ADInsightDll64.dll is part of admondll and developed by Sysinternals - www.sysinternals.com according to the ADInsightDll64.dll version information.
ADInsightDll64.dll's description is "Insight for Active Directory monitoring DLL"
ADInsightDll64.dll is digitally signed by Microsoft Corporation.
ADInsightDll64.dll is usually located in the 'C:\Users\ADMINI~1\AppData\Local\Temp\' folder.
None of the anti-virus scanners at VirusTotal reports anything malicious about ADInsightDll64.dll.
If you have additional information about the file, please share it with the FreeFixer users by posting a comment at the bottom of this page.
The following is the available information on ADInsightDll64.dll:
| Property | Value |
|---|---|
| Product name | admondll |
| Company name | Sysinternals - www.sysinternals.com |
| File description | Insight for Active Directory monitoring DLL |
| Internal name | admondll |
| Original filename | admondll |
| Legal copyright | Copyright (C) 2007-2015 Mark Russinovich |
| Product version | 1.20.0.0 |
| File version | 1.20.0.0 |
Here's a screenshot of the file properties when displayed by Windows Explorer:
| Product name | admondll |
| Company name | Sysinternals - www.sysinternals.com |
| File description | Insight for Active Directory monitor.. |
| Internal name | admondll |
| Original filename | admondll |
| Legal copyright | Copyright (C) 2007-2015 Mark Russino.. |
| Product version | 1.20.0.0 |
| File version | 1.20.0.0 |
ADInsightDll64.dll has a valid digital signature.
| Property | Value |
|---|---|
| Signer name | Microsoft Corporation |
| Certificate issuer name | Microsoft Code Signing PCA |
| Certificate serial number | 330000010a2c79aed7797ba6ac00010000010a |
None of the 72 anti-virus programs at VirusTotal detected the ADInsightDll64.dll file.
The following information was gathered by executing the file inside Cuckoo Sandbox.
Successfully executed process in sandbox.
{
"dll_loaded": [
"kernel32.dll",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\4135b4bdef074e9f5af1cef45de552b3cde66f24ec25f62660be616842005b15.bin.dll"
],
"file_opened": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\4135b4bdef074e9f5af1cef45de552b3cde66f24ec25f62660be616842005b15.bin.dll",
"C:\\Windows\\Globalization\\Sorting\\sortdefault.nls"
],
"command_line": [
"\"C:\\Windows\\System32\\rundll32.exe\" C:\\Users\\cuck\\AppData\\Local\\Temp\\4135b4bdef074e9f5af1cef45de552b3cde66f24ec25f62660be616842005b15.bin.dll,DllMain"
],
"file_exists": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\4135b4bdef074e9f5af1cef45de552b3cde66f24ec25f62660be616842005b15.bin.dll.manifest",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\4135b4bdef074e9f5af1cef45de552b3cde66f24ec25f62660be616842005b15.bin.dll"
],
"file_read": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\4135b4bdef074e9f5af1cef45de552b3cde66f24ec25f62660be616842005b15.bin.dll"
],
"regkey_read": [
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US"
]
}[
{
"process_path": "C:\\Windows\\System32\\rundll32.exe",
"process_name": "rundll32.exe",
"pid": 2968,
"summary": {
"file_opened": [
"C:\\Windows\\Globalization\\Sorting\\sortdefault.nls"
],
"file_exists": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\4135b4bdef074e9f5af1cef45de552b3cde66f24ec25f62660be616842005b15.bin.dll.manifest",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\4135b4bdef074e9f5af1cef45de552b3cde66f24ec25f62660be616842005b15.bin.dll"
],
"regkey_read": [
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US"
],
"dll_loaded": [
"kernel32.dll",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\4135b4bdef074e9f5af1cef45de552b3cde66f24ec25f62660be616842005b15.bin.dll"
]
},
"first_seen": 1594630386.828125,
"ppid": 2816
},
{
"process_path": "C:\\Windows\\SysWOW64\\rundll32.exe",
"process_name": "rundll32.exe",
"pid": 2816,
"summary": {
"dll_loaded": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\4135b4bdef074e9f5af1cef45de552b3cde66f24ec25f62660be616842005b15.bin.dll"
],
"file_opened": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\4135b4bdef074e9f5af1cef45de552b3cde66f24ec25f62660be616842005b15.bin.dll"
],
"command_line": [
"\"C:\\Windows\\System32\\rundll32.exe\" C:\\Users\\cuck\\AppData\\Local\\Temp\\4135b4bdef074e9f5af1cef45de552b3cde66f24ec25f62660be616842005b15.bin.dll,DllMain"
],
"file_exists": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\4135b4bdef074e9f5af1cef45de552b3cde66f24ec25f62660be616842005b15.bin.dll.manifest",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\4135b4bdef074e9f5af1cef45de552b3cde66f24ec25f62660be616842005b15.bin.dll"
],
"file_read": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\4135b4bdef074e9f5af1cef45de552b3cde66f24ec25f62660be616842005b15.bin.dll"
],
"regkey_read": [
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles"
]
},
"first_seen": 1594630386.65625,
"ppid": 2016
},
{
"process_path": "C:\\Windows\\System32\\lsass.exe",
"process_name": "lsass.exe",
"pid": 476,
"summary": {},
"first_seen": 1594630386.34375,
"ppid": 376
}
][
{
"markcount": 1,
"families": [],
"description": "This executable has a PDB path",
"severity": 1,
"marks": [
{
"category": "pdb_path",
"ioc": "C:\\Builds\\13810\\Tools\\ADInsight_master\\bin\\x64\\Release\\ADInsightDLL6464.pdb",
"type": "ioc",
"description": null
}
],
"references": [],
"name": "has_pdb"
},
{
"markcount": 1,
"families": [],
"description": "The executable contains unknown PE section names indicative of a packer (could be a false positive)",
"severity": 1,
"marks": [
{
"category": "section",
"ioc": "Shared",
"type": "ioc",
"description": null
}
],
"references": [],
"name": "pe_features"
},
{
"markcount": 1,
"families": [],
"description": "One or more processes crashed",
"severity": 1,
"marks": [
{
"call": {
"category": "__notification__",
"status": 1,
"stacktrace": [],
"raw": [
"stacktrace"
],
"api": "__exception__",
"return_value": 0,
"arguments": {
"stacktrace": "0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf\n\n\n0\nx\n7\nf\ne\nf\n0\na\nf\n6\n1\n5\nf",
"registers": {
"r14": 4284416000,
"r9": 2290288,
"rcx": 48,
"rsi": 0,
"r10": 0,
"rbx": 3776144,
