IOC Report
muk.ps1

loading gif

Files

File Path
Type
Category
Malicious
muk.ps1
ASCII text, with very long lines (57417), with CRLF line terminators
initial sample
malicious
C:\Users\user\AppData\Local\Temp\JXCJKXCJHKJHXCJHKXCXCJHK.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\JXCJKXCJHKJHXCJHKXCXCJHK.exe.log
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\ZVZFKMB9\json[1].json
JSON data
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
data
dropped
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_4triemkc.rbt.ps1
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_n2javxcs.wj2.psm1
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\9O7A38Z8NHXX7KZ1G4ZX.temp
data
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms (copy)
data
dropped

Processes

Path
Cmdline
Malicious
C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -noLogo -ExecutionPolicy unrestricted -file "C:\Users\user\Desktop\muk.ps1"
malicious
C:\Users\user\AppData\Local\Temp\JXCJKXCJHKJHXCJHKXCXCJHK.exe
"C:\Users\user\AppData\Local\Temp\JXCJKXCJHKJHXCJHKXCXCJHK.exe"
malicious
C:\Users\user\AppData\Local\Temp\JXCJKXCJHKJHXCJHKXCXCJHK.exe
"C:\Users\user\AppData\Local\Temp\JXCJKXCJHKJHXCJHKXCXCJHK.exe"
malicious
C:\Users\user\AppData\Local\Temp\JXCJKXCJHKJHXCJHKXCXCJHK.exe
"C:\Users\user\AppData\Local\Temp\JXCJKXCJHKJHXCJHKXCXCJHK.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\System32\notepad.exe
"C:\Windows\System32\notepad.exe" "C:\Users\user\Desktop\muk.ps1"

URLs

Name
IP
Malicious
http://geoplugin.net/json.gp
178.237.33.50
http://nuget.org/NuGet.exe
unknown
http://176.65.144.3/dev/muk.exed
unknown
http://geoplugin.net/json.gp&
unknown
http://geoplugin.net/
unknown
http://pesterbdd.com/images/Pester.png
unknown
http://geoplugin.net/json.gp/C
unknown
http://geoplugin.net/json.gpl
unknown
http://geoplugin.net/json.gpwK
unknown
https://aka.ms/pscore6lB
unknown
http://www.apache.org/licenses/LICENSE-2.0.html
unknown
https://contoso.com/
unknown
https://nuget.org/nuget.exe
unknown
https://contoso.com/License
unknown
http://176.65.144.3
unknown
https://contoso.com/Icon
unknown
http://176.65.144.3/dev/muk.exeP
unknown
http://176.65.144.3/dev/muk.exe
176.65.144.3
http://crl.micro6
unknown
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
unknown
https://github.com/Pester/Pester
unknown
http://geoplugin.net/json.gpSystem32
unknown
There are 12 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
geoplugin.net
178.237.33.50
18.31.95.13.in-addr.arpa
unknown

IPs

IP
Domain
Country
Malicious
198.23.227.212
unknown
United States
malicious
176.65.144.3
unknown
Germany
178.237.33.50
geoplugin.net
Netherlands

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-DJTZHJ
exepath
malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-DJTZHJ
licence
malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-DJTZHJ
time
malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-DJTZHJ
UID
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing
EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\JXCJKXCJHKJHXCJHKXCXCJHK_RASAPI32
EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\JXCJKXCJHKJHXCJHKXCXCJHK_RASAPI32
EnableAutoFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\JXCJKXCJHKJHXCJHKXCXCJHK_RASAPI32
EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\JXCJKXCJHKJHXCJHKXCXCJHK_RASAPI32
FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\JXCJKXCJHKJHXCJHKXCXCJHK_RASAPI32
ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\JXCJKXCJHKJHXCJHKXCXCJHK_RASAPI32
MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\JXCJKXCJHKJHXCJHKXCXCJHK_RASAPI32
FileDirectory
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\JXCJKXCJHKJHXCJHKXCXCJHK_RASMANCS
EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\JXCJKXCJHKJHXCJHKXCXCJHK_RASMANCS
EnableAutoFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\JXCJKXCJHKJHXCJHKXCXCJHK_RASMANCS
EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\JXCJKXCJHKJHXCJHKXCXCJHK_RASMANCS
FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\JXCJKXCJHKJHXCJHKXCXCJHK_RASMANCS
ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\JXCJKXCJHKJHXCJHKXCXCJHK_RASMANCS
MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\JXCJKXCJHKJHXCJHKXCXCJHK_RASMANCS
FileDirectory
There are 9 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
400000
remote allocation
page execute and read and write
malicious
DA8000
heap
page read and write
malicious
17897732000
heap
page read and write
17897732000
heap
page read and write
17897740000
heap
page read and write
1789772B000
heap
page read and write
1789772B000
heap
page read and write
17897734000
heap
page read and write
7A20000
trusted library allocation
page read and write
2C6F000
trusted library allocation
page read and write
17897734000
heap
page read and write
1789772B000
heap
page read and write
17897732000
heap
page read and write
