230ffff Private Memory Readable, Writable True False False
private_0x0000000002330000 0x02330000 0x0233ffff Private Memory Readable, Writable True False False
private_0x0000000002390000 0x02390000 0x023cffff Private Memory Readable, Writable True False False
private_0x0000000002420000 0x02420000 0x0251ffff Private Memory Readable, Writable True False False
winnsi.dll 0x671b0000 0x671b6fff Memory Mapped File Readable, Writable, Executable False False False
IPHLPAPI.DLL 0x671c0000 0x671dbfff Memory Mapped File Readable, Writable, Executable False False False
winrnr.dll 0x67290000 0x67297fff Memory Mapped File Readable, Writable, Executable False False False
dnsapi.dll 0x672a0000 0x672e3fff Memory Mapped File Readable, Writable, Executable False False False
pnrpnsp.dll 0x672f0000 0x67301fff Memory Mapped File Readable, Writable, Executable False False False
mpr.dll 0x67590000 0x675a1fff Memory Mapped File Readable, Writable, Executable False False False
NapiNSP.dll 0x675b0000 0x675bffff Memory Mapped File Readable, Writable, Executable False False False
WSHTCPIP.DLL 0x675c0000 0x675c4fff Memory Mapped File Readable, Writable, Executable False False False
mswsock.dll 0x675d0000 0x6760bfff Memory Mapped File Readable, Writable, Executable False False False
rasadhlp.dll 0x685f0000 0x685f5fff Memory Mapped File Readable, Writable, Executable False False False
nlaapi.dll 0x69410000 0x6941ffff Memory Mapped File Readable, Writable, Executable False False False
wow64win.dll 0x75090000 0x750ebfff Memory Mapped File Readable, Writable, Executable False False False
wow64.dll 0x750f0000 0x7512efff Memory Mapped File Readable, Writable, Executable False False False
wow64cpu.dll 0x75680000 0x75687fff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x756c0000 0x756cbfff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x756d0000 0x7572ffff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x75730000 0x7581ffff Memory Mapped File Readable, Writable, Executable False False False
ole32.dll 0x75880000 0x759dbfff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x759e0000 0x75a25fff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x75a30000 0x75accfff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x75b00000 0x75b09fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75b10000 0x75bdbfff Memory Mapped File Readable, Writable, Executable False False False
iertutil.dll 0x75be0000 0x75ddafff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x75e10000 0x75f0ffff Memory Mapped File Readable, Writable, Executable False False False
crypt32.dll 0x75f10000 0x7602cfff Memory Mapped File Readable, Writable, Executable False False False
msasn1.dll 0x76030000 0x7603bfff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76040000 0x760ebfff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x76220000 0x7627ffff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76280000 0x7630ffff Memory Mapped File Readable, Writable, Executable False False False
ws2_32.dll 0x763a0000 0x763d4fff Memory Mapped File Readable, Writable, Executable False False False
shlwapi.dll 0x76410000 0x76466fff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76470000 0x7650ffff Memory Mapped File Readable, Writable, Executable False False False
nsi.dll 0x76510000 0x76515fff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x76530000 0x7663ffff Memory Mapped File Readable, Writable, Executable False False False
wininet.dll 0x767e0000 0x768d4fff Memory Mapped File Readable, Writable, Executable False False False
oleaut32.dll 0x768e0000 0x7696efff Memory Mapped File Readable, Writable, Executable False False False
shell32.dll 0x76970000 0x775b9fff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x77610000 0x77628fff Memory Mapped File Readable, Writable, Executable False False False
urlmon.dll 0x77630000 0x77765fff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000077770000 0x77770000 0x77869fff Private Memory Readable, Writable, Executable True False False
private_0x0000000077870000 0x77870000 0x7798efff Private Memory Readable, Writable, Executable True False False
ntdll.dll 0x77990000 0x77b38fff Memory Mapped File Readable, Writable, Executable False False False
psapi.dll 0x77b40000 0x77b44fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77b70000 0x77ceffff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007efb0000 0x7efb0000 0x7efd2fff Pagefile Backed Memory Readable True False False
