IOC Report
photo-ai.exe

loading gif

Files

File Path
Type
Category
Malicious
photo-ai.exe
PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
initial sample
C:\Users\user\AppData\Local\Temp\hitpawphotoai_hitpawnet\galog.json
JSON data
dropped
C:\Users\user\AppData\Local\Temp\hitpawphotoai_hitpawnet\hitpawphotoai_hitpawnet_20240424093959189.log
ASCII text, with CRLF line terminators
dropped
C:\Users\user\Desktop\cloud
Netscape cookie, ASCII text, with CRLF line terminators
dropped
C:\Users\user\Desktop\cloud.0cb4b46f.tmp
Netscape cookie, ASCII text, with CRLF line terminators
dropped
C:\Users\user\Desktop\cloud.16976361.tmp
Netscape cookie, ASCII text, with CRLF line terminators
dropped
C:\Users\user\Desktop\cloud.251da255.tmp
Netscape cookie, ASCII text, with CRLF line terminators
dropped
C:\Users\user\Desktop\cloud.64b7edbe.tmp
Netscape cookie, ASCII text, with CRLF line terminators
dropped
C:\Users\user\Desktop\cloud.673af80e.tmp
Netscape cookie, ASCII text, with CRLF line terminators
dropped
C:\Users\user\Desktop\cloud.6c70947c.tmp
Netscape cookie, ASCII text, with CRLF line terminators
dropped
C:\Users\user\Desktop\cloud.9641442a.tmp
Netscape cookie, ASCII text, with CRLF line terminators
dropped
C:\Users\user\Desktop\cloud.b1cd87e1.tmp
Netscape cookie, ASCII text, with CRLF line terminators
dropped
C:\Users\user\Desktop\cloud.d4d21360.tmp
Netscape cookie, ASCII text, with CRLF line terminators
dropped
C:\Users\user\Desktop\cloud.e0b37c8c.tmp
Netscape cookie, ASCII text, with CRLF line terminators
dropped
There are 4 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Windows\SysWOW64\wbem\WMIC.exe
wmic BaseBoard get SerialNumber
malicious
C:\Windows\SysWOW64\wbem\WMIC.exe
wmic logicaldisk where DeviceID='C:' get VolumeSerialNumber
malicious
C:\Users\user\Desktop\photo-ai.exe
"C:\Users\user\Desktop\photo-ai.exe"
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\cmd.exe /C sc start winmgmt
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\sc.exe
sc start winmgmt
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

URLs

Name
IP
Malicious
http://192.168.40.249:56215/synct4(t4:curl
unknown
https://www.tenorshare.com/www.tenorshare.come
unknown
https://analytics.afirstsoft.cn/collect
unknown
http://crl.microsoft
unknown
https://download.hitpaw.
unknown
https://www.tenorshare.com/downloads/service/softwarelog.txt
unknown
https://update.tenorshare.cn/download/checkCross?cross_end_id=%s
unknown
https://download.hitpaw.net/downloads/extra/hitpawphotoai_hitpawnet.exe
unknown
https://curl.se/docs/hsts.html
unknown
https://www.runoob.com/python/att-string-replace.html
unknown
https://integrated.tenorshare.com/api/v1/ticket/feedback&subject=&version=&log_id=&content=&useremai
unknown
https://www.runoob.com/matplotlib/matplotlib-tutorial.html
unknown
https://check.mobie.app6
unknown
http://update.tenorshare.com/queryDownloader?LanguageId=%d&SoftWareID=%d&SiteID=%d%scn
unknown
https://download.hitpaw.net/download
unknown
https://www.baidu.com):t1(t1:curl
unknown
http://www.tenorshare.com/downloads/service/softwarelog.txt
unknown
http://www.tenorshare.com/downloads/service/softwarelog.txthttp://ip-api.com/csvsuccess/QueryTools?L
unknown
https://www.runoob.com/python/att-string-replace.htmlt2(t2:curl
unknown
https://update.tenorshare.cn/queryDownloader?LanguageId=%d&SoftWareID=%d&SiteID=%d%scompKV
unknown
https://download.hitpaw.net/downloads/extra/hitpawphotoai_hitpawnet.exe&
unknown
https://www.tenorshare.com/Ko0
unknown
https://update.tenorshare.cn/queryDownloader?LanguageId=%d&SoftWareID=%d&SiteID=%d%s
unknown
https://update.tenorshare.com/queryDownloader?LanguageId=1033&SoftWareID=423&SiteID=74
unknown
https://curl.se/docs/http-cookies.html
unknown
https://update.tenorshare.com/api/exception/sendhttps://product-alert.afirstsoft.cn/api/exception/se
unknown
https://integrated.tenorshare.com/api/v1/ticket/feedback
unknown
http://update.tenorshare.com/download/checkCross?cross_end_id=%s
unknown
http://www.tenorshare.com/downloads/service/softwarelog.txt2
unknown
http://www.microsoft.