17897734000
heap
page read and write
7837000
heap
page read and write
17897734000
heap
page read and write
E2A000
heap
page read and write
17897734000
heap
page read and write
2C20000
trusted library allocation
page read and write
4D38000
trusted library allocation
page read and write
17897740000
heap
page read and write
17897740000
heap
page read and write
17897726000
heap
page read and write
783B000
heap
page read and write
EA0000
heap
page read and write
17897727000
heap
page read and write
87B0000
heap
page read and write
17897734000
heap
page read and write
17897740000
heap
page read and write
4CB0000
trusted library allocation
page read and write
17897732000
heap
page read and write
4CB5000
trusted library allocation
page execute and read and write
17897726000
heap
page read and write
17897727000
heap
page read and write
17897726000
heap
page read and write
17897732000
heap
page read and write
17897732000
heap
page read and write
5416000
trusted library allocation
page read and write
1789772B000
heap
page read and write
1789772B000
heap
page read and write
17897732000
heap
page read and write
2A27000
trusted library allocation
page execute and read and write
17897726000
heap
page read and write
17897740000
heap
page read and write
2B7E000
stack
page read and write
17897732000
heap
page read and write
17897726000
heap
page read and write
7853000
heap
page read and write
17897726000
heap
page read and write
1789772B000
heap
page read and write
17897732000
heap
page read and write
17897732000
heap
page read and write
17897732000
heap
page read and write
178976B8000
heap
page read and write
17897740000
heap
page read and write
17897740000
heap
page read and write
17897740000
heap
page read and write
17897734000
heap
page read and write
17897726000
heap
page read and write
17899070000
heap
page read and write
17897734000
heap
page read and write
2C30000
trusted library allocation
page read and write
17897732000
heap
page read and write
4C763C9000
stack
page read and write
34E0000
heap
page read and write
17897734000
heap
page read and write
7931000
heap
page read and write
17897732000
heap
page read and write
51DE000
stack
page read and write
47C000
remote allocation
page execute and read and write
17897740000
heap
page read and write
4465000
trusted library allocation
page read and write
17897734000
heap
page read and write
122F000
stack
page read and write
17897734000
heap
page read and write
17897726000
heap
page read and write
2ADE000
stack
page read and write
562C000
trusted library allocation
page read and write
17897732000
heap
page read and write
17897734000
heap
page read and write
17897734000
heap
page read and write
17897732000
heap
page read and write
7C20000
trusted library allocation
page read and write
17897740000
heap
page read and write
17899100000
trusted library allocation
page read and write
1789772B000
heap
page read and write
1789772B000
heap
page read and write
17897726000
heap
page read and write
17897734000
heap
page read and write
4C68000
trusted library allocation
page read and write
17897740000
heap
page read and write
17897727000
heap
page read and write
17897732000
heap
page read and write
7540000
heap
page read and write
17897740000
heap
page read and write
17897726000
heap
page read and write
17897734000
heap
page read and write
E83000
heap
page read and write
D75000
heap
page read and write
17897726000
heap
page read and write
D75000
heap
page read and write
7A49000
trusted library allocation
page read and write
17897734000
heap
page read and write
1789772B000
heap
page read and write
17897727000
heap
page read and write
1789772B000
heap
page read and write
17897740000
heap
page read and write
5275000
heap
page execute and read and write
4D1E000
stack
page read and write
363F000
stack
page read and write
17897734000
heap
page read and write
2C61000
trusted library allocation
page read and write
17897726000
heap
page read and write
17897732000
heap
page read and write
1789772B000
heap
page read and write
1789772B000
heap
page read and write
17897726000
heap
page read and write
17897650000
heap
page read and write
1789772B000
heap
page read and write
17897732000
heap
page read and write
17897740000
heap
page read and write
1789772B000
heap
page read and write
17897726000
heap
page read and write
1789772B000
heap
page read and write
4C0D000
stack
page read and write
4DFE000
stack
page read and write
1789772B000
heap
page read and write
17897732000
heap
page read and write
17897740000
heap
page read and write
17897734000
heap
page read and write
52C1000
trusted library allocation
page read and write
1789772B000
heap
page read and write
17897732000
heap
page read and write
17897732000
heap
page read and write
17897740000
heap
page read and write
17897734000
heap
page read and write
D39000
stack
page read and write
17897727000
heap
page read and write
17897740000
heap
page read and write
