IOCReport

loading gif

Files

File Path
Type
Category
Malicious
DHL-Address.xlsx
Microsoft Excel 2007+
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\vbc[1].exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
downloaded
malicious
C:\Users\user\Desktop\~$DHL-Address.xlsx
data
dropped
malicious
C:\Users\Public\vbc.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Microsoft Cabinet archive data, 58936 bytes, 1 file
dropped
clean
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
data
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\102D7B51.jpeg
gd-jpeg v1.0 (using IJG JPEG v80), quality = 90", baseline, precision 8, 700x990, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\5B636490.emf
Windows Enhanced Metafile (EMF) image data version 0x10000
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\FC5A891E.jpeg
gd-jpeg v1.0 (using IJG JPEG v80), quality = 90", baseline, precision 8, 700x990, frames 3
dropped
clean
C:\Users\user\AppData\Local\Temp\CabCFB4.tmp
Microsoft Cabinet archive data, 58936 bytes, 1 file
dropped
clean
C:\Users\user\AppData\Local\Temp\TarCFB5.tmp
data
modified
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
'C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE' -Embedding
malicious
C:\Users\Public\vbc.exe
'C:\Users\Public\vbc.exe'
malicious
C:\Users\Public\vbc.exe
C:\Users\Public\vbc.exe
malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
clean

URLs

Name
IP
Malicious
http://globuserinessserverfiletransferprotocol.mangospot.net/csrss/vbc.exe
192.210.214.178
malicious
https://jUxNbkiTmoSYxyvoDh.net
malicious
http://127.0.0.1:HTTP/1.1
unknown
clean
http://fedir.comsign.co.il/crl/ComSignSecuredCA.crl0
unknown
clean
http://www.a-cert.at0E
unknown
clean
http://www.e-me.lv/repository0
unknown
clean
http://www.acabogacia.org/doc0
unknown
clean
http://crl.chambersign.org/chambersroot.crl0
unknown
clean
http://www.digsigtrust.com/DST_TRUST_CPS_v990701.html0
unknown
clean
http://www.certifikat.dk/repository0
unknown
clean
http://www.chambersign.org1
unknown
clean
http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl0
unknown
clean
http://www.diginotar.nl/cps/pkioverheid0
unknown
clean
http://www.pkioverheid.nl/policies/root-policy0
unknown
clean
http://crl.ssc.lt/root-c/cacrl.crl0
unknown
clean
https://www.certification.tn/cgi-bin/pub/crl/cacrl.crl0
unknown
clean
http://ca.disig.sk/ca/crl/ca_disig.crl0
unknown
clean
http://www.certplus.com/CRL/class3P.crl0
unknown
clean
http://repository.infonotary.com/cps/qcps.html0$
unknown
clean
http://www.post.trust.ie/reposit/cps.html0
unknown
clean
http://www.certplus.com/CRL/class2.crl0
unknown
clean
http://www.disig.sk/ca/crl/ca_disig.crl0
unknown
clean
http://ocsp.infonotary.com/responder.cgi0V
unknown
clean
http://www.sk.ee/cps/0
unknown
clean
https://www.certification.tn/cgi-bin/pub/crl/cacrl.crl0E
unknown
clean
https://api.ipify.org%
unknown
clean
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip
unknown
clean
http://servername/isapibackend.dll
unknown
clean
http://www.ssc.lt/cps03
unknown
clean
http://crt.sectigo.com/SectigoRSADomainValidationSecureServerCA.crt0#
unknown
clean
http://crl.oces.certifikat.dk/oces.crl0
unknown
clean
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha
unknown
clean
http://www.certicamara.com/dpc/0Z
unknown
clean
http://crl.pki.wellsfargo.com/wsprca.crl0
unknown
clean
http://www.dnie.es/dpc0
unknown
clean
http://www.rootca.or.kr/rca/cps.html0
unknown
clean
http://www.trustcenter.de/guidelines0
unknown
clean
http://pki-root.ecertpki.cl/CertEnroll/E-CERT%20ROOT%20CA.crl0
unknown
clean
http://certificates.starfieldtech.com/repository/1604
unknown
clean
http://smtp.privateemail.com
unknown
clean
http://www.entrust.net/CRL/Client1.crl0
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://www.disig.sk/ca0f
unknown
clean
http://www.sk.ee/juur/crl/0
unknown
clean
http://crl.chambersign.org/chambersignroot.crl0
unknown
clean
http://crl.xrampsecurity.com/XGCA.crl0
unknown
clean
http://www.quovadis.bm0
unknown
clean
http://crl.ssc.lt/root-a/cacrl.crl0
unknown
clean
http://www.firmaprofesional.com0
