Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
PO-FRE590164.xlsx
|
CDFV2 Encrypted
|
initial sample
|
||
C:\Program Files (x86)\SMTP Service\smtpsvc.exe
|
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\Vbb[1].exe
|
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
|
downloaded
|
||
C:\Users\user\AppData\Local\Temp\tmpD9BD.tmp
|
XML 1.0 document, ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Roaming\EA860E7A-A87F-4A88-92EF-38F744458171\run.dat
|
data
|
dropped
|
||
C:\Users\user\AppData\Roaming\TrXHdHpWh.exe
|
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\Desktop\~$PO-FRE590164.xlsx
|
data
|
dropped
|
||
C:\Users\Public\vbc.exe
|
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\6C03033E.jpeg
|
gd-jpeg v1.0 (using IJG JPEG v80), quality = 90", baseline, precision 8, 700x990, frames 3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\82CE75F1.jpeg
|
gd-jpeg v1.0 (using IJG JPEG v80), quality = 90", baseline, precision 8, 700x990, frames 3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\F36B41B0.emf
|
Windows Enhanced Metafile (EMF) image data version 0x10000
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\tmp1334.tmp
|
XML 1.0 document, ASCII text, with CRLF line terminators
|
dropped
|
There are 2 hidden files, click here to show them.
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
|
'C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE' -Embedding
|
||
C:\Users\Public\vbc.exe
|
'C:\Users\Public\vbc.exe'
|
||
C:\Windows\SysWOW64\schtasks.exe
|
'C:\Windows\System32\schtasks.exe' /Create /TN 'Updates\TrXHdHpWh' /XML 'C:\Users\user\AppData\Local\Temp\tmpD9BD.tmp'
|
||
C:\Users\Public\vbc.exe
|
C:\Users\Public\vbc.exe
|
||
C:\Users\Public\vbc.exe
|
C:\Users\Public\vbc.exe
|
||
C:\Program Files (x86)\SMTP Service\smtpsvc.exe
|
'C:\Program Files (x86)\SMTP Service\smtpsvc.exe'
|
||
C:\Windows\SysWOW64\schtasks.exe
|
'C:\Windows\System32\schtasks.exe' /Create /TN 'Updates\TrXHdHpWh' /XML 'C:\Users\user\AppData\Local\Temp\tmp1334.tmp'
|
||
C:\Program Files (x86)\SMTP Service\smtpsvc.exe
|
C:\Program Files (x86)\SMTP Service\smtpsvc.exe
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://nop.myq-see.com/win/Vbb.exe
|
198.23.207.63
|
||
http://www.%s.comPA
|
unknown
|
||
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
|
unknown
|
||
http://www.day.com/dam/1.0
|
unknown
|
||
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
|
unknown
|
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
nop.myq-see.com
|
198.23.207.63
|
IPs
IP
|
Domain
|
Country
|
Active
|
Malicious
|
|
---|---|---|---|---|---|
127.0.0.1
|
unknown
|
unknown
|
unknown
|
||
127.0.0.1:4009
|
unknown
|
unknown
|
unknown
|
||
198.23.207.63
|
unknown
|
United States
|
unknown
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
7(5
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
MTTT
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
ReviewToken
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
F0C8E
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
VBAFiles
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
DefaultSheetR2L
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
UseSystemSeparators
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
ThousandsSeparator
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
DecimalSeparator
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
,/5
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
F5496
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
F6307
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Max Display
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 1
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Max Display
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 1
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 2
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 3
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 4
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 5
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 6
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 7
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 8
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 9
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 10
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 11
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 12
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 13
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 14
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 15
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 16
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 17
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 18
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 19
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 20
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 21
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
LastPurgeTime
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
1033
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
1033
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
EXCELFiles
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
ProductFiles
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_3082
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_3082
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_1036
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_1036
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_1033
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_1033
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_3082
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_3082
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_1036
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_1036
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_1033
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_1033
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
ProductFiles
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
ProductFiles
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
ProductFiles
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
ProductFiles
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
F5496
|
||
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
|
EquationEditorFilesIntl_1033
|
||
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
|
SavedLegacySettings
|
||
C:\Users\Public\vbc.exe
|
SMTP Service
|
There are 51 hidden registries, click here to show them.