17897734000
heap
page read and write
1789772B000
heap
page read and write
17897732000
heap
page read and write
17897734000
heap
page read and write
86DD000
stack
page read and write
4C70000
heap
page read and write
17897740000
heap
page read and write
17897732000
heap
page read and write
17897732000
heap
page read and write
7BC0000
trusted library allocation
page read and write
1789772B000
heap
page read and write
17897726000
heap
page read and write
17897740000
heap
page read and write
17897740000
heap
page read and write
17897732000
heap
page read and write
2D3B000
stack
page read and write
17897734000
heap
page read and write
3108000
heap
page read and write
1789772B000
heap
page read and write
C3C000
stack
page read and write
D70000
heap
page read and write
17897732000
heap
page read and write
2CE5000
trusted library allocation
page read and write
1789772B000
heap
page read and write
7C40000
trusted library allocation
page read and write
EB6000
heap
page read and write
78B9000
trusted library allocation
page read and write
17897734000
heap
page read and write
17897734000
heap
page read and write
17897734000
heap
page read and write
17897732000
heap
page read and write
1789772B000
heap
page read and write
17897740000
heap
page read and write
17897740000
heap
page read and write
7A8D000
stack
page read and write
17897732000
heap
page read and write
17897740000
heap
page read and write
17897732000
heap
page read and write
17897726000
heap
page read and write
17897726000
heap
page read and write
8720000
heap
page read and write
17897740000
heap
page read and write
17897734000
heap
page read and write
17897732000
heap
page read and write
17897740000
heap
page read and write
44C9000
trusted library allocation
page read and write
7BF0000
trusted library allocation
page read and write
17897726000
heap
page read and write
17897740000
heap
page read and write
17897726000
heap
page read and write
17897732000
heap
page read and write
17897726000
heap
page read and write
1789772B000
heap
page read and write
17897734000
heap
page read and write
78E0000
heap
page execute and read and write
4CD0000
trusted library allocation
page read and write
88B0000
heap
page read and write
8690000
trusted library allocation
page read and write
1789772B000
heap
page read and write
17897740000
heap
page read and write
17897734000
heap
page read and write
ECA000
heap
page read and write
1789772B000
heap
page read and write
17897732000
heap
page read and write
17897734000
heap
page read and write
17897732000
heap
page read and write
17897732000
heap
page read and write
3C61000
trusted library allocation
page read and write
F13000
heap
page read and write
17897732000
heap
page read and write
17897732000
heap
page read and write
17897740000
heap
page read and write
1789772B000
heap
page read and write
17897740000
heap
page read and write
17897740000
heap
page read and write
7C10000
trusted library allocation
page read and write
10C0000
heap
page read and write
17897734000
heap
page read and write
17899570000
heap
page read and write
17897740000
heap
page read and write
17897734000
heap
page read and write
2D7D000
stack
page read and write
17897732000
heap
page read and write
737E000
stack
page read and write
17897726000
heap
page read and write
1250000
heap
page read and write
17897740000
heap
page read and write
34D0000
heap
page read and write
17897732000
heap
page read and write
1789772B000
heap
page read and write
17897726000
heap
page read and write
17897732000
heap
page read and write
17897740000
heap
page read and write
772E000
stack
page read and write
5270000
heap
page execute and read and write
17897726000
heap
page read and write
17897732000
heap
page read and write
517E000
stack
page read and write
17897734000
heap
page read and write
4C83000
trusted library allocation
page execute and read and write
17897740000
heap
page read and write
17897740000
heap
page read and write
7B1E000
stack
page read and write
17897734000
heap
page read and write
2C50000
heap
page execute and read and write
178976FD000
heap
page read and write
17897734000
heap
page read and write
4D9F000
stack
page read and write
17897726000
heap
page read and write
1789772B000
heap
page read and write
17897732000
heap
page read and write
1789772B000
heap
page read and write
17897727000
heap
page read and write
1789772B000
heap
page read and write
3C65000
trusted library allocation
page read and write
316F000
heap
page read and write
17897740000
heap
page read and write
17897732000
heap
page read and write
17897732000
heap
page read and write
17897734000
heap
page read and write
1789772B000
heap
page read and write
17897734000
heap
page read and write
17897734000
heap
page read and write
17897726000
heap
page read and write
17897727000
heap
page read and write
4E00000
heap
page read and write
1789772B000
heap
page read and write
7CCE000
stack
page read and write