private_0x000000007efd8000 0x7efd8000 0x7efdafff Private Memory Readable, Writable True False False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable True False False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable True False False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable True False False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
pagefile_0x000000007efe0000 0x7efe0000 0x7f0dffff Pagefile Backed Memory Readable True False False
private_0x000000007f0e0000 0x7f0e0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True False False
private_0x000000007fff0000 0x7fff0000 0x7fffffeffff Private Memory Readable True False False
Injection Information
+
Injection Type Source Process Source Os Thread ID Injection Info Success Count Logfile
Modify Memory c:\windows\syswow64\explorer.exe 0xbdc address = 0xd30000, size = 679936 True 1
Fn
Data
Host Behavior
Process (3)
+
Operation Process Name Additional Information Success Count Logfile
CREATE vssadmin.exe delete shadows /all /quiet show_window = SW_HIDE True 1
Fn
CREATE bcdedit /set {default} recoveryenabled no show_window = SW_HIDE False 1
Fn
CREATE bcdedit /set {default} bootstatuspolicy ignoreallfailures show_window = SW_HIDE False 1
Fn
Module (14)
+
Operation Module Additional Information Success Count Logfile
LOAD advapi32.dll base_address = 0x76470000 True 1
Fn
LOAD shell32.dll base_address = 0x76970000 True 1
Fn
LOAD user32.dll base_address = 0x75e10000 True 1
Fn
LOAD urlmon.dll base_address = 0x77630000 True 1
Fn
LOAD wininet.dll base_address = 0x767e0000 True 1
Fn
LOAD crypt32.dll base_address = 0x75f10000 True 1
Fn
LOAD mpr.dll base_address = 0x67590000 True 1
Fn
LOAD ole32.dll base_address = 0x75880000 True 1
Fn
LOAD ws2_32.dll base_address = 0x763a0000 True 1
Fn
LOAD psapi.dll base_address = 0x77b40000 True 1
Fn
CREATE_MAPPING module_name = Nameless FileMapping, maximum_size = 86016, protection = PAGE_EXECUTE_READWRITE, SEC_COMMIT True 1
Fn
MAP c:\program files (x86)\internet explorer\iexplore.exe os_pid = 0x834, desired_access = FILE_MAP_WRITE, FILE_MAP_READ, file_offset = 0, address = 0x90000 True 1
Fn
MAP c:\program files (x86)\internet explorer\iexplore.exe os_pid = 0x834, module_name = Nameless FileMapping, desired_access = FILE_MAP_ALL_ACCESS, file_offset = 0, address = 0x170000 True 1
Fn
GET_FILENAME C:\Program Files (x86)\Internet Explorer\iexplore.exe True 1
Fn
Network Behavior
DNS (1)
+
Operation Host Additional Information Success Count Logfile
RESOLVE_NAME foandrenla.com False 1
Fn
Process #27: vssadmin.exe
+
Information Value
ID / OS PID #27 / 0x828
OS Parent PID 0x834 (c:\program files (x86)\internet explorer\iexplore.exe)
Initial Working Directory C:\Windows\system32
File Name c:\windows\syswow64\vssadmin.exe
Command Line vssadmin.exe delete shadows /all /quiet
Monitor Start Time: 00:01:19, Reason: Child Process
Unmonitor End Time: 00:01:22, Reason: Terminated
Monitor Duration 00:00:03
OS Thread IDs
# 67
0x 5D8
# 68
0x 68C
# 69
0x 274
# 70
0x 6B8
# 71
0x 8AC
Remarks No high level activity detected in monitored regions
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000030000 0x00030000 0x00031fff Private Memory Readable, Writable True False False
pagefile_0x0000000000030000 0x00030000 0x00036fff Pagefile Backed Memory Readable True False False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000050000 0x00050000 0x00053fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000060000 0x00060000 0x00060fff Pagefile Backed Memory Readable True False False
locale.nls 0x00070000 0x000d6fff Memory Mapped File Readable False False False
pagefile_0x00000000000e0000 0x000e0000 0x000e1fff Pagefile Backed Memory Readable, Writable True False False
vssadmin.exe.mui 0x000f0000 0x000fcfff Memory Mapped File Readable, Writable False False False
private_0x0000000000100000 0x00100000 0x0013ffff Private Memory Readable, Writable True False False
private_0x0000000000140000 0x00140000 0x00140fff Private Memory Readable, Writable True False False
private_0x0000000000150000 0x00150000 0x00150fff Private Memory Readable, Writable True False False
private_0x0000000000160000 0x00160000 0x0019ffff Private Memory Readable, Writable True False False
pagefile_0x00000000001a0000 0x001a0000 0x001a0fff Pagefile Backed Memory Readable True False False
private_0x00000000001b0000 0x001b0000 0x001effff Private Memory Readable, Writable True False False
pagefile_0x00000000001f0000 0x001f0000 0x001f0fff Pagefile Backed Memory Readable True False False
private_0x0000000000220000 0x00220000 0x0025ffff Private Memory Readable, Writable True False False