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
2131000
|
unkown
|
page read and write
|
||
402000
|
unkown
|
page execute and read and write
|
||
3239000
|
unkown
|
page read and write
|
||
2164000
|
unkown
|
page read and write
|
||
367A000
|
unkown
|
page read and write
|
||
23C1000
|
unkown
|
page read and write
|
||
33EA000
|
unkown
|
page read and write
|
||
3139000
|
unkown
|
page read and write
|
||
402000
|
unkown
|
page execute and read and write
|
||
530000
|
unkown
|
page read and write
|
||
2400000
|
unkown
|
page read and write
|
||
2231000
|
unkown
|
page read and write
|
||
20B1000
|
unkown
|
page read and write
|
||
30F9000
|
unkown
|
page read and write
|
||
33C9000
|
unkown
|
page read and write
|
||
107BE000
|
unkown image
|
page readonly
|
||
23BE000
|
unkown
|
page read and write | page guard
|
||
218000
|
unkown
|
page read and write
|
||
8E1000
|
heap default
|
page read and write
|
||
107A8000
|
unkown image
|
page readonly
|
||
7EFDF000
|
unkown
|
page read and write
|
||
488000
|
unkown
|
page read and write
|
||
4CA0000
|
unkown
|
page read and write
|
||
476F000
|
unkown
|
page read and write
|
||
570000
|
heap private
|
page execute and read and write
|
||
3F0000
|
unkown
|
page read and write
|
||
150000
|
heap default
|
page read and write
|
||
207000
|
heap private
|
page read and write
|
||
510000
|
unkown
|
page read and write
|
||
530000
|
unkown
|
page read and write
|
||
172000
|
unkown
|
page read and write
|
||
57D0000
|
unkown
|
page read and write
|
||
8A0000
|
heap private
|
page execute and read and write
|
||
430000
|
heap private
|
page read and write
|
||
20A0000
|
unkown
|
page read and write
|
||
4840000
|
unkown
|
page read and write
|
||
19B000
|
unkown
|
page execute and read and write
|
||
922000
|
heap default
|
page read and write
|
||
3F0000
|
unkown
|
page read and write
|
||
3E0000
|
unkown
|
page read and write
|
||
570000
|
heap default
|
page read and write
|
||
2B0000
|
unkown
|
page execute and read and write
|
||
200000
|
heap private
|
page read and write
|
||
23F3000
|
unkown
|
page read and write
|
||
1F0000
|
unkown
|
page read and write
|
||
50E0000
|
unkown
|
page read and write
|
||
500000
|
heap private
|
page read and write
|
||
3E6000
|
unkown
|
page read and write
|
||
60CE000
|
unkown
|
page read and write | page guard
|
||
2194000
|
heap private
|
page read and write
|
||
16D000
|
unkown
|
page execute and read and write
|
||
AD0000
|
unkown
|
page readonly
|
||
626000
|
heap default
|
page read and write
|
||
670000
|
unkown
|
page read and write
|
||
48F0000
|
unkown
|
page readonly
|
||
107BE000
|
unkown image
|
page readonly
|
||
57D0000
|
unkown
|
page read and write
|
||
578E000
|
stack
|
page read and write
|
||
59E000
|
unkown
|
page read and write
|
||
6FC000
|
unkown
|
page read and write
|
||
1010E000
|
unkown image
|
page readonly
|
||
3F0000
|
unkown
|
page read and write
|
||
670000
|
unkown
|
page read and write
|
||
90B000
|
heap default
|
page read and write
|
||
530000
|
unkown
|
page read and write
|
||
10050000
|
unkown image
|
page readonly
|
||
2020000
|
unkown
|
page read and write
|
||
8F1000
|
heap default
|
page read and write
|
||
4CE000
|
unkown
|
page read and write
|
||
21C0000
|
heap private
|
page execute and read and write
|
||
8F0000
|
unkown
|
page readonly
|
||
4D10000
