WriteProcessMemory
Aug. 12, 2024, 8:51 a.m.
buffer:
MZ ÿÿ ¸ @ º ´ Í!¸LÍ!This program cannot be run in DOS mode.
$ PE L ±!c à Æ o @ 7 @ @ 0¢ P p Ì ¡ p .text F} ~ `.itext i `.rdata ² @ @.data È ° @ À.pdata e ` . @ À.reloc Ì p : @ B
base_address:
0x001c0000
process_identifier:
2608
process_handle:
0x0000010c
1
1
0
WriteProcessMemory
Aug. 12, 2024, 8:51 a.m.
buffer:
à UìSVWu}» ÈÁÈ
Ð÷ÒÁÀÈ3«ÁÀ ÈÐ÷Ò«ÁÀÈ3ÂÐ÷Ò«ÁÀ3«wðK
ÛuÇ_^[] @ UìSVW¸üýþÿ¹@ ]Dü-Iuô}¾@ 3ÛUmÁ3Ò÷öÁT Ó\ T T T Aù uÖ]3É}¾ UmÁ3Ò÷öÁT Ó\ T T T Aù uÖ]3É}¾@ UmÁ3Ò÷öÁT Ó\ T T T Aù uÖ]Ã_^[] UìSVW3À]3É3Òu}
öt3UmT
Ó\ T T þÂD 0T T
T þÁGN
öuÒ]_^[]Â fff èûÿÿff è
ÏþÿfD èÆÿÿff èßÿÿf j ÿÈUB D èdøÿÿèeøÿÿèHøÿÿèIøÿÿèbøÿÿèWøÿÿè@øÿÿèYøÿÿèBøÿÿè=øÿÿè øÿÿèñ÷ÿÿè
øÿÿèí÷ÿÿè øÿÿèøÿÿèä÷ÿÿè÷÷ÿÿèæ÷ÿÿèÛ÷ÿÿèâ÷ÿÿè3ãÿÿè@ãÿÿèMãÿÿè*ãÿÿè7ãÿÿè,ãÿÿèEãÿÿè
ãÿÿè5ãÿÿè$ãÿÿèãÿÿèãÿÿèãÿÿ
base_address:
0x001d9000
process_identifier:
2608
process_handle:
0x0000010c
1
1
0
WriteProcessMemory
Aug. 12, 2024, 8:51 a.m.
buffer:
\¤ ¤ ~¤ l¤ ¤ F¤ 4¤ "¤ ü£ î£ £ ¦£ ¸£ Ê£ Ø£ z£ >£ j£ Z£ J£ ð¢ .£ £ £ ú¢ ±!c
ô <¡ < ì| .text ì Z .text$mn i .itext p .idata$5 p Ì .rdata <¡ ô .rdata$zzzdbg 0¢ <