unknown
clean
https://www.netlock.net/docs
unknown
clean
http://www.trustcenter.de/crl/v2/tc_class_2_ca_II.crl
unknown
clean
http://crl.entrust.net/2048ca.crl0
unknown
clean
http://www.pki.admin.ch/policy/CPS_2_16_756_1_17_3_21_1.pdf0
unknown
clean
http://cps.chambersign.org/cps/publicnotaryroot.html0
unknown
clean
http://www.e-trust.be/CPS/QNcerts
unknown
clean
http://www.certicamara.com/certicamaraca.crl0
unknown
clean
http://fedir.comsign.co.il/crl/ComSignCA.crl0
unknown
clean
http://www.certificadodigital.com.br/repositorio/serasaca/crl/SerasaCAI.crl0
unknown
clean
http://ocsp.sectigo.com0
unknown
clean
http://ocsp.entrust.net03
unknown
clean
http://cps.chambersign.org/cps/chambersroot.html0
unknown
clean
http://www.acabogacia.org0
unknown
clean
http://MLrjrg.com
unknown
clean
https://ca.sia.it/seccli/repository/CPS0
unknown
clean
http://fedir.comsign.co.il/cacert/ComSignAdvancedSecurityCA.crt0
unknown
clean
http://crl.securetrust.com/STCA.crl0
unknown
clean
http://www.certificadodigital.com.br/repositorio/serasaca/crl/SerasaCAIII.crl0
unknown
clean
http://www.certicamara.com/certicamaraca.crl0;
unknown
clean
http://www.e-szigno.hu/RootCA.crt0
unknown
clean
http://www.quovadisglobal.com/cps0
unknown
clean
http://www.valicert.com/1
unknown
clean
http://www.e-szigno.hu/SZSZ/0
unknown
clean
https://api.ipify.org%GETMozilla/5.0
unknown
clean
http://www.%s.comPA
unknown
clean
http://www.certificadodigital.com.br/repositorio/serasaca/crl/SerasaCAII.crl0
unknown
clean
https://ocsp.quovadisoffshore.com0
unknown
clean
http://ocsp.entrust.net0D
unknown
clean
http://cps.chambersign.org/cps/chambersignroot.html0
unknown
clean
http://DynDns.comDynDNS
unknown
clean
https://sectigo.com/CPS0
unknown
clean
http://crl.entrust.net/server1.crl0
unknown
clean
http://www.ancert.com/cps0
unknown
clean
http://ca.sia.it/seccli/repository/CRL.der0J
unknown
clean
https://rca.e-szigno.hu/ocsp0-
unknown
clean
https://www.netlock.hu/docs/
unknown
clean
http://www.a-cert.at/certificate-policy.html0;
unknown
clean
http://www.crc.bg0
unknown
clean
http://crl.chambersign.org/publicnotaryroot.crl0
unknown
clean
http://crl.pkioverheid.nl/DomOvLatestCRL.crl0
unknown
clean
http://www.informatik.admin.ch/PKI/links/CPS_2_16_756_1_17_3_1_0.pdf0
unknown
clean
http://www.a-cert.at/certificate-policy.html0
unknown
clean
https://secure.a-cert.at/cgi-bin/a-cert-advanced.cgi0
unknown
clean
http://fedir.comsign.co.il/crl/ComSignAdvancedSecurityCA.crl0
unknown
clean
http://www.e-certchile.cl/html/productos/download/CPSv1.7.pdf01
unknown
clean
http://www.wellsfargo.com/certpolicy0
unknown
clean
https://secure.comodo.com/CPS0
unknown
clean
http://www.comsign.co.il/cps0
unknown
clean
There are 87 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
globuserinessserverfiletransferprotocol.mangospot.net
192.210.214.178
malicious
smtp.privateemail.com
199.193.7.228
clean

IPs

IP
Domain
Country
Active
Malicious
192.210.214.178
unknown
United States
unknown
malicious
199.193.7.228
unknown
United States
unknown
clean

Registry

Path
Value
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
3o7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
MTTT
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ReviewToken
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EEB49
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
VBAFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DefaultSheetR2L
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
UseSystemSeparators
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ThousandsSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DecimalSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
#v7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F3469
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F46B1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 21
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
LastPurgeTime
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EXCELFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F3469
clean
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