"rdi": 8791541088256,
"r11": 518,
"r8": 2290216,
"rdx": 8796092883536,
"rbp": 8791541088256,
"r15": 2292992,
"r12": 0,
"rsp": 2291056,
"rax": 1,
"r13": 3776356
},
"exception": {
"symbol": "",
"exception_code": "0xc0000005",
"address": "0x7fef0af615f"
}
},
"time": 1594630391.937125,
"tid": 2588,
"flags": {}
},
"pid": 2968,
"type": "call",
"cid": 4105
}
],
"references": [],
"name": "raises_exception"
},
{
"markcount": 40,
"families": [],
"description": "Allocates read-write-execute memory (usually to unpack itself)",
"severity": 2,
"marks": [
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2968,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffffffffffff",
"base_address": "0x000007feff542000"
},
"time": 1594630386.968125,
"tid": 2588,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2968,
"type": "call",
"cid": 82
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2968,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffffffffffff",
"base_address": "0x000007fefdcd1000"
},
"time": 1594630386.968125,
"tid": 2588,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2968,
"type": "call",
"cid": 86
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2968,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffffffffffff",
"base_address": "0x000007feff35a000"
},
"time": 1594630386.968125,
"tid": 2588,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2968,
"type": "call",
"cid": 90
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2968,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffffffffffff",
"base_address": "0x000007feff2e6000"
},
"time": 1594630386.984125,
"tid": 2588,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2968,
"type": "call",
"cid": 100
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2968,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffffffffffff",
"base_address": "0x0000000077932000"
},
"time": 1594630386.984125,
"tid": 2588,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2968,
"type": "call",
"cid": 113
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2968,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffffffffffff",
"base_address": "0x000007feff542000"
},
"time": 1594630386.984125,
"tid": 2588,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2968,
"type": "call",
"cid": 116
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2968,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffffffffffff",
"base_address": "0x000007feffc2d000"
},
"time": 1594630386.984125,
"tid": 2588,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2968,
"type": "call",
"cid": 123
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2968,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffffffffffff",
"base_address": "0x000007fefdee1000"
},
"time": 1594630386.984125,
"tid": 2588,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2968,
"type": "call",
"cid": 126
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2968,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffffffffffff",
"base_address": "0x000007feff2e6000"
},
"time": 1594630386.999125,
"tid": 2588,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2968,
"type": "call",
"cid": 134
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2968,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffffffffffff",
"base_address": "0x00000000ff5f1000"
},
"time": 1594630386.999125,
"tid": 2588,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2968,
"type": "call",
"cid": 143
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2968,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffffffffffff",
"base_address": "0x0000000077932000"
},
"time": 1594630386.999125,
"tid": 2588,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2968,
"type": "call",
"cid": 149
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2968,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffffffffffff",
"base_address": "0x000007fefdcd1000"
},
"time": 1594630386.999125,
"tid": 2588,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2968,
"type": "call",
"cid": 154
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2968,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffffffffffff",
"base_address": "0x000007fefdee1000"
},
"time": 1594630386.999125,
"tid": 2588,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2968,
"type": "call",
"cid": 160
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2968,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffffffffffff",
"base_address": "0x000007fefd734000"
},
"time": 1594630386.999125,
"tid": 2588,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2968,
"type": "call",
"cid": 165
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2968,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffffffffffff",
"base_address": "0x000007feff2e7000"
},
"time": 1594630386.999125,
"tid": 2588,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2968,
"type": "call",
"cid": 170
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2968,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffffffffffff",
"base_address": "0x00000000ff5f1000"
},
"time": 1594630387.015125,
"tid": 2588,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2968,
"type": "call",
"cid": 179
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2968,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffffffffffff",
"base_address": "0x0000000077932000"
},
"time": 1594630387.015125,
"tid": 2588,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2968,
"type": "call",
"cid": 185
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2968,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffffffffffff",
"base_address": "0x000007feff542000"
},
"time": 1594630387.015125,
"tid": 2588,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2968,
"type": "call",
"cid": 188
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2968,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffffffffffff",
"base_address": "0x000007fefdee1000"
},
"time": 1594630387.015125,
"tid": 2588,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2968,
"type": "call",
"cid": 196
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2968,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffffffffffff",