|
unkown
|
page read and write
|
||
88C000
|
heap default
|
page read and write
|
||
20A000
|
unkown
|
page read and write
|
||
107A8000
|
unkown image
|
page readonly
|
||
5E0000
|
heap default
|
page read and write
|
||
58DE000
|
unkown
|
page read and write
|
||
518F000
|
stack
|
page read and write
|
||
5A2000
|
heap private
|
page read and write
|
||
20A000
|
unkown
|
page execute and read and write
|
||
489F000
|
unkown
|
page read and write
|
||
3F6000
|
unkown
|
page read and write
|
||
107AB000
|
unkown image
|
page readonly
|
||
580000
|
heap private
|
page read and write
|
||
560000
|
unkown
|
page read and write
|
||
21B2000
|
heap private
|
page read and write
|
||
7B0000
|
unkown
|
page read and write
|
||
4840000
|
heap private
|
page read and write
|
||
5BDE000
|
unkown
|
page read and write
|
||
210000
|
unkown
|
page readonly
|
||
48E0000
|
heap private
|
page read and write
|
||
3E0000
|
unkown
|
page read and write
|
||
100FB000
|
unkown image
|
page readonly
|
||
5AA0000
|
unkown
|
page write copy
|
||
60CF000
|
unkown
|
page read and write
|
||
6F0000
|
unkown
|
page read and write
|
||
207000
|
unkown
|
page execute and read and write
|
||
4B0000
|
unkown
|
page read and write
|
||
4BE0000
|
unkown
|
page read and write
|
||
3C0000
|
unkown
|
page read and write
|
||
875000
|
heap private
|
page read and write
|
||
107AB000
|
unkown image
|
page readonly
|
||
450000
|
unkown
|
page read and write
|
||
5A0000
|
unkown
|
page read and write
|
||
4950000
|
unkown
|
page readonly
|
||
10702000
|
unkown image
|
page execute read
|
||
3F0000
|
unkown
|
page read and write
|
||
212F000
|
unkown
|
page read and write
|
||
250000
|
unkown
|
page read and write
|
||
100FB000
|
unkown image
|
page readonly
|
||
630000
|
unkown
|
page readonly
|
||
506F000
|
unkown
|
page read and write
|
||
4310000
|
unkown
|
page readonly
|
||
4D70000
|
heap private
|
page read and write
|
||
4A0000
|
heap default
|
page read and write
|
||
4D2D000
|
unkown
|
page read and write
|
||
5D0000
|
unkown
|
page read and write
|
||
5540000
|
unkown
|
page read and write
|
||
400000
|
unkown
|
page execute and read and write
|
||
520000
|
unkown
|
page readonly
|
||
3F0000
|
unkown
|
page read and write
|
||
FD000
|
unkown
|
page execute and read and write
|
||
46C0000
|
unkown
|
page readonly
|
||
43F0000
|
unkown
|
page readonly
|
||
5280000
|
unkown
|
page readonly
|
||
5F2E000
|
unkown
|
page read and write
|
||
3F0000
|
unkown
|
page read and write
|
||
5D0000
|
unkown
|
page read and write
|
||
510000
|
unkown
|
page read and write
|
||
2C8000
|
unkown
|
page read and write
|
||
107AB000
|
unkown image
|
page readonly
|
||
3231000
|
unkown
|
page read and write
|
||
3E8000
|
unkown
|
page read and write
|
||
5D0000
|
unkown
|
page read and write
|
||
554000
|
heap default
|
page read and write
|
||
7EFDF000
|
unkown
|
page read and write
|
||
4D4E000
|
stack
|
page read and write
|
||
250000
|
unkown
|
page read and write
|
||
81E000
|
unkown
|
page read and write
|
||
2E0000
|
unkown
|
page read and write
|
||
28A000
|
unkown
|
page execute and read and write
|
||
30B1000
|
unkown
|
page read and write
|
||
4932000
|
heap private
|
page read and write
|
||
130000
|
unkown
|
page read and write
|
||
620E000
|
unkown
|
page read and write
|
||
8E0000
|
heap private
|
page read and write