17897732000
heap
page read and write
17897726000
heap
page read and write
17897732000
heap
page read and write
E47000
heap
page read and write
17897740000
heap
page read and write
17897740000
heap
page read and write
3050000
heap
page read and write
178976E1000
heap
page read and write
1789772B000
heap
page read and write
774E000
stack
page read and write
17897740000
heap
page read and write
17897732000
heap
page read and write
1789907C000
heap
page read and write
17897734000
heap
page read and write
17897727000
heap
page read and write
7ADE000
stack
page read and write
17897734000
heap
page read and write
17897726000
heap
page read and write
8740000
trusted library allocation
page read and write
17897732000
heap
page read and write
ECE000
heap
page read and write
17897740000
heap
page read and write
17897734000
heap
page read and write
3100000
heap
page read and write
17897740000
heap
page read and write
E10000
heap
page read and write
1789772B000
heap
page read and write
2A3B000
trusted library allocation
page execute and read and write
518E000
stack
page read and write
17897740000
heap
page read and write
8785000
trusted library allocation
page read and write
17897734000
heap
page read and write
17897734000
heap
page read and write
2A37000
trusted library allocation
page execute and read and write
D3D000
stack
page read and write
17897740000
heap
page read and write
17897734000
heap
page read and write
17897726000
heap
page read and write
30DE000
stack
page read and write
1789772B000
heap
page read and write
7877000
heap
page read and write
1789772B000
heap
page read and write
17897732000
heap
page read and write
17897726000
heap
page read and write
17897726000
heap
page read and write
3156000
heap
page read and write
17897734000
heap
page read and write
2CDC000
trusted library allocation
page read and write
17897734000
heap
page read and write
17897740000
heap
page read and write
17897732000
heap
page read and write
1789772B000
heap
page read and write
4D50000
heap
page read and write
17897736000
heap
page read and write
4C7667F000
stack
page read and write
17897732000
heap
page read and write
D90000
heap
page read and write
1789772B000
heap
page read and write
1789772B000
heap
page read and write
1789772B000
heap
page read and write
17897740000
heap
page read and write
17897734000
heap
page read and write
1789772B000
heap
page read and write
11DF000
stack
page read and write
17897726000
heap
page read and write
DEE000
heap
page read and write
17897740000
heap
page read and write
1789772B000
heap
page read and write
17897732000
heap
page read and write
17897740000
heap
page read and write
1789772B000
heap
page read and write
17897740000
heap
page read and write
1789772B000
heap
page read and write
17897732000
heap
page read and write
1789772B000
heap
page read and write
17897726000
heap
page read and write
17897726000
heap
page read and write
17897734000
heap
page read and write
17897726000
heap
page read and write
7C30000
trusted library allocation
page read and write
17897734000
heap
page read and write
17897726000
heap
page read and write
17897734000
heap
page read and write
3055000
heap
page read and write
1789772B000
heap
page read and write
17897732000
heap
page read and write
17897727000
heap
page read and write
1789772B000
heap
page read and write
17897740000
heap
page read and write
1789772B000
heap
page read and write
17897732000
heap
page read and write
17897734000
heap
page read and write
17897732000
heap
page read and write
17897732000
heap
page read and write
1789772B000
heap
page read and write
17897734000
heap
page read and write
4C84000
trusted library allocation
page read and write
17897726000
heap
page read and write
972000
unkown
page readonly
17897734000
heap
page read and write
17897740000
heap
page read and write
1789772B000
heap
page read and write
4469000
trusted library allocation
page read and write
17899020000
heap
page read and write
17897727000
heap
page read and write
62C1000
trusted library allocation
page read and write
17897740000
heap
page read and write
17897732000
heap
page read and write
7B8E000
stack
page read and write
778E000
stack
page read and write
17897734000
heap
page read and write
17897732000
heap
page read and write
309E000
stack
page read and write
17897740000
heap
page read and write
17897732000
heap
page read and write
17897740000
heap
page read and write
17897740000
heap
page read and write
17897732000
heap
page read and write
17897734000
heap
page read and write
1789772B000
heap
page read and write
7BA0000
trusted library allocation
page read and write
17897734000
heap
page read and write
17897732000
heap
page read and write
17897740000
heap
page read and write
1789772B000
heap
page read and write
17897726000
heap
page read and write
17897732000
heap
page read and write
17897734000
heap
page read and write
1789772B000
heap
page read and write
2A20000