"base_address": "0x000007feff2e6000"
},
"time": 1594630387.015125,
"tid": 2588,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2968,
"type": "call",
"cid": 204
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2968,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffffffffffff",
"base_address": "0x00000000ff5f1000"
},
"time": 1594630387.015125,
"tid": 2588,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2968,
"type": "call",
"cid": 213
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2968,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffffffffffff",
"base_address": "0x0000000077932000"
},
"time": 1594630387.015125,
"tid": 2588,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2968,
"type": "call",
"cid": 219
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2968,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffffffffffff",
"base_address": "0x000007feff542000"
},
"time": 1594630387.031125,
"tid": 2588,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2968,
"type": "call",
"cid": 222
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2968,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffffffffffff",
"base_address": "0x000007fefdcd1000"
},
"time": 1594630387.031125,
"tid": 2588,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2968,
"type": "call",
"cid": 226
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2968,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffffffffffff",
"base_address": "0x000007feffc2d000"
},
"time": 1594630387.031125,
"tid": 2588,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2968,
"type": "call",
"cid": 231
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2968,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffffffffffff",
"base_address": "0x000007fefdee1000"
},
"time": 1594630387.031125,
"tid": 2588,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2968,
"type": "call",
"cid": 234
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2968,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffffffffffff",
"base_address": "0x000007fefd734000"
},
"time": 1594630387.031125,
"tid": 2588,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2968,
"type": "call",
"cid": 239
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2968,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffffffffffff",
"base_address": "0x000007feff2e6000"
},
"time": 1594630387.031125,
"tid": 2588,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2968,
"type": "call",
"cid": 244
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2968,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffffffffffff",
"base_address": "0x000007feff2e6000"
},
"time": 1594630387.046125,
"tid": 2588,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2968,
"type": "call",
"cid": 270
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2968,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffffffffffff",
"base_address": "0x00000000ff5f1000"
},
"time": 1594630387.046125,
"tid": 2588,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2968,
"type": "call",
"cid": 279
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2968,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffffffffffff",
"base_address": "0x0000000077932000"
},
"time": 1594630387.046125,
"tid": 2588,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2968,
"type": "call",
"cid": 285
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2968,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffffffffffff",
"base_address": "0x000007feff542000"
},
"time": 1594630387.046125,
"tid": 2588,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2968,
"type": "call",
"cid": 288
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2968,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffffffffffff",
"base_address": "0x000007fefdcd1000"
},
"time": 1594630387.046125,
"tid": 2588,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2968,
"type": "call",
"cid": 292
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2968,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffffffffffff",
"base_address": "0x000007feffc2d000"
},
"time": 1594630387.046125,
"tid": 2588,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2968,
"type": "call",
"cid": 297
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2968,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffffffffffff",
"base_address": "0x000007fefdee1000"
},
"time": 1594630387.046125,
"tid": 2588,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2968,
"type": "call",
"cid": 300
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2968,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffffffffffff",
"base_address": "0x000007fefd734000"
},
"time": 1594630387.046125,
"tid": 2588,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2968,
"type": "call",
"cid": 305
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2968,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffffffffffff",
"base_address": "0x000007feff2e6000"
},
"time": 1594630387.062125,
"tid": 2588,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2968,
"type": "call",
"cid": 310
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2968,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffffffffffff",
"base_address": "0x00000000ff5f1000"
},
"time": 1594630387.062125,
"tid": 2588,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2968,
"type": "call",
"cid": 319
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2968,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffffffffffff",
"base_address": "0x0000000077932000"
},
"time": 1594630387.062125,
"tid": 2588,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2968,
"type": "call",
"cid": 325
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2968,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffffffffffff",
"base_address": "0x000007fefdee1000"
},
"time": 1594630387.062125,
"tid": 2588,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2968,
"type": "call",
"cid": 334
}
],
"references": [],
"name": "allocates_rwx"
}
]The Yara rules did not detect anything in the file.