unknown
https://curl.se/docs/alt-svc.html
unknown
https://update.tenorshare.com/queryDownloader?LanguageId=1033&SoftWareID=423&SiteID=74ws
unknown
http://192.168.40.249:56215/sync
unknown
https://update.tenorshare.com/api/exception/send
unknown
https://www.runoob.com/matplotlib/matplotlib-tutorial.htmlt3(t3:curl
unknown
http://www.tenorshare.com/downloads/service/softwarelog.txtP$
unknown
https://download.hitpaw.net/downloadexh
unknown
https://www.baidu.com
unknown
https://www.tenorshare.com/orshare.com/downloads/service/softwarelog.txt
unknown
https://www.tenorshare.com/
unknown
http://update.tenorshare.com/download/checkCross?cross_end_id=%shttps://update.tenorshare.cn/downloa
unknown
https://update.tenorshare.com/download/checkCross?cross_end_id=%s
unknown
https://update.tenorshare.com/queryDownloader?LanguageId=%d&SoftWareID=%d&SiteID=%d%s
unknown
https://analytics-test.afirstsoft.cn/collector
unknown
https://product-alert.afirstsoft.cn/api/exception/send
unknown
https://analytics-test.afirstsoft.cn/collectorurl:WMIService%s
unknown
https://download.hitpaw.net/downloads/extra/hitpawphotoai_hitpawnet.exel
unknown
https://www.tenorshare.com/downloads/service/softwarelog.txtas
unknown
https://download.hitpaw.net/downloads/extra/hitpawphotoai_hitpawnet.exef
unknown
http://ip-api.com/csv
208.95.112.1
https://check.mobie.app
unknown
http://update.tenorshare.com/queryDownloader?LanguageId=%d&SoftWareID=%d&SiteID=%d%s
unknown
https://update.tenorshare.com/queryDownloader?LanguageId=%d&SoftWareID=%d&SiteID=%d%sDL003DL002int
unknown
There are 43 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
ip-api.com
208.95.112.1
www.tenorshare.com
unknown
update.tenorshare.com
unknown
analytics.afirstsoft.cn
unknown

IPs

IP
Domain
Country
Malicious
208.95.112.1
ip-api.com
United States
127.0.0.1
unknown
unknown

Registry

Path
Value
Malicious
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Tenorshare\Downloader2.5.0
GA_PC
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\GuidGuidold
guid
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\GuidGuidold
user_id

Memdumps

Base Address
Regiontype
Protect
Malicious
32C4000
heap
page read and write
3591000
heap
page read and write
35AB000
heap
page read and write
3CE7000
heap
page read and write
3521000
heap
page read and write
3630000
heap
page read and write
3521000
heap
page read and write
3521000
heap
page read and write
32C4000
heap
page read and write
7BA000
heap
page read and write
3741000
heap
page read and write
3CEB000
heap
page read and write
35DA000
heap
page read and write
3132000
heap
page read and write
33E4000
heap
page read and write
3D69000
heap
page read and write
3CAD000
heap
page read and write
3BA2000
heap
page read and write
3521000
heap
page read and write
3741000
heap
page read and write
3407000
heap
page read and write
3741000
heap
page read and write
32C4000
heap
page read and write
3741000
heap
page read and write
3591000
heap
page read and write
33E4000
heap
page read and write
32C4000
heap
page read and write
3741000
heap
page read and write
3CBC000
heap
page read and write
32C4000
heap
page read and write
89E000
heap
page read and write
3741000
heap
page read and write
3C53000
heap
page read and write
3741000
heap
page read and write
3CCC000
heap
page read and write
3521000
heap
page read and write
3406000
heap
page read and write
3521000
heap
page read and write
86D000
heap
page read and write
3741000
heap
page read and write
3521000
heap
page read and write
3741000
heap
page read and write
4182000
heap
page read and write
359A000
heap
page read and write
35E3000
heap
page read and write
857000
heap
page read and write
359B000
heap
page read and write
3741000
heap
page read and write
3591000
heap
page read and write
3521000
heap
page read and write
810000
heap
page read and write
3DCE000
heap
page read and write
32C4000
heap
page read and write
33E4000
heap
page read and write
811000
heap
page read and write
33E4000
heap
page read and write
33E4000
heap
page read and write
2F5E000
stack
page read and write
3579000
heap
page read and write
3C48000
heap
page read and write
33E4000
heap
page read and write
3CDE000
heap
page read and write
358F000
heap
page read and write
33E4000
heap
page read and write
3741000
heap
page read and write
3CE9000
heap
page read and write
7F4000
heap
page read and write
30C1000
heap
page read and write
30E7000
heap
page read and write
3521000
heap
page read and write
33E4000
heap
page read and write
647C000
heap
page read and write
884000
heap
page read and write
3195000
heap
page read and write
3CEB000
heap
page read and write
3C6C000
heap
page read and write
3741000
heap
page read and write
3741000
heap
page read and write
3595000
heap
page read and write
3521000
heap
page read and write
33D0000
heap
page read and write
3521000
heap
page read and write
3741000
heap
page read and write