|
||
5A5000
|
unkown
|
page read and write
|
||
50C000
|
unkown
|
page read and write
|
||
7E0000
|
unkown
|
page readonly
|
||
460000
|
heap default
|
page read and write
|
||
107A8000
|
unkown image
|
page readonly
|
||
4A2E000
|
stack
|
page read and write
|
||
5CFE000
|
stack
|
page read and write
|
||
560000
|
unkown
|
page read and write
|
||
560000
|
unkown
|
page read and write
|
||
529000
|
heap private
|
page read and write
|
||
560000
|
unkown
|
page read and write
|
||
7F0000
|
unkown
|
page read and write
|
||
10052000
|
unkown image
|
page execute read
|
||
20B0000
|
unkown
|
page read and write
|
||
4F1E000
|
stack
|
page read and write
|
||
527C000
|
unkown
|
page read and write
|
||
91B000
|
heap default
|
page read and write
|
||
520000
|
unkown
|
page read and write
|
||
100F8000
|
unkown image
|
page readonly
|
||
720000
|
unkown
|
page read and write
|
||
5A0000
|
unkown
|
page read and write
|
||
4810000
|
unkown
|
page readonly
|
||
84E000
|
unkown
|
page read and write
|
||
2190000
|
heap private
|
page read and write
|
||
4AD000
|
heap default
|
page read and write
|
||
2030000
|
heap private
|
page read and write
|
||
1ED0000
|
unkown
|
page read and write
|
||
110000
|
unkown
|
page read and write
|
||
483C000
|
unkown
|
page read and write
|
||
570000
|
unkown
|
page read and write
|
||
107BE000
|
unkown image
|
page readonly
|
||
1010E000
|
unkown image
|
page readonly
|
||
4F80000
|
unkown
|
page read and write
|
||
520000
|
unkown
|
page read and write
|
||
56BE000
|
unkown
|
page read and write
|
||
10700000
|
unkown image
|
page readonly
|
||
511E000
|
unkown
|
page read and write
|
||
197000
|
unkown
|
page execute and read and write
|
||
F0000
|
heap private
|
page execute and read and write
|
||
422000
|
unkown
|
page execute and read and write
|
||
107BC000
|
unkown image
|
page readonly
|
||
847000
|
heap default
|
page read and write
|
||
4FE0000
|
unkown
|
page read and write
|
||
550000
|
unkown
|
page read and write
|
||
47E000
|
unkown
|
page read and write
|
||
467000
|
heap default
|
page read and write
|
||
890000
|
heap private
|
page read and write
|
||
3E0000
|
unkown
|
page read and write
|
||
80000
|
unkown
|
page readonly
|
||
574E000
|
unkown
|
page read and write
|
||
676000
|
unkown
|
page read and write
|
||
62B000
|
heap default
|
page read and write
|
||
740000
|
unkown
|
page readonly
|
||
560000
|
unkown
|
page read and write
|
||
690000
|
heap private
|
page read and write
|
||
10700000
|
unkown image
|
page readonly
|
||
550000
|
unkown
|
page read and write
|
||
2102000
|
unkown
|
page read and write
|
||
170000
|
unkown
|
page read and write
|
||
21B000
|
unkown
|
page execute and read and write
|
||
107A8000
|
unkown image
|
page readonly
|
||
2E0000
|
unkown
|
page read and write
|
||
1E4000
|
unkown
|
page read and write
|
||
10050000
|
unkown image
|
page readonly
|
||
5D0000
|
unkown
|
page read and write
|
||
565E000
|
unkown
|
page read and write
|
||
164000
|
unkown
|
page read and write
|
||
520000
|
unkown
|
page read and write
|
||
255000
|
unkown
|
page read and write
|
||
E0000
|
unkown
|
page read and write
|
||
47C0000
|
unkown
|
page read and write
|
||
530000
|
unkown
|
page read and write
|
||
1F0E000
|
unkown
|
page read and write
|
||
520000
|
unkown
|
page read and write
|
||
6A0000
|
unkown
|