EquationEditorFilesIntl_1033
clean
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
SavedLegacySettings
clean
C:\Users\Public\vbc.exe
Blob
clean
C:\Users\Public\vbc.exe
Blob
clean
C:\Users\Public\vbc.exe
Blob
clean
C:\Users\Public\vbc.exe
Blob
clean
C:\Users\Public\vbc.exe
Blob
clean
C:\Users\Public\vbc.exe
Blob
clean
There are 56 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
2511000
unkown
page read and write
malicious
402000
unkown
page execute and read and write
malicious
2511000
unkown
page read and write
malicious
259A000
unkown
page read and write
malicious
3519000
unkown
page read and write
malicious
17A000
unkown
page read and write
clean
3879000
unkown
page read and write
clean
340000
unkown
page read and write
clean
3881000
unkown
page read and write
clean
340000
unkown
page read and write
clean
C50000
unkown
page read and write
clean
880000
unkown
page read and write
clean
9C4000
unkown
page read and write
clean
6A20000
unkown
page read and write
clean
C30000
unkown
page read and write
clean
1100000
unkown image
page readonly
clean
890000
unkown
page read and write
clean
D26000
unkown
page read and write
clean
3888000
unkown
page read and write
clean
4FBD000
unkown
page read and write
clean
E2E000
unkown
page read and write
clean
337000
stack
page read and write
clean
5183000
unkown
page read and write
clean
584000
unkown
page read and write
clean
345000
unkown
page read and write
clean
890000
unkown
page read and write
clean
6A8E000
unkown
page read and write
clean
564E000
unkown
page read and write | page guard
clean
3881000
unkown
page read and write
clean
510000
heap default
page read and write
clean
3880000
unkown
page read and write
clean
585000
unkown
page read and write
clean
440000
unkown
page read and write
clean
580000
unkown
page read and write
clean
3886000
unkown
page read and write
clean
5101000
unkown
page read and write
clean
3894000
unkown
page read and write
clean
63DE000
unkown
page read and write
clean
5158000
unkown
page read and write
clean
C20000
unkown
page read and write
clean
440000
unkown
page read and write
clean
1100000
unkown image
page readonly
clean
49EE000
unkown
page read and write
clean
9B0000
unkown
page read and write
clean
860000
unkown
page readonly
clean
20000
unkown
page read and write
clean
3890000
unkown
page read and write
clean
50E000
unkown
page read and write
clean
585000
unkown
page read and write
clean
297000
unkown
page execute and read and write
clean
345000
unkown
page read and write
clean
3883000
unkown
page read and write
clean
D80000
unkown
page read and write
clean
580000
unkown
page read and write
clean
C40000
unkown
page read and write
clean
583000
unkown
page read and write
clean
3872000
unkown
page read and write
clean
528E000
unkown
page read and write
clean
9A1000
unkown
page read and write
clean
3893000
unkown
page read and write
clean
9A0000
unkown
page read and write
clean
1E0000
unkown
page read and write
clean
4EFF000
unkown
page read and write
clean
590000
unkown
page readonly
clean
5BCC000
unkown
page read and write
clean
3882000
unkown
page read and write
clean
2648000
unkown
page read and write
clean
48DF000
stack
page read and write
clean
340000
unkown
page read and write
clean
750000
unkown
page read and write
clean
880000
unkown
page read and write
clean
345000
unkown
page read and write
clean
580000
unkown
page read and write
clean
3897000
unkown
page read and write
clean
170000
unkown
page read and write
clean
387F000
unkown
page read and write
clean
2A83000
unkown
page read and write
clean
3F0000
unkown
page execute and read and write
clean
3876000
unkown
page read and write
clean
710000
unkown
page readonly
clean
388F000
unkown
page read and write
clean
880000
unkown
page read and write
clean
FDD000
unkown
page read and write
clean
585000
unkown
page read and write
clean
387C000
unkown
page read and write
clean
7FF000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
345000
unkown
page read and write
clean
19B000
unkown
page execute and read and write
clean
880000
unkown
page read and write
clean
DEE000
unkown