32C4000
heap
page read and write
3521000
heap
page read and write
370D000
heap
page read and write
81D000
heap
page read and write
3C11000
heap
page read and write
29E0000
heap
page read and write
3741000
heap
page read and write
315C000
heap
page read and write
3741000
heap
page read and write
32C4000
heap
page read and write
3521000
heap
page read and write
63CE000
heap
page read and write
3118000
heap
page read and write
32C4000
heap
page read and write
3730000
heap
page read and write
3CC6000
heap
page read and write
3D79000
heap
page read and write
3D74000
heap
page read and write
54AF000
stack
page read and write
373D000
heap
page read and write
3220000
heap
page read and write
33E4000
heap
page read and write
89E000
heap
page read and write
315C000
heap
page read and write
3521000
heap
page read and write
3D63000
heap
page read and write
3521000
heap
page read and write
DEB000
heap
page read and write
3521000
heap
page read and write
35DF000
heap
page read and write
599F000
stack
page read and write
3CFE000
stack
page read and write
582000
unkown
page execute and read and write
315C000
heap
page read and write
3C48000
heap
page read and write
3D6A000
heap
page read and write
3562000
heap
page read and write
3741000
heap
page read and write
3521000
heap
page read and write
7F4000
heap
page read and write
3521000
heap
page read and write
32C4000
heap
page read and write
3741000
heap
page read and write
32C4000
heap
page read and write
3BA0000
heap
page read and write
35BF000
heap
page read and write
722000
unkown
page execute and write copy
33E4000
heap
page read and write
32C4000
heap
page read and write
3521000
heap
page read and write
3107000
heap
page read and write
3597000
heap
page read and write
368E000
stack
page read and write
3521000
heap
page read and write
3521000
heap
page read and write
4160000
heap
page read and write
3183000
heap
page read and write
63B0000
heap
page read and write
5699000
heap
page read and write
31B7000
heap
page read and write
3741000
heap
page read and write
81F000
heap
page read and write
3521000
heap
page read and write
3D1C000
heap
page read and write
2740000
heap
page read and write
3741000
heap
page read and write
3521000
heap
page read and write
64A9000
heap
page read and write
3521000
heap
page read and write
35E3000
heap
page read and write
3741000
heap
page read and write
33E4000
heap
page read and write
5CAF000
stack
page read and write
3521000
heap
page read and write
DE0000
heap
page read and write
3741000
heap
page read and write
5600000
heap
page read and write
347A000
heap
page read and write
3741000
heap
page read and write
838000
heap
page read and write
3521000
heap
page read and write
88B000
heap
page read and write
3CC6000
heap
page read and write
3132000
heap
page read and write
3BD0000
heap
page read and write
8A0000
heap
page read and write
3521000
heap
page read and write
3128000
heap
page read and write
717000
unkown
page execute and read and write
32C4000
heap
page read and write
33E4000
heap
page read and write
3107000
heap
page read and write
3D66000
heap
page read and write
861000
heap
page read and write
3461000
heap
page read and write
6476000
heap
page read and write
357A000
heap
page read and write
33E4000
heap
page read and write
3741000
heap
page read and write
33DE000
stack
page read and write
33E4000
heap
page read and write
2B3C000
stack
page read and write
32C4000
heap
page read and write
3490000
heap
page read and write
861000
heap
page read and write
3521000
heap
page read and write
3550000
heap
page read and write
3741000
heap
page read and write
3620000
trusted library allocation
page read and write
5618000
heap
page read and write
3476000
heap
page read and write
3579000
heap
page read and write
33E4000
heap
page read and write
32C4000
heap
page read and write
32C4000
heap
page read and write
3118000
heap
page read and write
33E4000
heap
page read and write
35BD000
heap
page read and write
32C4000
heap
page read and write
33E0000
heap
page read and write
3741000
heap
page read and write
33E4000
heap
page read and write
32C4000
heap
page read and write
3CE7000
heap
page read and write
3521000
heap
page read and write
3521000
heap
page read and write
812000
heap
page read and write
40A6000
heap
page read and write
32C4000
heap
page read and write
3CE7000
heap
page read and write
3521000
heap
page read and write
32C4000
heap
page read and write
3C1A000
heap
page read and write
345E000
heap
page read and write
346C000
heap
page read and write
3B9D000
heap
page read and write
35E0000
heap
page read and write
3C19000
heap
page read and write
3521000
heap
page read and write
32C4000
heap
page read and write
3461000
heap
page read and write
888000
heap
page read and write
32C4000
heap
page read and write
3D7F000
heap
page read and write
3C95000
heap
page read and write
3132000
heap
page read and write