page read and write
|
||
4FFE000
|
unkown
|
page read and write
|
||
3F0000
|
unkown
|
page execute and read and write
|
||
100F8000
|
unkown image
|
page readonly
|
||
880000
|
heap default
|
page read and write
|
||
23BF000
|
unkown
|
page read and write
|
||
622000
|
heap default
|
page read and write
|
||
3F5000
|
unkown
|
page read and write
|
||
10700000
|
unkown image
|
page readonly
|
||
22BE000
|
unkown
|
page read and write
|
||
1E3000
|
unkown
|
page execute and read and write
|
||
20A0000
|
unkown
|
page read and write
|
||
464F000
|
unkown
|
page read and write
|
||
270000
|
unkown
|
page readonly
|
||
100F8000
|
unkown image
|
page readonly
|
||
3930000
|
unkown
|
page read and write
|
||
23F5000
|
unkown
|
page read and write
|
||
88A000
|
heap default
|
page read and write
|
||
100F8000
|
unkown image
|
page readonly
|
||
550000
|
unkown
|
page read and write
|
||
7A0000
|
unkown
|
page read and write
|
||
80000
|
unkown
|
page readonly
|
||
540000
|
unkown
|
page readonly
|
||
20AF000
|
unkown
|
page read and write
|
||
520000
|
heap private
|
page read and write
|
||
510000
|
unkown
|
page read and write
|
||
1010E000
|
unkown image
|
page readonly
|
||
150000
|
heap private
|
page read and write
|
||
56C000
|
unkown
|
page read and write
|
||
410000
|
unkown
|
page read and write
|
||
100FB000
|
unkown image
|
page readonly
|
||
107BE000
|
unkown image
|
page readonly
|
||
7C0000
|
unkown
|
page readonly
|
||
678000
|
unkown
|
page read and write
|
||
7EFDF000
|
unkown
|
page read and write
|
||
3E0000
|
unkown
|
page read and write
|
||
50BE000
|
unkown
|
page read and write
|
||
10052000
|
unkown image
|
page execute read
|
||
5D7E000
|
unkown
|
page read and write
|
||
3E0000
|
unkown
|
page read and write
|
||
42CF000
|
stack
|
page read and write
|
||
5D0000
|
unkown
|
page read and write
|
||
4690000
|
unkown
|
page readonly
|
||
80000
|
unkown
|
page readonly
|
||
535000
|
unkown
|
page read and write
|
||
484000
|
heap default
|
page read and write
|
||
21F0000
|
heap private
|
page execute and read and write
|
||
3E0000
|
unkown
|
page read and write
|
||
13D000
|
unkown
|
page execute and read and write
|
||
107AB000
|
unkown image
|
page readonly
|
||
17D000
|
unkown
|
page execute and read and write
|
||
5E0000
|
unkown
|
page readonly
|
||
5540000
|
unkown
|
page read and write
|
||
4E50000
|
heap private
|
page execute and read and write
|
||
4FD000
|
unkown
|
page read and write
|
||
100000
|
unkown
|
page read and write
|
||
10700000
|
unkown image
|
page readonly
|
||
43C0000
|
unkown
|
page readonly
|
||
100000
|
unkown
|
page read and write
|
||
740000
|
unkown
|
page read and write
|
||
5A8E000
|
stack
|
page read and write
|
||
107BC000
|
unkown image
|
page readonly
|
||
207000
|
stack
|
page read and write
|
||
710000
|
heap private
|
page read and write
|
||
1F7D000
|
unkown
|
page read and write
|
||
57D000
|
heap default
|
page read and write
|
||
10700000
|
unkown image
|
page readonly
|
||
5E5E000
|
unkown
|
page read and write | page guard
|
||
F3000
|
unkown
|
page execute and read and write
|
||
1ED000
|
unkown
|
page execute and read and write
|
||
847000
|
heap default
|
page read and write
|
||
5C0000
|
unkown
|
page execute and read and write
|
||
540000
|
unkown
|
page read and write
|
||
710000
|
unkown
|
page read and write
|
||
53A000