{
"tls": [],
"udp": [
{
"src": "192.168.56.101",
"dst": "192.168.56.255",
"offset": 662,
"time": 6.164500951766968,
"dport": 137,
"sport": 137
},
{
"src": "192.168.56.101",
"dst": "192.168.56.255",
"offset": 5990,
"time": 12.29592514038086,
"dport": 138,
"sport": 138
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 7834,
"time": 6.087747097015381,
"dport": 5355,
"sport": 51001
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 8162,
"time": 4.138642072677612,
"dport": 5355,
"sport": 53595
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 8490,
"time": 6.140136957168579,
"dport": 5355,
"sport": 53848
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 8818,
"time": 4.643718004226685,
"dport": 5355,
"sport": 54255
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 9146,
"time": 2.977504014968872,
"dport": 5355,
"sport": 55314
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 9474,
"time": 13.43379807472229,
"dport": 5355,
"sport": 55880
},
{
"src": "192.168.56.101",
"dst": "239.255.255.250",
"offset": 9794,
"time": 4.6553590297698975,
"dport": 1900,
"sport": 1900
},
{
"src": "192.168.56.101",
"dst": "239.255.255.250",
"offset": 29204,
"time": 4.1596519947052,
"dport": 3702,
"sport": 49152
},
{
"src": "192.168.56.101",
"dst": "239.255.255.250",
"offset": 37588,
"time": 6.219583034515381,
"dport": 1900,
"sport": 53598
}
],
"dns_servers": [],
"http": [],
"icmp": [],
"smtp": [],
"tcp": [],
"smtp_ex": [],
"mitm": [],
"hosts": [],
"pcap_sha256": "32828191281f1f9b2f40f4ee89a66e40f443416c569ce47a22f38282d69d9080",
"dns": [],
"http_ex": [],
"domains": [],
"dead_hosts": [],
"sorted_pcap_sha256": "2a7e5de3d808dbbb46166d466a5184f4928a2c6013fa578917c15e6aee12a6f9",
"irc": [],
"https_ex": []
}





| Property | Value |
|---|---|
| MD5 | cfaf65598254ef8d1d027f77eb8f94ee |
| SHA256 | 4135b4bdef074e9f5af1cef45de552b3cde66f24ec25f62660be616842005b15 |
To help other users, please let us know what you will do with the file:
The poll result listed below shows what users chose to do with the file. 100% have voted for removal. Based on votes from 1 user.
| Votes | |||
|---|---|---|---|
| Keep | 0 % | 0 | |
| Remove | 100 % | 1 |
NOTE: Please do not use this poll as the only source of input to determine what you will do with the file. Only 1 user has voted so far so it does not offer a high degree of confidence.
If you feel that you need more information to determine if your should keep this file or remove it, please read this guide.
Hi, my name is Roger Karlsson. I've been running this website since 2006. I want to let you know about the FreeFixer program. FreeFixer is a freeware tool that analyzes your system and let you manually identify unwanted programs. Once you've identified some malware files, FreeFixer is pretty good at removing them. You can download FreeFixer here. It runs on Windows 2000/XP/2003/2008/2016/2019/Vista/7/8/8.1/10. Supports both 32- and 64-bit Windows.
If you have questions, feedback on FreeFixer or the freefixer.com website, need help analyzing FreeFixer's scan result or just want to say hello, please contact me. You can find my email address at the contact page.
Please share with the other users what you think about this file. What does this file do? Is it legitimate or something that your computer is better without? Do you know how it was installed on your system? Did you install it yourself or did it come bundled with some other software? Is it running smoothly or do you get some error message? Any information that will help to document this file is welcome. Thank you for your contributions.
I'm reading all new comments so don't hesitate to post a question about the file. If I don't have the answer perhaps another user can help you.
No comments posted yet.