3D7E000
heap
page read and write
33E4000
heap
page read and write
3741000
heap
page read and write
36FF000
stack
page read and write
3741000
heap
page read and write
3741000
heap
page read and write
3741000
heap
page read and write
3D7A000
heap
page read and write
33E4000
heap
page read and write
416B000
heap
page read and write
3138000
heap
page read and write
3FE0000
remote allocation
page read and write
3CEC000
heap
page read and write
3521000
heap
page read and write
401000
unkown
page execute and read and write
3521000
heap
page read and write
34EE000
stack
page read and write
3741000
heap
page read and write
33E4000
heap
page read and write
546E000
stack
page read and write
33E4000
heap
page read and write
5618000
heap
page read and write
3741000
heap
page read and write
5611000
heap
page read and write
3741000
heap
page read and write
3521000
heap
page read and write
3D70000
heap
page read and write
96000
stack
page read and write
3741000
heap
page read and write
3521000
heap
page read and write
33D0000
trusted library allocation
page read and write
370D000
heap
page read and write
32C4000
heap
page read and write
81D000
heap
page read and write
32C4000
heap
page read and write
2FB0000
heap
page read and write
822000
heap
page read and write
3C99000
heap
page read and write
3B96000
heap
page read and write
6052000
heap
page read and write
305F000
stack
page read and write
3521000
heap
page read and write
3298000
stack
page read and write
4162000
heap
page read and write
7B0000
heap
page read and write
35DF000
heap
page read and write
33E4000
heap
page read and write
4131000
heap
page read and write
888000
heap
page read and write
355F000
heap
page read and write
331E000
stack
page read and write
3521000
heap
page read and write
3486000
heap
page read and write
33E4000
heap
page read and write
33E4000
heap
page read and write
4075000
heap
page read and write
3520000
heap
page read and write
3521000
heap
page read and write
32C4000
heap
page read and write
3FE0000
remote allocation
page read and write
3D06000
heap
page read and write
83B000
heap
page read and write
33E4000
heap
page read and write
857000
heap
page read and write
3741000
heap
page read and write
32C4000
heap
page read and write
3521000
heap
page read and write
35DA000
heap
page read and write
32C4000
heap
page read and write
5693000
heap
page read and write
421E000
stack
page read and write
30C0000
heap
page read and write
3C53000
heap
page read and write
878000
heap
page read and write
3B97000
heap
page read and write
315C000
heap
page read and write
2FFE000
stack
page read and write
3D67000
heap
page read and write
3521000
heap
page read and write
3521000
heap
page read and write
3128000
heap
page read and write
3598000
heap
page read and write
ACF000
stack
page read and write
32C4000
heap
page read and write
3521000
heap
page read and write
35DA000
heap
page read and write
345E000
heap
page read and write
3340000
heap
page read and write
33E4000
heap
page read and write
3741000
heap
page read and write
5618000
heap
page read and write
311C000
heap
page read and write
3741000
heap
page read and write
344A000
heap
page read and write
3521000
heap
page read and write
3D3F000
stack
page read and write
33E4000
heap
page read and write
3741000
heap
page read and write
315C000
heap
page read and write
32C4000
heap
page read and write
370B000
heap
page read and write
3741000
heap
page read and write
33E4000
heap
page read and write
33E4000
heap
page read and write
3CAD000
heap
page read and write
3D05000
heap
page read and write
3741000
heap
page read and write
6427000
heap
page read and write
3741000
heap
page read and write
2F0B000
stack
page read and write
3CFB000
heap
page read and write
33E4000
heap
page read and write
35D0000
heap
page read and write
3741000
heap
page read and write
342F000
heap
page read and write
194000
stack
page read and write
3741000
heap
page read and write
3741000
heap
page read and write
3741000
heap
page read and write
3741000
heap
page read and write
3100000
heap
page read and write
3741000
heap
page read and write
3741000
heap
page read and write
36BE000
stack
page read and write
54EE000
stack
page read and write
3521000
heap
page read and write
3741000
heap
page read and write
3521000
heap
page read and write
3128000
heap
page read and write
32C4000
heap
page read and write
3741000
heap
page read and write
3521000
heap
page read and write
814000
heap
page read and write
7A0000
heap
page read and write
5CC0000
heap
page read and write
3583000
heap
page read and write
3125000
heap
page read and write
3521000
heap
page read and write
33E4000
heap
page read and write
3591000
heap
page read and write
3741000
heap
page read and write
30E7000
heap
page read and write
3741000
heap
page read and write
3741000
heap
page read and write
3521000
heap
page read and write
4167000
heap