trusted library allocation
page read and write
17897740000
heap
page read and write
17897726000
heap
page read and write
17897734000
heap
page read and write
17897726000
heap
page read and write
1789772B000
heap
page read and write
4D30000
trusted library allocation
page read and write
782A000
heap
page read and write
1789772B000
heap
page read and write
17897734000
heap
page read and write
2A30000
trusted library allocation
page read and write
17897726000
heap
page read and write
4DDC000
stack
page read and write
17897734000
heap
page read and write
17897734000
heap
page read and write
62E9000
trusted library allocation
page read and write
17897734000
heap
page read and write
17897734000
heap
page read and write
17897740000
heap
page read and write
31F6000
heap
page read and write
17897740000
heap
page read and write
1789772B000
heap
page read and write
17897726000
heap
page read and write
2C1F000
stack
page read and write
17897734000
heap
page read and write
87AE000
stack
page read and write
17897732000
heap
page read and write
17897726000
heap
page read and write
2A3E000
stack
page read and write
8680000
trusted library allocation
page read and write
17897726000
heap
page read and write
17897734000
heap
page read and write
17897732000
heap
page read and write
1789772B000
heap
page read and write
17897732000
heap
page read and write
1789772B000
heap
page read and write
1789772B000
heap
page read and write
17897734000
heap
page read and write
17897726000
heap
page read and write
17897732000
heap
page read and write
970000
unkown
page readonly
17897734000
heap
page read and write
842E000
stack
page read and write
17897727000
heap
page read and write
17897726000
heap
page read and write
17897734000
heap
page read and write
17897732000
heap
page read and write
17897727000
heap
page read and write
17897734000
heap
page read and write
178976EB000
heap
page read and write
17897726000
heap
page read and write
17897734000
heap
page read and write
4C60000
trusted library allocation
page read and write
4DF0000
trusted library allocation
page read and write
3162000
heap
page read and write
34E6000
heap
page read and write
17897726000
heap
page read and write
17897740000
heap
page read and write
17897740000
heap
page read and write
17897732000
heap
page read and write
7C00000
trusted library allocation
page read and write
4C90000
trusted library allocation
page read and write
1789772B000
heap
page read and write
17897740000
heap
page read and write
17897726000
heap
page read and write
871F000
stack
page read and write
73BE000
stack
page read and write
2C46000
trusted library allocation
page read and write
17897726000
heap
page read and write
E20000
heap
page read and write
17897726000
heap
page read and write
1789772B000
heap
page read and write
17897732000
heap
page read and write
17897734000
heap
page read and write
17897734000
heap
page read and write
DA0000
heap
page read and write
2DF0000
heap
page read and write
1789772B000
heap
page read and write
17897740000
heap
page read and write
78A4000
trusted library allocation
page read and write
17897726000
heap
page read and write
17897732000
heap
page read and write
17897740000
heap
page read and write
17897726000
heap
page read and write
17897734000
heap
page read and write
17897734000
heap
page read and write
1789772B000
heap
page read and write
E7A000
heap
page read and write
17897732000
heap
page read and write
17897740000
heap
page read and write
7B5E000
stack
page read and write
E20000
heap
page read and write
17897726000
heap
page read and write
1789772B000
heap
page read and write
76EE000
stack
page read and write
784D000
heap
page read and write
17897726000
heap
page read and write
77AE000
stack
page read and write
1789772B000
heap
page read and write
17897740000
heap
page read and write
17897740000
heap
page read and write
472000
remote allocation
page execute and read and write
2A03000
trusted library allocation
page execute and read and write
10EF000
stack
page read and write
17897740000
heap
page read and write
1789772B000
heap
page read and write
17897740000
heap
page read and write
8640000
trusted library allocation
page execute and read and write
17897740000
heap
page read and write
1789772B000
heap
page read and write
17897734000
heap
page read and write
2C7F000
stack
page read and write
17897726000
heap
page read and write
1789772B000
heap
page read and write
1789772B000
heap
page read and write
52B0000
heap
page execute and read and write
17897726000
heap
page read and write
1789772B000
heap
page read and write
17897734000
heap
page read and write
17897740000
heap
page read and write
17897732000
heap
page read and write
1789772B000
heap
page read and write
1240000
trusted library allocation
page read and write
8730000
trusted library allocation
page execute and read and write
E22000
heap
page read and write
17897740000
heap
page read and write