private_0x0000000000290000 0x00290000 0x0030ffff Private Memory Readable, Writable True False False
private_0x00000000003b0000 0x003b0000 0x004affff Private Memory Readable, Writable True False False
private_0x0000000000560000 0x00560000 0x0056ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000570000 0x00570000 0x006f7fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000700000 0x00700000 0x00880fff Pagefile Backed Memory Readable True False False
private_0x00000000008c0000 0x008c0000 0x008fffff Private Memory Readable, Writable True False False
private_0x0000000000940000 0x00940000 0x0097ffff Private Memory Readable, Writable True False False
SortDefault.nls 0x00980000 0x00c4efff Memory Mapped File Readable False False False
vssadmin.exe 0x00d50000 0x00d6efff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000d70000 0x00d70000 0x0216ffff Pagefile Backed Memory Readable True False False
vssapi.dll 0x67010000 0x67125fff Memory Mapped File Readable, Writable, Executable False False False
atl.dll 0x675f0000 0x67603fff Memory Mapped File Readable, Writable, Executable False False False
vsstrace.dll 0x685f0000 0x685fffff Memory Mapped File Readable, Writable, Executable False False False
RpcRtRemote.dll 0x693a0000 0x693adfff Memory Mapped File Readable, Writable, Executable False False False
rsaenh.dll 0x693b0000 0x693eafff Memory Mapped File Readable, Writable, Executable False False False
cryptsp.dll 0x693f0000 0x69405fff Memory Mapped File Readable, Writable, Executable False False False
wow64win.dll 0x75090000 0x750ebfff Memory Mapped File Readable, Writable, Executable False False False
wow64.dll 0x750f0000 0x7512efff Memory Mapped File Readable, Writable, Executable False False False
wow64cpu.dll 0x75680000 0x75687fff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x756c0000 0x756cbfff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x756d0000 0x7572ffff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x75730000 0x7581ffff Memory Mapped File Readable, Writable, Executable False False False
ole32.dll 0x75880000 0x759dbfff Memory Mapped File Readable, Writable, Executable False False False
KernelBase.dll 0x759e0000 0x75a25fff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x75a30000 0x75accfff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x75b00000 0x75b09fff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75b10000 0x75bdbfff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x75e10000 0x75f0ffff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x76040000 0x760ebfff Memory Mapped File Readable, Writable, Executable False False False
clbcatq.dll 0x760f0000 0x76172fff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x76220000 0x7627ffff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x76280000 0x7630ffff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x76470000 0x7650ffff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x76530000 0x7663ffff Memory Mapped File Readable, Writable, Executable False False False
oleaut32.dll 0x768e0000 0x7696efff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x77610000 0x77628fff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000077770000 0x77770000 0x77869fff Private Memory Readable, Writable, Executable True False False
private_0x0000000077870000 0x77870000 0x7798efff Private Memory Readable, Writable, Executable True False False
ntdll.dll 0x77990000 0x77b38fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77b70000 0x77ceffff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007efb0000 0x7efb0000 0x7efd2fff Pagefile Backed Memory Readable True False False
private_0x000000007efd5000 0x7efd5000 0x7efd7fff Private Memory Readable, Writable True False False
private_0x000000007efd8000 0x7efd8000 0x7efdafff Private Memory Readable, Writable True False False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable True False False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable True False False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable True False False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
pagefile_0x000000007efe0000 0x7efe0000 0x7f0dffff Pagefile Backed Memory Readable True False False
private_0x000000007f0e0000 0x7f0e0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True False False
private_0x000000007fff0000 0x7fff0000 0x7fffffeffff Private Memory Readable True False False
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefox with deactivated setting "security.fileuri.strict_origin_policy".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image