page read and write
3741000
heap
page read and write
3521000
heap
page read and write
5694000
heap
page read and write
32C4000
heap
page read and write
3D76000
heap
page read and write
346A000
heap
page read and write
3476000
heap
page read and write
346D000
heap
page read and write
3741000
heap
page read and write
3521000
heap
page read and write
3741000
heap
page read and write
B0E000
stack
page read and write
3741000
heap
page read and write
3741000
heap
page read and write
3521000
heap
page read and write
32C4000
heap
page read and write
649A000
heap
page read and write
29D0000
heap
page read and write
3521000
heap
page read and write
3521000
heap
page read and write
7E1000
heap
page read and write
33E4000
heap
page read and write
2B4A000
stack
page read and write
3CA8000
heap
page read and write
3740000
heap
page read and write
3521000
heap
page read and write
861000
heap
page read and write
3191000
heap
page read and write
3521000
heap
page read and write
33E4000
heap
page read and write
861000
heap
page read and write
3741000
heap
page read and write
3710000
heap
page read and write
3142000
heap
page read and write
3741000
heap
page read and write
32C4000
heap
page read and write
3741000
heap
page read and write
C0F000
stack
page read and write
81A000
heap
page read and write
3CF7000
heap
page read and write
400000
unkown
page readonly
3D6C000
heap
page read and write
884000
heap
page read and write
2D4F000
stack
page read and write
3741000
heap
page read and write
346B000
heap
page read and write
3402000
heap
page read and write
3D07000
heap
page read and write
3D12000
heap
page read and write
7F4000
heap
page read and write
3521000
heap
page read and write
3521000
heap
page read and write
817000
heap
page read and write
3C40000
heap
page read and write
32C4000
heap
page read and write
790000
heap
page read and write
33E4000
heap
page read and write
3741000
heap
page read and write
344A000
heap
page read and write
3741000
heap
page read and write
3123000
heap
page read and write
32C4000
heap
page read and write
4163000
heap
page read and write
8EE000
stack
page read and write
32C4000
heap
page read and write
321C000
stack
page read and write
3521000
heap
page read and write
5710000
heap
page read and write
340A000
heap
page read and write
3741000
heap
page read and write
3741000
heap
page read and write
3521000
heap
page read and write
3741000
heap
page read and write
3521000
heap
page read and write
7F4000
heap
page read and write
3CD6000
heap
page read and write
857000
heap
page read and write
32F0000
heap
page read and write
3521000
heap
page read and write
3C40000
heap
page read and write
3741000
heap
page read and write
7EF000
heap
page read and write
7E1000
heap
page read and write
3741000
heap
page read and write
35D0000
heap
page read and write
3CC8000
heap
page read and write
32C4000
heap
page read and write
3CAD000
heap
page read and write
818000
heap
page read and write
325B000
stack
page read and write
3521000
heap
page read and write
3431000
heap
page read and write
3D67000
heap
page read and write
33E4000
heap
page read and write
564E000
stack
page read and write
578000
unkown
page execute and read and write
3521000
heap
page read and write
3521000
heap
page read and write
32C4000
heap
page read and write
3521000
heap
page read and write
32C4000
heap
page read and write
3521000
heap
page read and write
33E4000
heap
page read and write
32C4000
heap
page read and write
3741000
heap
page read and write
32C4000
heap
page read and write
3CE7000
heap
page read and write
35AB000
heap
page read and write
3741000
heap
page read and write
3741000
heap
page read and write
346E000
stack
page read and write
3521000
heap
page read and write
32C4000
heap
page read and write
33E4000
heap
page read and write
33E4000
heap
page read and write
35D7000
heap
page read and write
3741000
heap
page read and write
3400000
heap
page read and write
33E4000
heap
page read and write
3CDF000
heap
page read and write
33E4000
heap
page read and write
3741000
heap
page read and write
3521000
heap
page read and write
31B7000
heap
page read and write
329E000
stack
page read and write
3521000
heap
page read and write
3741000
heap
page read and write
5614000
heap
page read and write
3741000
heap
page read and write
861000
heap
page read and write
3521000
heap
page read and write
819000
heap
page read and write
3CE7000
heap
page read and write
5754000
heap
page read and write
5714000
heap
page read and write
861000
heap
page read and write
33E4000
heap
page read and write
5711000
heap
page read and write
3128000
heap
page read and write
33E4000
heap
page read and write
31B7000
heap
page read and write
34F0000
trusted library allocation
page read and write
344C000
heap
page read and write
33E4000
heap
page read and write
32C4000
heap
page read and write
3195000
heap
page read and write
32C4000
heap