17897732000
heap
page read and write
1789772B000
heap
page read and write
52BE000
stack
page read and write
17897740000
heap
page read and write
17897734000
heap
page read and write
1789772B000
heap
page read and write
17897726000
heap
page read and write
17897734000
heap
page read and write
1789772B000
heap
page read and write
17897732000
heap
page read and write
17897740000
heap
page read and write
86AE000
stack
page read and write
77B0000
heap
page read and write
17897734000
heap
page read and write
1789772B000
heap
page read and write
17897727000
heap
page read and write
17897726000
heap
page read and write
17897734000
heap
page read and write
17897734000
heap
page read and write
7B9D000
stack
page read and write
17897727000
heap
page read and write
2A50000
trusted library allocation
page read and write
17897740000
heap
page read and write
17897726000
heap
page read and write
17897732000
heap
page read and write
303E000
stack
page read and write
7E0E000
stack
page read and write
17897734000
heap
page read and write
17897732000
heap
page read and write
17897740000
heap
page read and write
17897734000
heap
page read and write
17897732000
heap
page read and write
17897726000
heap
page read and write
527E000
stack
page read and write
17897732000
heap
page read and write
1789772B000
heap
page read and write
17897734000
heap
page read and write
17897734000
heap
page read and write
78C0000
trusted library allocation
page read and write
743A000
stack
page read and write
17897726000
heap
page read and write
1789772B000
heap
page read and write
17897732000
heap
page read and write
1789772B000
heap
page read and write
17897727000
heap
page read and write
17897726000
heap
page read and write
17897732000
heap
page read and write
78F0000
trusted library allocation
page read and write
17897740000
heap
page read and write
5323000
trusted library allocation
page read and write
17897734000
heap
page read and write
17899075000
heap
page read and write
17897732000
heap
page read and write
1789772B000
heap
page read and write
632A000
trusted library allocation
page read and write
74FE000
stack
page read and write
17897732000
heap
page read and write
17897732000
heap
page read and write
17897740000
heap
page read and write
17897732000
heap
page read and write
1789772B000
heap
page read and write
1789772B000
heap
page read and write
17897726000
heap
page read and write
17897734000
heap
page read and write
DFF000
heap
page read and write
17897734000
heap
page read and write
1789772B000
heap
page read and write
4DE0000
trusted library allocation
page execute and read and write
4CB2000
trusted library allocation
page read and write
1789B1F0000
trusted library allocation
page read and write
1789772B000
heap
page read and write
1789772B000
heap
page read and write
E55000
heap
page read and write
1789772B000
heap
page read and write
17897732000
heap
page read and write
17897734000
heap
page read and write
17897734000
heap
page read and write
17897727000
heap
page read and write
17897726000
heap
page read and write
7BCE000
stack
page read and write
17897726000
heap
page read and write
17897740000
heap
page read and write
1789772B000
heap
page read and write
17897740000
heap
page read and write
1789772B000
heap
page read and write
17897732000
heap
page read and write
17897734000
heap
page read and write
4C77000
heap
page read and write
1789772B000
heap
page read and write
1789772B000
heap
page read and write
17897740000
heap
page read and write
17897726000
heap
page read and write
17899223000
heap
page read and write
7BE0000
trusted library allocation
page read and write
1789772B000
heap
page read and write
17897734000
heap
page read and write
17897734000
heap
page read and write
972000
unkown
page execute and read and write
2A04000
trusted library allocation
page read and write
17897734000
heap
page read and write
17897732000
heap
page read and write
17897734000
heap
page read and write
521F000
stack
page read and write
17897740000
heap
page read and write
17897726000
heap
page read and write
17897740000
heap
page read and write
7C50000
trusted library allocation
page read and write
17897726000
heap
page read and write
2C40000
trusted library allocation
page read and write
17897734000
heap
page read and write
17897734000
heap
page read and write
17897740000
heap
page read and write
17897740000
heap
page read and write
17897740000
heap
page read and write
17897732000
heap
page read and write
17897740000
heap
page read and write
72FD000
stack
page read and write
17897726000
heap
page read and write
10BE000
stack
page read and write
17897734000
heap
page read and write
17897740000
heap
page read and write
F80000
heap
page read and write
1789772B000
heap
page read and write
77FD000
heap
page read and write
17897732000
heap
page read and write
17897734000
heap
page read and write
17897734000
heap
page read and write
17897740000
heap