page read and write
clean
3C8000
heap private
page read and write
clean
D00000
unkown
page read and write
clean
6E50000
unkown
page readonly
clean
345000
unkown
page read and write
clean
880000
unkown
page read and write
clean
585000
unkown
page read and write
clean
5158000
unkown
page read and write
clean
123000
unkown
page execute and read and write
clean
1032000
unkown image
page execute read
clean
9B0000
unkown
page read and write
clean
348000
unkown
page read and write
clean
582000
unkown
page read and write
clean
230000
unkown
page read and write
clean
387C000
unkown
page read and write
clean
163000
unkown
page execute and read and write
clean
2567000
unkown
page read and write
clean
2609000
unkown
page read and write
clean
880000
unkown
page read and write
clean
2669000
unkown
page read and write
clean
3883000
unkown
page read and write
clean
D50000
heap private
page execute and read and write
clean
860000
unkown
page read and write
clean
210000
unkown
page read and write
clean
580000
unkown
page read and write
clean
4E2E000
unkown
page read and write
clean
890000
unkown
page read and write
clean
6A4B000
unkown
page read and write
clean
388B000
unkown
page read and write
clean
5183000
unkown
page read and write
clean
4F9D000
unkown
page read and write
clean
760000
heap default
page read and write
clean
B6B000
unkown
page read and write
clean
440000
unkown
page read and write
clean
80000
unkown
page readonly
clean
387D000
unkown
page read and write
clean
9A0000
unkown
page read and write
clean
DD0000
unkown
page readonly
clean
345000
unkown
page read and write
clean
589000
unkown
page read and write
clean
197000
unkown
page execute and read and write
clean
9AA000
unkown
page read and write
clean
580000
unkown
page read and write
clean
388D000
unkown
page read and write
clean
D00000
unkown
page read and write
clean
9B0000
unkown
page read and write
clean
50A0000
unkown
page read and write
clean
580000
unkown
page read and write
clean
B60000
unkown
page read and write
clean
590000
heap default
page read and write
clean
5158000
unkown
page read and write
clean
569E000
unkown
page read and write
clean
3882000
unkown
page read and write
clean
340000
unkown
page read and write
clean
3887000
unkown
page read and write
clean
62AE000
unkown
page read and write
clean
890000
unkown
page read and write
clean
580000
unkown
page read and write
clean
6AB4000
unkown
page read and write
clean
580000
unkown
page read and write
clean
729F000
unkown
page read and write
clean
264E000
unkown
page read and write
clean
54B8000
heap private
page read and write
clean
585000
unkown
page read and write
clean
B24000
heap private
page read and write
clean
345000
unkown
page read and write
clean
57FE000
stack
page read and write
clean
345000
unkown
page read and write
clean
3884000
unkown
page read and write
clean
3893000
unkown
page read and write
clean
880000
unkown
page read and write
clean
9B0000
unkown
page read and write
clean
340000
unkown
page read and write
clean
287000
unkown
page read and write
clean
200000
heap private
page read and write
clean
3888000
unkown
page read and write
clean
7AC000
heap default
page read and write
clean
580000
unkown
page read and write
clean
390000
unkown
page read and write
clean
295000
unkown
page execute and read and write
clean
1032000
unkown image
page execute read
clean
857000
heap default
page read and write
clean
C39000
unkown
page read and write
clean
1F0000
unkown
page read and write
clean
3895000
unkown
page read and write
clean
6A1F000
unkown
page read and write
clean
1032000
unkown image
page execute read
clean
340000
unkown
page read and write
clean
3C0000
heap private
page read and write
clean
2546000
unkown
page read and write
clean
54F0000
unkown
page read and write
clean
9A0000
unkown
page read and write
clean
585000
unkown
page read and write
clean
2676000
unkown
page read and write
clean
890000
unkown
page read and write
clean
387A000
unkown
page read and write
clean
760000
heap default
page read and write
clean
292000
unkown
page read and write
clean
F50000
heap private