page read and write
3FE0000
remote allocation
page read and write
3240000
heap
page read and write
32C4000
heap
page read and write
3741000
heap
page read and write
3420000
heap
page read and write
2F58000
heap
page read and write
3741000
heap
page read and write
3741000
heap
page read and write
3521000
heap
page read and write
3521000
heap
page read and write
344A000
heap
page read and write
312C000
heap
page read and write
3521000
heap
page read and write
33E4000
heap
page read and write
34AE000
stack
page read and write
3521000
heap
page read and write
296E000
stack
page read and write
3741000
heap
page read and write
32C4000
heap
page read and write
2DA0000
heap
page read and write
5718000
heap
page read and write
723000
unkown
page write copy
3741000
heap
page read and write
7BE000
heap
page read and write
3D63000
heap
page read and write
32C4000
heap
page read and write
3521000
heap
page read and write
5E61000
heap
page read and write
2D0E000
stack
page read and write
400000
unkown
page readonly
81D000
heap
page read and write
3521000
heap
page read and write
33E4000
heap
page read and write
33E4000
heap
page read and write
3741000
heap
page read and write
3521000
heap
page read and write
3CE6000
heap
page read and write
7E3000
heap
page read and write
3521000
heap
page read and write
33E4000
heap
page read and write
3584000
heap
page read and write
3521000
heap
page read and write
35E3000
heap
page read and write
3741000
heap
page read and write
32C4000
heap
page read and write
3B99000
heap
page read and write
3090000
heap
page read and write
3741000
heap
page read and write
3CC6000
heap
page read and write
3132000
heap
page read and write
2F48000
stack
page read and write
3B90000
heap
page read and write
312C000
heap
page read and write
3741000
heap
page read and write
7E1000
heap
page read and write
3741000
heap
page read and write
347B000
heap
page read and write
3521000
heap
page read and write
3D62000
heap
page read and write
359B000
heap
page read and write
3741000
heap
page read and write
3741000
heap
page read and write
3521000
heap
page read and write
33E4000
heap
page read and write
32C4000
heap
page read and write
32C4000
heap
page read and write
552F000
stack
page read and write
3521000
heap
page read and write
3142000
heap
page read and write
323F000
stack
page read and write
3132000
heap
page read and write
3D59000
heap
page read and write
3741000
heap
page read and write
3521000
heap
page read and write
32C4000
heap
page read and write
3C2D000
heap
page read and write
3521000
heap
page read and write
3530000
heap
page read and write
3521000
heap
page read and write
861000
heap
page read and write
33E4000
heap
page read and write
3521000
heap
page read and write
3741000
heap
page read and write
32C4000
heap
page read and write
315C000
heap
page read and write
8A3000
heap
page read and write
3191000
heap
page read and write
32C4000
heap
page read and write
3741000
heap
page read and write
3B94000
heap
page read and write
33E4000
heap
page read and write
33E4000
heap
page read and write
3660000
heap
page read and write
3741000
heap
page read and write
35DA000
heap
page read and write
817000
heap
page read and write
3521000
heap
page read and write
3521000
heap
page read and write
3C75000
heap
page read and write
33E4000
heap
page read and write
3521000
heap
page read and write
3B99000
heap
page read and write
3521000
heap
page read and write
3741000
heap
page read and write
32C4000
heap
page read and write
3521000
heap
page read and write
3521000
heap
page read and write
33E4000
heap
page read and write
3521000
heap
page read and write
33E4000
heap
page read and write
3D63000
heap
page read and write
3128000
heap
page read and write
32C4000
heap
page read and write
32C4000
heap
page read and write
3741000
heap
page read and write
3741000
heap
page read and write
33E4000
heap
page read and write
32C4000
heap
page read and write
3521000
heap
page read and write
3741000
heap
page read and write
8F5000
heap
page read and write
345E000
heap
page read and write
3741000
heap
page read and write
8A4000
heap
page read and write
3741000
heap
page read and write
32C4000
heap
page read and write
5718000
heap
page read and write
3741000
heap
page read and write
3521000
heap
page read and write
899000
heap
page read and write
568F000
stack
page read and write
650A000
heap
page read and write
32C4000
heap
page read and write
3620000
trusted library allocation
page read and write
33E4000
heap
page read and write
347A000
heap
page read and write
3D0F000
heap
page read and write
3741000
heap
page read and write
3521000
heap
page read and write
35BF000
heap
page read and write
3521000
heap
page read and write
3409000
heap
page read and write
3741000
heap
page read and write
3741000
heap
page read and write
3741000
heap
page read and write
32C4000
heap
page read and write
3521000
heap
