digital-forensics-ram/malfind-image1.txt

46 lines
1.5 KiB
Plaintext

Volatility 3 Framework 1.0.1
PID Process Start VPN End VPN Tag Protection CommitCharge PrivateMemory File output Hexdump Disasm
3708 svchost.exe 0x400000 0x404fff VadS PAGE_EXECUTE_READWRITE 5 1 Disabled
00 00 00 00 00 00 00 00 ........
00 00 00 00 00 00 00 00 ........
00 00 00 00 00 00 00 00 ........
00 00 00 00 00 00 00 00 ........
00 00 00 00 00 00 00 00 ........
00 00 00 00 00 00 00 00 ........
00 00 00 00 00 00 00 00 ........
00 00 00 00 00 00 00 00 ........
0x400000: add byte ptr [eax], al
0x400002: add byte ptr [eax], al
0x400004: add byte ptr [eax], al
0x400006: add byte ptr [eax], al
0x400008: add byte ptr [eax], al
0x40000a: add byte ptr [eax], al
0x40000c: add byte ptr [eax], al
0x40000e: add byte ptr [eax], al
0x400010: add byte ptr [eax], al
0x400012: add byte ptr [eax], al
0x400014: add byte ptr [eax], al
0x400016: add byte ptr [eax], al
0x400018: add byte ptr [eax], al
0x40001a: add byte ptr [eax], al
0x40001c: add byte ptr [eax], al
0x40001e: add byte ptr [eax], al
0x400020: add byte ptr [eax], al
0x400022: add byte ptr [eax], al
0x400024: add byte ptr [eax], al
0x400026: add byte ptr [eax], al
0x400028: add byte ptr [eax], al
0x40002a: add byte ptr [eax], al
0x40002c: add byte ptr [eax], al
0x40002e: add byte ptr [eax], al
0x400030: add byte ptr [eax], al
0x400032: add byte ptr [eax], al
0x400034: add byte ptr [eax], al
0x400036: add byte ptr [eax], al
0x400038: add byte ptr [eax], al
0x40003a: add byte ptr [eax], al
0x40003c: add byte ptr [eax], al
0x40003e: add byte ptr [eax], al