page read and write
clean
345000
unkown
page read and write
clean
3879000
unkown
page read and write
clean
585000
unkown
page read and write
clean
390000
unkown
page read and write
clean
350000
unkown
page read and write
clean
F50000
unkown
page read and write
clean
110000
unkown
page read and write
clean
3883000
unkown
page read and write
clean
54D6000
heap private
page read and write
clean
164000
unkown
page read and write
clean
345000
unkown
page read and write
clean
675F000
unkown
page read and write
clean
6A96000
unkown
page read and write
clean
7A0000
heap default
page read and write
clean
340000
unkown
page read and write
clean
387D000
unkown
page read and write
clean
871000
unkown
page read and write
clean
A2E000
unkown
page read and write
clean
130000
unkown
page read and write
clean
340000
unkown
page read and write
clean
1030000
unkown image
page readonly
clean
17D000
unkown
page execute and read and write
clean
51EE000
unkown
page read and write | page guard
clean
D10000
unkown
page read and write
clean
4510000
unkown
page readonly
clean
C10000
unkown
page read and write
clean
450000
unkown
page read and write
clean
880000
unkown
page read and write
clean
460000
heap private
page execute and read and write
clean
13D000
unkown
page execute and read and write
clean
4E6E000
unkown
page read and write
clean
18A000
unkown
page execute and read and write
clean
3874000
unkown
page read and write
clean
580000
unkown
page read and write
clean
50CE000
stack
page read and write
clean
9A0000
unkown
page read and write
clean
E80000
unkown
page readonly
clean
3E0000
unkown
page read and write
clean
9C0000
unkown
page read and write
clean
54AE000
unkown
page read and write
clean
345000
unkown
page read and write
clean
3511000
unkown
page read and write
clean
9B0000
unkown
page read and write
clean
739000
heap private
page read and write
clean
880000
unkown
page read and write
clean
440000
unkown
page read and write
clean
124000
unkown
page read and write
clean
610000
unkown
page readonly
clean
3887000
unkown
page read and write
clean
50ED000
unkown
page read and write
clean
880000
unkown
page read and write
clean
9A0000
unkown
page read and write
clean
340000
unkown
page read and write
clean
580000
unkown
page read and write
clean
58D0000
heap private
page read and write
clean
340000
unkown
page read and write
clean
456E000
unkown
page read and write
clean
9A0000
unkown
page read and write
clean
663E000
unkown
page read and write
clean
3874000
unkown
page read and write
clean
340000
unkown
page read and write
clean
9A1000
unkown
page read and write
clean
880000
unkown
page read and write
clean
5169000
unkown
page read and write
clean
580000
unkown
page read and write
clean
3884000
unkown
page read and write
clean
9C0000
unkown
page read and write
clean
1020000
heap private
page read and write
clean
29B000
unkown
page execute and read and write
clean
4592000
heap private
page read and write
clean
2F0000
heap private
page execute and read and write
clean
6F0000
unkown
page read and write
clean
387F000
unkown
page read and write
clean
345000
unkown
page read and write
clean
9C0000
unkown
page read and write
clean
767000
heap default
page read and write
clean
210000
unkown
page read and write
clean
3885000
unkown
page read and write
clean
360000
heap private
page execute and read and write
clean
3876000
unkown
page read and write
clean
9A0000
unkown
page read and write
clean
4B0F000
unkown
page read and write
clean
880000
unkown
page read and write
clean
9D0000
heap private
page read and write
clean
C0000
unkown
page readonly
clean
754000
unkown
page read and write
clean
9A0000
unkown
page read and write
clean
890000
unkown
page read and write
clean
580000
unkown
page read and write
clean
440000
unkown
page read and write
clean
6A53000
unkown
page read and write
clean
186000
unkown
page execute and read and write
clean
6A76000
unkown
page read and write
clean
3872000
unkown
page read and write
clean
3878000
unkown
page read and write
clean
6F0000
unkown
page read and write
clean
580000
unkown
page read and write
clean
345000
unkown