page read and write
32C4000
heap
page read and write
DB0000
heap
page read and write
30E0000
heap
page read and write
7F4000
heap
page read and write
3CFF000
heap
page read and write
3741000
heap
page read and write
3BE2000
heap
page read and write
33E4000
heap
page read and write
3521000
heap
page read and write
723000
unkown
page read and write
3C76000
heap
page read and write
3130000
heap
page read and write
3CA8000
heap
page read and write
33E4000
heap
page read and write
32C4000
heap
page read and write
35D0000
heap
page read and write
3B95000
heap
page read and write
3521000
heap
page read and write
33E4000
heap
page read and write
8F0000
heap
page read and write
2A4C000
stack
page read and write
3741000
heap
page read and write
3521000
heap
page read and write
3741000
heap
page read and write
3100000
heap
page read and write
63CC000
heap
page read and write
33E4000
heap
page read and write
33E4000
heap
page read and write
30E0000
heap
page read and write
33E4000
heap
page read and write
3521000
heap
page read and write
3741000
heap
page read and write
5610000
heap
page read and write
3741000
heap
page read and write
81E000
heap
page read and write
3521000
heap
page read and write
2F50000
heap
page read and write
3CBB000
heap
page read and write
83B000
heap
page read and write
550000
unkown
page execute and write copy
348B000
heap
page read and write
3C07000
heap
page read and write
3741000
heap
page read and write
340C000
heap
page read and write
30C1000
heap
page read and write
3521000
heap
page read and write
3521000
heap
page read and write
DE7000
heap
page read and write
3521000
heap
page read and write
3741000
heap
page read and write
3C24000
heap
page read and write
3521000
heap
page read and write
3741000
heap
page read and write
3521000
heap
page read and write
32C4000
heap
page read and write
32C4000
heap
page read and write
33E4000
heap
page read and write
5718000
heap
page read and write
32C4000
heap
page read and write
32C4000
heap
page read and write
196000
stack
page read and write
3D6A000
heap
page read and write
31B7000
heap
page read and write
3741000
heap
page read and write
33E4000
heap
page read and write
32C4000
heap
page read and write
32C4000
heap
page read and write
32C4000
heap
page read and write
3741000
heap
page read and write
3D60000
heap
page read and write
89E000
heap
page read and write
5DD8000
heap
page read and write
3741000
heap
page read and write
33E4000
heap
page read and write
3C40000
heap
page read and write
3521000
heap
page read and write
3741000
heap
page read and write
3521000
heap
page read and write
87A000
heap
page read and write
3521000
heap
page read and write
3521000
heap
page read and write
33E4000
heap
page read and write
7E1000
heap
page read and write
3132000
heap
page read and write
3521000
heap
page read and write
292D000
stack
page read and write
3DCC000
heap
page read and write
3471000
heap
page read and write
32C4000
heap
page read and write
3D79000
heap
page read and write
7E1000
heap
page read and write
3741000
heap
page read and write
3521000
heap
page read and write
30E0000
heap
page read and write
357B000
heap
page read and write
3521000
heap
page read and write
3521000
heap
page read and write
3C9D000
heap
page read and write
3521000
heap
page read and write
33E4000
heap
page read and write
33E4000
heap
page read and write
313D000
heap
page read and write
3471000
heap
page read and write
3D0B000
heap
page read and write
3521000
heap
page read and write
86D000
heap
page read and write
3142000
heap
page read and write
33E4000
heap
page read and write
3B9A000
heap
page read and write
315C000
heap
page read and write
32C4000
heap
page read and write
817000
heap
page read and write
35E3000
heap
page read and write
3741000
heap
page read and write
33E4000
heap
page read and write
3521000
heap
page read and write
3142000
heap
page read and write
33E4000
heap
page read and write
3521000
heap
page read and write
815000
heap
page read and write
34F0000
trusted library allocation
page read and write
861000
heap
page read and write
32C4000
heap
page read and write
3741000
heap
page read and write
32C4000
heap
page read and write
3741000
heap
page read and write
642E000
heap
page read and write
33E4000
heap
page read and write
3191000
heap
page read and write
3BA1000
heap
page read and write
88B000
heap
page read and write
3579000
heap
page read and write
3521000
heap
page read and write
3D9D000
heap
page read and write
3FED000
heap
page read and write
3521000
heap
page read and write
3741000
heap
page read and write
32C4000
heap
page read and write
32C4000
heap
page read and write
589E000
stack
page read and write
3521000
heap
page read and write
348A000
heap
page read and write
875000
heap
page read and write
33E4000
heap
page read and write
3521000
heap
page read and write
3521000
heap
page read and write
3510000
heap
page read and write