page read and write
17897726000
heap
page read and write
17897740000
heap
page read and write
747E000
stack
page read and write
1789772B000
heap
page read and write
7BB0000
trusted library allocation
page read and write
17897732000
heap
page read and write
17897732000
heap
page read and write
1789772B000
heap
page read and write
178976EA000
heap
page read and write
DE0000
heap
page read and write
1789772B000
heap
page read and write
17897740000
heap
page read and write
17897726000
heap
page read and write
17897726000
heap
page read and write
17897740000
heap
page read and write
4C80000
trusted library allocation
page read and write
17897732000
heap
page read and write
481000
remote allocation
page execute and read and write
17897740000
heap
page read and write
17897726000
heap
page read and write
17897727000
heap
page read and write
17897736000
heap
page read and write
17897734000
heap
page read and write
1789772B000
heap
page read and write
1789772B000
heap
page read and write
475000
remote allocation
page execute and read and write
4C4F000
stack
page read and write
2A2A000
trusted library allocation
page execute and read and write
1789772B000
heap
page read and write
2D0A000
trusted library allocation
page read and write
17897734000
heap
page read and write
897B000
stack
page read and write
17897732000
heap
page read and write
17897740000
heap
page read and write
7A50000
trusted library allocation
page read and write
17897734000
heap
page read and write
17897740000
heap
page read and write
17897732000
heap
page read and write
4BCE000
stack
page read and write
DA0000
heap
page read and write
353E000
stack
page read and write
2A9E000
stack
page read and write
17897740000
heap
page read and write
17897732000
heap
page read and write
17897732000
heap
page read and write
17897727000
heap
page read and write
776E000
stack
page read and write
1789772B000
heap
page read and write
17897740000
heap
page read and write
1789772B000
heap
page read and write
73FE000
stack
page read and write
17897740000
heap
page read and write
17897727000
heap
page read and write
17897732000
heap
page read and write
17897740000
heap
page read and write
17897740000
heap
page read and write
17897740000
heap
page read and write
E62000
heap
page read and write
1789772B000
heap
page read and write
17897726000
heap
page read and write
1789772B000
heap
page read and write
17897726000
heap
page read and write
1789772B000
heap
page read and write
17897732000
heap
page read and write
330E000
stack
page read and write
17897726000
heap
page read and write
17897740000
heap
page read and write
17897734000
heap
page read and write
17897732000
heap
page read and write
17897732000
heap
page read and write
1789772B000
heap
page read and write
1789772B000
heap
page read and write
17897732000
heap
page read and write
EE5000
heap
page read and write
1250000
heap
page read and write
17897740000
heap
page read and write
7A31000
trusted library allocation
page read and write
17897726000
heap
page read and write
17897732000
heap
page read and write
1789772B000
heap
page read and write
17897734000
heap
page read and write
17897734000
heap
page read and write
17897734000
heap
page read and write
52C0000
heap
page execute and read and write
17897740000
heap
page read and write
785B000
heap
page read and write
733B000
stack
page read and write
17897734000
heap
page read and write
17897732000
heap
page read and write
1789772B000
heap
page read and write
17897726000
heap
page read and write
17897732000
heap
page read and write
17897740000
heap
page read and write
17897734000
heap
page read and write
1220000
heap
page read and write
17899950000
heap
page read and write
7900000
trusted library allocation
page execute and read and write
1789772B000
heap
page read and write
1789772B000
heap
page read and write
17897726000
heap
page read and write
17897740000
heap
page read and write
17897740000
heap
page read and write
17897732000
heap
page read and write
17897726000
heap
page read and write
17897727000
heap
page read and write
17897740000
heap
page read and write
54C8000
trusted library allocation
page read and write
17897732000
heap
page read and write
17899220000
heap
page read and write
17897732000
heap
page read and write
1789772B000
heap
page read and write
17897727000
heap
page read and write
17897734000
heap
page read and write
17897732000
heap
page read and write
1789772B000
heap
page read and write
753B000
stack
page read and write
2AE0000
trusted library allocation
page execute and read and write
1789772B000
heap
page read and write
DEE000
stack
page read and write
17897732000
heap
page read and write
17897740000
heap
page read and write
1789772B000
heap
page read and write
17897740000
heap
page read and write
17897734000
heap
page read and write
2CBE000
trusted library allocation
page read and write
17897732000
heap
page read and write
89BD000
stack
page read and write
