Program did not start
MALICIOUS | SUSPICIOUS | INFO |
---|---|---|
Uses SVCHOST.EXE for hidden code execution
|
Executable content was dropped or overwritten
|
Changes internet zones settings
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
---|---|---|---|---|---|
CODE | 0x00001000 | 0x00006CB8 | 0x00006E00 | IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ | 6.51771 |
DATA | 0x00008000 | 0x00000830 | 0x00000A00 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE | 4.21269 |
BSS | 0x00009000 | 0x00000A75 | 0x00000000 | IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE | 0 |
.idata | 0x0000A000 | 0x0000087C | 0x00000A00 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE | 4.11254 |
.tls | 0x0000B000 | 0x00000008 | 0x00000000 | IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE | 0 |
.rdata | 0x0000C000 | 0x00000018 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_SHARED | 0.204488 |
.reloc | 0x0000D000 | 0x00000754 | 0x00000800 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_SHARED | 6.41981 |
.rsrc | 0x0000E000 | 0x0000102C | 0x00001200 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_SHARED | 4.38169 |
No exports.
Click at the process to see the details.
Image |
---|
c:\users\admin\desktop\netbull.exe |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\oleaut32.dll |
c:\windows\system32\ole32.dll |
c:\windows\system32\shell32.dll |
c:\windows\system32\shlwapi.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\sspicli.dll |
c:\windows\system32\cryptbase.dll |
c:\windows\system32\clbcatq.dll |
c:\windows\system32\apphelp.dll |
Image |
---|
c:\windows\system32\svchost.exe |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\crypt32.dll |
c:\windows\system32\msasn1.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\ole32 |