3521000
heap
page read and write
5F7B000
heap
page read and write
64FB000
heap
page read and write
373B000
heap
page read and write
4168000
heap
page read and write
342B000
heap
page read and write
3521000
heap
page read and write
3741000
heap
page read and write
33E4000
heap
page read and write
815000
heap
page read and write
33E4000
heap
page read and write
3521000
heap
page read and write
3134000
heap
page read and write
348B000
heap
page read and write
3741000
heap
page read and write
3CD9000
heap
page read and write
3521000
heap
page read and write
3521000
heap
page read and write
3521000
heap
page read and write
32C4000
heap
page read and write
32C4000
heap
page read and write
3741000
heap
page read and write
3741000
heap
page read and write
3D7D000
heap
page read and write
7E7000
heap
page read and write
33E4000
heap
page read and write
3C44000
heap
page read and write
3CC6000
heap
page read and write
81D000
heap
page read and write
3741000
heap
page read and write
3461000
heap
page read and write
32C4000
heap
page read and write
33E4000
heap
page read and write
3700000
heap
page read and write
3741000
heap
page read and write
3741000
heap
page read and write
32C4000
heap
page read and write
346C000
heap
page read and write
3738000
heap
page read and write
3741000
heap
page read and write
344B000
heap
page read and write
3521000
heap
page read and write
3741000
heap
page read and write
3521000
heap
page read and write
3521000
heap
page read and write
3D68000
heap
page read and write
3D33000
heap
page read and write
32C4000
heap
page read and write
32C4000
heap
page read and write
33E4000
heap
page read and write
3741000
heap
page read and write
32C4000
heap
page read and write
3741000
heap
page read and write
35BD000
heap
page read and write
3142000
heap
page read and write
33E4000
heap
page read and write
3521000
heap
page read and write
33E4000
heap
page read and write
3521000
heap
page read and write
3C9D000
heap
page read and write
355E000
heap
page read and write
3100000
heap
page read and write
3741000
heap
page read and write
3741000
heap
page read and write
3521000
heap
page read and write
32C4000
heap
page read and write
3741000
heap
page read and write
342E000
stack
page read and write
36CF000
stack
page read and write
32C4000
heap
page read and write
3741000
heap
page read and write
3741000
heap
page read and write
861000
heap
page read and write
32C4000
heap
page read and write
3521000
heap
page read and write
3521000
heap
page read and write
3521000
heap
page read and write
3521000
heap
page read and write
355C000
heap
page read and write
3D6A000
heap
page read and write
35BD000
heap
page read and write
3123000
heap
page read and write
3403000
heap
page read and write
3B9D000
heap
page read and write
3741000
heap
page read and write
32B0000
heap
page read and write
3D78000
heap
page read and write
33E4000
heap
page read and write
373D000
heap
page read and write
33E4000
heap
page read and write
3D82000
heap
page read and write
33E4000
heap
page read and write
33E4000
heap
page read and write
3741000
heap
page read and write
310A000
heap
page read and write
33F0000
heap
page read and write
3741000
heap
page read and write
871000
heap
page read and write
3741000
heap
page read and write
3741000
heap
page read and write
3741000
heap
page read and write
32C4000
heap
page read and write
3D43000
heap
page read and write
7F4000
heap
page read and write
3741000
heap
page read and write
3741000
heap
page read and write
3521000
heap
page read and write
33E4000
heap
page read and write
3C53000
heap
page read and write
32C4000
heap
page read and write
32C4000
heap
page read and write
3741000
heap
page read and write
3C3F000
heap
page read and write
3DA6000
heap
page read and write
3741000
heap
page read and write
3741000
heap
page read and write
33E4000
heap
page read and write
33E4000
heap
page read and write
3594000
heap
page read and write
3D81000
heap
page read and write
3521000
heap
page read and write
35C2000
heap
page read and write
3486000
heap
page read and write
3521000
heap
page read and write
3521000
heap
page read and write
3708000
heap
page read and write
81E000
heap
page read and write
861000
heap
page read and write
3521000
heap
page read and write
32C4000
heap
page read and write
3D78000
heap
page read and write
818000
heap
page read and write
33E4000
heap
page read and write
3521000
heap
page read and write
3741000
heap
page read and write
3521000
heap
page read and write
3195000
heap
page read and write
7E4000
heap
page read and write
3CAD000
heap
page read and write
888000
heap
page read and write
3562000
heap
page read and write
3591000
heap
page read and write
32C0000
heap
page read and write
3741000
heap
page read and write
33E4000
heap
page read and write
7F4000
heap
page read and write
There are 952 hidden memdumps, click here to show them.