F90000
heap
page read and write
17897734000
heap
page read and write
17897732000
heap
page read and write
17897732000
heap
page read and write
17897726000
heap
page read and write
7A40000
trusted library allocation
page read and write
17897740000
heap
page read and write
78D0000
trusted library allocation
page read and write
4D20000
heap
page readonly
1789772B000
heap
page read and write
17897740000
heap
page read and write
17897734000
heap
page read and write
17897734000
heap
page read and write
2B3F000
stack
page read and write
17897740000
heap
page read and write
E2E000
heap
page read and write
17897732000
heap
page read and write
1789772B000
heap
page read and write
17897734000
heap
page read and write
2A0D000
trusted library allocation
page execute and read and write
17897740000
heap
page read and write
17897740000
heap
page read and write
17897734000
heap
page read and write
17897734000
heap
page read and write
17897727000
heap
page read and write
17897732000
heap
page read and write
1789772B000
heap
page read and write
17897732000
heap
page read and write
1789772B000
heap
page read and write
2D78000
stack
page read and write
17897734000
heap
page read and write
1789772B000
heap
page read and write
17897726000
heap
page read and write
17897726000
heap
page read and write
2A00000
trusted library allocation
page read and write
17897726000
heap
page read and write
7C60000
trusted library allocation
page read and write
17897726000
heap
page read and write
4B8D000
stack
page read and write
17897726000
heap
page read and write
17897740000
heap
page read and write
852E000
stack
page read and write
17897726000
heap
page read and write
17897734000
heap
page read and write
17897732000
heap
page read and write
4C8D000
trusted library allocation
page execute and read and write
1789772B000
heap
page read and write
74BA000
stack
page read and write
78C5000
trusted library allocation
page read and write
3040000
heap
page read and write
4D3A000
trusted library allocation
page read and write
17897727000
heap
page read and write
4C99000
trusted library allocation
page read and write
2AF0000
heap
page read and write
17897734000
heap
page read and write
1789772B000
heap
page read and write
17897732000
heap
page read and write
1789772B000
heap
page read and write
17897740000
heap
page read and write
17897727000
heap
page read and write
17897732000
heap
page read and write
7BD0000
trusted library allocation
page read and write
17897732000
heap
page read and write
17897734000
heap
page read and write
17897740000
heap
page read and write
17897726000
heap
page read and write
17897734000
heap
page read and write
178976B0000
heap
page read and write
17897734000
heap
page read and write
17897740000
heap
page read and write
866F000
stack
page read and write
1789772B000
heap
page read and write
17897732000
heap
page read and write
17897740000
heap
page read and write
D70000
heap
page read and write
17897740000
heap
page read and write
17897740000
heap
page read and write
17897740000
heap
page read and write
788E000
stack
page read and write
17897732000
heap
page read and write
1789772B000
heap
page read and write
17897740000
heap
page read and write
17897732000
heap
page read and write
1789772B000
heap
page read and write
78B6000
trusted library allocation
page read and write
1789772B000
heap
page read and write
7D0D000
stack
page read and write
17897740000
heap
page read and write
2C6B000
trusted library allocation
page read and write
17897726000
heap
page read and write
17897726000
heap
page read and write
856E000
stack
page read and write
7894000
trusted library allocation
page read and write
2B10000
heap
page read and write
1789772B000
heap
page read and write
17897734000
heap
page read and write
E14000
heap
page read and write
4B30000
heap
page read and write
17897734000
heap
page read and write
17897740000
heap
page read and write
17897734000
heap
page read and write
1789772B000
heap
page read and write
17897734000
heap
page read and write
17897732000
heap
page read and write
782D000
heap
page read and write
17897732000
heap
page read and write
17897726000
heap
page read and write
2A10000
trusted library allocation
page read and write
17897732000
heap
page read and write
E7F000
heap
page read and write
17897740000
heap
page read and write
17897727000
heap
page read and write
DF0000
heap
page read and write
C3C000
stack
page read and write
17897660000
heap
page read and write
17897732000
heap
page read and write
17897732000
heap
page read and write
17897734000
heap
page read and write
17897740000
heap
page read and write
1789772B000
heap
page read and write
112E000
stack
page read and write
17897734000
heap
page read and write
315B000
heap
page read and write
17897732000
heap
page read and write
1789772B000
heap
page read and write
17897740000
heap
page read and write
There are 893 hidden memdumps, click here to show them.