page read and write
clean
4575000
heap private
page read and write
clean
585000
unkown
page read and write
clean
1D0000
unkown
page execute and read and write
clean
52F0000
unkown
page write copy
clean
340000
unkown
page read and write
clean
890000
unkown
page read and write
clean
340000
unkown
page read and write
clean
599F000
stack
page read and write
clean
D5E000
unkown
page read and write | page guard
clean
700000
heap private
page read and write
clean
890000
unkown
page read and write
clean
450000
unkown
page read and write
clean
890000
unkown
page read and write
clean
2D0000
unkown
page execute and read and write
clean
7F2000
heap default
page read and write
clean
9B0000
unkown
page read and write
clean
440000
unkown
page read and write
clean
388C000
unkown
page read and write
clean
390000
unkown
page read and write
clean
E40000
heap private
page read and write
clean
740000
unkown
page execute and read and write
clean
514E000
unkown
page read and write
clean
6F0000
unkown
page read and write
clean
387A000
unkown
page read and write
clean
2650000
unkown
page read and write
clean
387B000
unkown
page read and write
clean
345000
unkown
page read and write
clean
46CE000
unkown
page read and write
clean
580000
unkown
page read and write
clean
50D0000
unkown
page read and write
clean
4570000
heap private
page read and write
clean
585000
unkown
page read and write
clean
340000
unkown
page read and write
clean
890000
unkown
page read and write
clean
D30000
unkown
page read and write
clean
345000
unkown
page read and write
clean
340000
unkown
page read and write
clean
890000
unkown
page read and write
clean
340000
unkown
page read and write
clean
3885000
unkown
page read and write
clean
B20000
heap private
page read and write
clean
340000
unkown
page read and write
clean
3D0000
unkown
page readonly
clean
580000
unkown
page read and write
clean
3875000
unkown
page read and write
clean
3511000
unkown
page read and write
clean
890000
unkown
page execute and read and write
clean
1100000
unkown image
page readonly
clean
FE0000
heap private
page execute and read and write
clean
4E2E000
unkown
page read and write
clean
560000
unkown
page readonly
clean
585000
unkown
page read and write
clean
890000
unkown
page read and write
clean
387E000
unkown
page read and write
clean
51D0000
unkown
page read and write
clean
388E000
unkown
page read and write
clean
6F0000
unkown
page read and write
clean
9D7000
heap private
page read and write
clean
340000
unkown
page read and write
clean
12D000
unkown
page execute and read and write
clean
3B0000
unkown
page readonly
clean
740000
unkown
page read and write
clean
880000
unkown
page read and write
clean
3873000
unkown
page read and write
clean
9C0000
unkown
page read and write
clean
52CE000
unkown
page read and write
clean
880000
unkown
page read and write
clean
495C000
unkown
page read and write
clean
340000
unkown
page read and write
clean
3872000
unkown
page read and write
clean
340000
unkown
page read and write
clean
340000
unkown
page read and write
clean
2E0000
unkown
page read and write
clean
3892000
unkown
page read and write
clean
345000
unkown
page read and write
clean
340000
unkown
page read and write
clean
345000
unkown
page read and write
clean
6A6A000
unkown
page read and write
clean
6AA2000
unkown
page read and write
clean
340000
unkown
page read and write
clean
6D50000
unkown
page read and write
clean
720000
unkown
page read and write
clean
570000
unkown
page read and write
clean
345000
unkown
page read and write
clean
A30000
unkown
page readonly
clean
880000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
20000
unkown
page read and write
clean
885000
unkown
page read and write
clean
387A000
unkown
page read and write
clean
C4E000
unkown
page read and write
clean
450000
unkown
page read and write
clean
580000
unkown
page read and write
clean
4AB0000
unkown
page readonly
clean
340000
unkown
page execute and read and write
clean
340000
unkown
page read and write
clean
767000
heap default
page read and write
clean
6F0000
unkown
page read and write
clean
340000
unkown