|
heap default
|
page read and write
|
||
670000
|
unkown
|
page read and write
|
||
7F0000
|
unkown
|
page read and write
|
||
2010000
|
unkown
|
page read and write
|
||
530000
|
unkown
|
page read and write
|
||
10050000
|
unkown image
|
page readonly
|
||
5DE000
|
unkown
|
page read and write
|
||
680000
|
unkown
|
page read and write
|
||
4F50000
|
heap private
|
page read and write
|
||
5540000
|
unkown
|
page readonly
|
||
4C1E000
|
unkown
|
page read and write
|
||
5050000
|
unkown
|
page read and write
|
||
440000
|
unkown
|
page read and write
|
||
460000
|
heap private
|
page execute and read and write
|
||
4E20000
|
heap private
|
page execute and read and write
|
||
4C90000
|
heap private
|
page read and write
|
||
520000
|
unkown
|
page read and write
|
||
550000
|
unkown
|
page read and write
|
||
2D0000
|
unkown
|
page read and write
|
||
29B000
|
unkown
|
page execute and read and write
|
||
A60000
|
unkown
|
page readonly
|
||
47BC000
|
unkown
|
page read and write
|
||
A70000
|
unkown
|
page readonly
|
||
5100000
|
heap private
|
page read and write
|
||
91E000
|
heap default
|
page read and write
|
||
2010000
|
unkown
|
page read and write
|
||
638E000
|
unkown
|
page read and write
|
||
43ED000
|
stack
|
page read and write
|
||
2020000
|
unkown
|
page read and write
|
||
2000000
|
unkown
|
page read and write
|
||
33C1000
|
unkown
|
page read and write
|
||
1E0000
|
unkown
|
page execute and read and write
|
||
556000
|
unkown
|
page read and write
|
||
10052000
|
unkown image
|
page execute read
|
||
3B6000
|
unkown
|
page read and write
|
||
540000
|
unkown
|
page read and write
|
||
3E6000
|
unkown
|
page read and write
|
||
240000
|
unkown
|
page read and write
|
||
10700000
|
unkown image
|
page readonly
|
||
550000
|
unkown
|
page read and write
|
||
530000
|
unkown
|
page read and write
|
||
4C6D000
|
unkown
|
page read and write
|
||
1CA000
|
unkown
|
page read and write
|
||
21E2000
|
unkown
|
page read and write
|
||
536E000
|
stack
|
page read and write
|
||
107BC000
|
unkown image
|
page readonly
|
||
510000
|
unkown
|
page read and write
|
||
480000
|
unkown
|
page read and write
|
||
287000
|
unkown
|
page execute and read and write
|
||
417C000
|
unkown
|
page read and write
|
||
41EE000
|
unkown
|
page read and write
|
||
10702000
|
unkown image
|
page execute read
|
||
150000
|
unkown
|
page read and write
|
||
50DD000
|
unkown
|
page read and write
|
||
2070000
|
unkown
|
page readonly
|
||
10700000
|
unkown image
|
page readonly
|
||
123000
|
unkown
|
page execute and read and write
|
||
5150000
|
unkown
|
page readonly
|
||
610000
|
unkown
|
page read and write
|
||
8D0000
|
unkown
|
page read and write
|
||
2F0000
|
heap private
|
page read and write
|
||
40B0000
|
unkown
|
page readonly
|
||
540000
|
unkown
|
page read and write
|
||
597E000
|
stack
|
page read and write
|
||
3E0000
|
unkown
|
page read and write
|
||
10050000
|
unkown image
|
page readonly
|
||
10D000
|
unkown
|
page execute and read and write
|
||
21BF000
|
stack
|
page read and write
|
||
660000
|
unkown
|
page readonly
|
||
1FD000
|
unkown
|
page execute and read and write
|
||
14A000
|
unkown
|
page execute and read and write
|
||
525000
|
unkown
|
page read and write
|
||
107BE000
|
unkown image
|
page readonly
|
||
124000
|
unkown
|
page read and write
|
||
480000