page read and write
clean
388A000
unkown
page read and write
clean
880000
unkown
page read and write
clean
99E000
unkown
page read and write | page guard
clean
880000
unkown
page read and write
clean
180000
unkown
page read and write
clean
585000
unkown
page read and write
clean
885000
unkown
page read and write
clean
3877000
unkown
page read and write
clean
9A1000
unkown
page read and write
clean
389A000
unkown
page read and write
clean
6A9A000
unkown
page read and write
clean
345000
unkown
page read and write
clean
893000
unkown
page read and write
clean
3878000
unkown
page read and write
clean
340000
unkown
page read and write
clean
4E90000
unkown
page read and write
clean
345000
unkown
page read and write
clean
7A0000
heap default
page read and write
clean
580000
unkown
page read and write
clean
DCE000
unkown
page read and write
clean
440000
unkown
page read and write
clean
4AAF000
stack
page read and write
clean
387A000
unkown
page read and write
clean
7370000
unkown
page read and write
clean
340000
unkown
page read and write
clean
730000
heap private
page read and write
clean
3896000
unkown
page read and write
clean
B42000
heap private
page read and write
clean
450000
unkown
page read and write
clean
B10000
unkown
page read and write
clean
519D000
unkown
page read and write
clean
3877000
unkown
page read and write
clean
890000
unkown
page read and write
clean
886000
unkown
page read and write
clean
B80000
unkown
page read and write
clean
34B000
unkown
page read and write
clean
3884000
unkown
page read and write
clean
784000
heap default
page read and write
clean
1100000
unkown image
page readonly
clean
267A000
unkown
page read and write
clean
4E50000
heap private
page execute and read and write
clean
9B0000
unkown
page read and write
clean
585000
unkown
page read and write
clean
6F0000
unkown
page readonly
clean
2658000
unkown
page read and write
clean
6D4F000
unkown
page read and write
clean
3899000
unkown
page read and write
clean
720000
unkown
page read and write
clean
890000
unkown
page read and write
clean
6A21000
unkown
page read and write
clean
345000
unkown
page read and write
clean
3898000
unkown
page read and write
clean
D90000
unkown
page read and write
clean
59DD000
unkown
page read and write
clean
3889000
unkown
page read and write
clean
9E0000
unkown
page readonly
clean
6F0000
unkown
page read and write
clean
64A0000
heap private
page read and write
clean
5167000
unkown
page read and write
clean
1EE000
unkown
page read and write
clean
1030000
unkown image
page readonly
clean
580000
unkown
page read and write
clean
345000
unkown
page read and write
clean
689F000
unkown
page read and write
clean
6A6A000
unkown
page read and write
clean
890000
unkown
page read and write
clean
387C000
unkown
page read and write
clean
387E000
unkown
page read and write
clean
580000
unkown
page read and write
clean
514E000
unkown
page read and write
clean
C0C000
unkown
page read and write
clean
B60000
unkown
page readonly
clean
345000
unkown
page read and write
clean
D5F000
unkown
page read and write
clean
1032000
unkown image
page execute read
clean
582E000
unkown
page read and write
clean
350000
unkown
page read and write
clean
1030000
unkown image
page readonly
clean
747C000
unkown
page read and write
clean
589E000
unkown
page read and write
clean
3875000
unkown
page read and write
clean
345000
unkown
page read and write
clean
580000
unkown
page read and write
clean
D40000
unkown
page read and write
clean
882000
unkown
page read and write
clean
9C5000
unkown
page read and write
clean
580000
unkown
page read and write
clean
564F000
unkown
page read and write
clean
340000
unkown
page read and write
clean
340000
unkown
page read and write
clean
890000
unkown
page read and write
clean
580000
unkown
page read and write
clean
89B000
unkown
page read and write
clean
1030000
unkown image
page readonly
clean
340000
unkown
page read and write
clean
740000
unkown
page readonly
clean
580000
unkown
page read and write
clean
54B0000
heap private
page read and write
clean
F0000
unkown
page read and write
clean
580000
unkown
page read and write