|
unkown
|
page read and write
|
||
107BE000
|
unkown image
|
page readonly
|
||
4A0000
|
unkown
|
page read and write
|
||
8E0000
|
unkown
|
page readonly
|
||
7FE000
|
unkown
|
page read and write
|
||
5A0000
|
unkown
|
page read and write
|
||
5D2000
|
unkown
|
page read and write
|
||
280000
|
heap private
|
page execute and read and write
|
||
507F000
|
stack
|
page read and write
|
||
217000
|
unkown
|
page execute and read and write
|
||
107BC000
|
unkown image
|
page readonly
|
||
670000
|
unkown
|
page read and write
|
||
5D0000
|
unkown
|
page read and write
|
||
520000
|
unkown
|
page read and write
|
||
670000
|
unkown
|
page read and write
|
||
550000
|
unkown
|
page read and write
|
||
83E000
|
unkown
|
page read and write
|
||
20000
|
unkown
|
page read and write
|
||
840000
|
heap default
|
page read and write
|
||
800000
|
unkown
|
page readonly
|
||
720000
|
unkown
|
page readonly
|
||
3E0000
|
unkown
|
page read and write
|
||
187000
|
unkown
|
page execute and read and write
|
||
620000
|
unkown
|
page write copy
|
||
48A0000
|
unkown
|
page readonly
|
||
680000
|
unkown
|
page readonly
|
||
57CF000
|
stack
|
page read and write
|
||
2C0000
|
unkown
|
page read and write
|
||
8E9000
|
heap private
|
page read and write
|
||
5120000
|
heap private
|
page execute and read and write
|
||
670000
|
unkown
|
page read and write
|
||
2010000
|
unkown
|
page readonly
|
||
585E000
|
unkown
|
page read and write
|
||
107BC000
|
unkown image
|
page readonly
|
||
10700000
|
unkown image
|
page readonly
|
||
163000
|
unkown
|
page execute and read and write
|
||
214C000
|
unkown
|
page read and write
|
||
5C0000
|
unkown
|
page read and write
|
||
4914000
|
heap private
|
page read and write
|
||
4B60000
|
unkown
|
page read and write
|
||
260000
|
unkown
|
page readonly
|
||
670000
|
unkown
|
page read and write
|
||
400000
|
unkown
|
page read and write
|
||
670000
|
unkown
|
page read and write
|
||
57FE000
|
unkown
|
page read and write
|
||
76E000
|
unkown
|
page read and write
|
||
584000
|
heap private
|
page read and write
|
||
47FD000
|
unkown
|
page read and write
|
||
5540000
|
unkown
|
page read and write
|
||
548000
|
unkown
|
page read and write
|
||
550000
|
unkown
|
page read and write
|
||
10702000
|
unkown image
|
page execute read
|
||
3F0000
|
unkown
|
page read and write
|
||
30D9000
|
unkown
|
page read and write
|
||
530000
|
unkown
|
page read and write
|
||
10700000
|
unkown image
|
page readonly
|
||
4F20000
|
heap private
|
page execute and read and write
|
||
1F7000
|
unkown
|
page read and write
|
||
857000
|
heap private
|
page read and write
|
||
670000
|
unkown
|
page read and write
|
||
3131000
|
unkown
|
page read and write
|
||
540000
|
unkown
|
page read and write
|
||
556000
|
unkown
|
page read and write
|
||
3E0000
|
unkown
|
page read and write
|
||
3F8000
|
stack
|
page read and write
|
||
4540000
|
unkown
|
page readonly
|
||
23DD000
|
unkown
|
page read and write
|
||
16B000
|
unkown
|
page execute and read and write
|
||
2278000
|
unkown
|
page read and write
|
||
20000
|
unkown
|
page read and write
|
||
3D0000
|
unkown
|
page write copy
|
||
528E000
|
stack
|
page read and write
|
||
550000
|
unkown
|
page read and write
|
||
530000
|
unkown
|
page read and write
|
||
47E000
|
unkown
|
page read and write
|
||
550000
|
unkown
|