clean
585000
unkown
page read and write
clean
18A000
unkown
page execute and read and write
clean
AA000
unkown
page read and write
clean
880000
unkown
page read and write
clean
51EF000
unkown
page read and write
clean
7AD000
heap default
page read and write
clean
1030000
unkown image
page readonly
clean
182000
unkown
page read and write
clean
538E000
unkown
page read and write
clean
5152000
unkown
page read and write
clean
580000
unkown
page execute and read and write
clean
387B000
unkown
page read and write
clean
784000
heap default
page read and write
clean
99F000
unkown
page read and write
clean
D60000
unkown
page read and write
clean
890000
unkown
page read and write
clean
5A8D000
unkown
page read and write
clean
4FA0000
unkown
page read and write
clean
B70000
unkown
page read and write
clean
580000
unkown
page read and write
clean
340000
unkown
page read and write
clean
860000
unkown
page read and write
clean
3887000
unkown
page read and write
clean
580000
unkown
page read and write
clean
1030000
unkown image
page readonly
clean
2C0000
unkown
page read and write
clean
400000
unkown
page execute and read and write
clean
4B10000
unkown
page readonly
clean
3876000
unkown
page read and write
clean
47E000
unkown
page read and write
clean
740000
unkown
page read and write
clean
387E000
unkown
page read and write
clean
890000
unkown
page read and write
clean
3891000
unkown
page read and write
clean
4D90000
unkown
page read and write
clean
3870000
unkown
page read and write
clean
D70000
unkown
page read and write
clean
FE0000
heap private
page read and write
clean
81D000
heap default
page read and write
clean
9C0000
unkown
page read and write
clean
3874000
unkown
page read and write
clean
860000
unkown
page read and write
clean
580000
unkown
page read and write
clean
3A8000
unkown
page read and write
clean
580000
unkown
page read and write
clean
345000
unkown
page read and write
clean
46D0000
unkown
page readonly
clean
210000
unkown
page read and write
clean
582000
unkown
page read and write
clean
9B0000
unkown
page read and write
clean
55C000
unkown
page read and write
clean
57AD000
unkown
page read and write
clean
3871000
unkown
page read and write
clean
D20000
unkown
page read and write
clean
580000
unkown
page read and write
clean
580000
unkown
page read and write
clean
9A0000
unkown
page read and write
clean
3873000
unkown
page read and write
clean
7C4000
heap default
page read and write
clean
585000
unkown
page read and write
clean
7AA000
heap default
page read and write
clean
F4D000
stack
page read and write
clean
D00000
unkown
page read and write
clean
348000
unkown
page read and write
clean
340000
unkown
page read and write
clean
580000
unkown
page read and write
clean
9A0000
unkown
page read and write
clean
704000
heap private
page read and write
clean
D00000
unkown
page read and write
clean
3881000
unkown
page read and write
clean
580000
unkown
page read and write
clean
5183000
unkown
page read and write
clean
38D000
unkown
page read and write
clean
3880000
unkown
page read and write
clean
440000
unkown
page read and write
clean
D4E000
unkown
page read and write
clean
3884000
unkown
page read and write
clean
614E000
unkown
page read and write
clean
388A000
unkown
page read and write
clean
150000
unkown
page read and write
clean
B90000
heap private
page read and write
clean
340000
unkown
page read and write
clean
880000
unkown
page read and write
clean
340000
unkown
page read and write
clean
345000
unkown
page read and write
clean
740000
unkown
page read and write
clean
3886000
unkown
page read and write
clean
5183000
unkown
page read and write
clean
5BD0000
unkown
page readonly
clean
16D000
unkown
page execute and read and write
clean
1110000
unkown
page readonly
clean
722000
heap private
page read and write
clean
4E91000
unkown
page read and write
clean
580000
unkown
page read and write
clean
890000
unkown
page read and write
clean
345000
unkown
page read and write
clean
6F0000
unkown
page read and write
clean
2607000
unkown
page read and write
clean
There are 574 hidden memdumps, click here to show them.