page read and write
|
||
167000
|
unkown
|
page execute and read and write
|
||
4910000
|
heap private
|
page read and write
|
||
600000
|
heap default
|
page read and write
|
||
520000
|
unkown
|
page read and write
|
||
557000
|
unkown
|
page read and write
|
||
1F0000
|
unkown
|
page read and write
|
||
10702000
|
unkown image
|
page execute read
|
||
1010C000
|
unkown image
|
page readonly
|
||
212E000
|
unkown
|
page read and write | page guard
|
||
107A8000
|
unkown image
|
page readonly
|
||
F0000
|
unkown
|
page read and write
|
||
1010C000
|
unkown image
|
page readonly
|
||
8D0000
|
unkown
|
page read and write
|
||
4A30000
|
unkown
|
page readonly
|
||
10050000
|
unkown image
|
page readonly
|
||
3E0000
|
unkown
|
page read and write
|
||
1010C000
|
unkown image
|
page readonly
|
||
730000
|
unkown
|
page read and write
|
||
5B70000
|
heap private
|
page read and write
|
||
10050000
|
unkown image
|
page readonly
|
||
5A0000
|
unkown
|
page read and write
|
||
530000
|
unkown
|
page read and write
|
||
4862000
|
heap private
|
page read and write
|
||
5B0000
|
heap private
|
page read and write
|
||
550000
|
unkown
|
page read and write
|
||
5E7000
|
heap default
|
page read and write
|
||
790000
|
unkown
|
page read and write
|
||
292000
|
unkown
|
page read and write
|
||
5B1E000
|
stack
|
page read and write
|
||
5AFD000
|
unkown
|
page read and write
|
||
550000
|
unkown
|
page read and write
|
||
840000
|
heap default
|
page read and write
|
||
6EE000
|
unkown
|
page read and write
|
||
18A000
|
unkown
|
page execute and read and write
|
||
7EFDF000
|
unkown
|
page read and write
|
||
530000
|
heap default
|
page read and write
|
||
562000
|
unkown
|
page read and write
|
||
680000
|
unkown
|
page read and write
|
||
453F000
|
stack
|
page read and write
|
||
2070000
|
unkown
|
page read and write
|
||
5290000
|
unkown
|
page readonly
|
||
5D0000
|
unkown
|
page read and write
|
||
537000
|
heap default
|
page read and write
|
||
1ED0000
|
unkown
|
page readonly
|
||
4A0000
|
unkown
|
page read and write
|
||
4880000
|
unkown
|
page readonly
|
||
226A000
|
unkown
|
page read and write
|
||
4F7E000
|
stack
|
page read and write
|
||
250000
|
unkown
|
page read and write
|
||
670000
|
unkown
|
page read and write
|
||
7D0000
|
unkown
|
page read and write
|
||
225000
|
heap private
|
page read and write
|
||
880000
|
heap default
|
page read and write
|
||
7BE000
|
unkown
|
page read and write
|
||
20000
|
unkown
|
page read and write
|
||
107BC000
|
unkown image
|
page readonly
|
||
107A8000
|
unkown image
|
page readonly
|
||
2664000
|
unkown
|
page read and write
|
||
4FDE000
|
stack
|
page read and write
|
||
750000
|
heap private
|
page execute and read and write
|
||
9B000
|
unkown
|
page read and write
|
||
568000
|
unkown
|
page read and write
|
||
3E0000
|
unkown
|
page read and write
|
||
66C000
|
unkown
|
page read and write
|
||
5D0000
|
unkown
|
page readonly
|
||
560000
|
unkown
|
page read and write
|
||
43DE000
|
stack
|
page read and write
|
||
4E4E000
|
unkown
|
page read and write
|
||
4820000
|
heap private
|
page read and write
|
||
102000
|
unkown
|
page read and write
|
||
F4000
|
unkown
|
page read and write
|
||
3E0000
|
unkown
|
page read and write
|
||
12A000
|
unkown
|
page read and write
|
||
607000
|
heap default
|
page read and write
|
||
88C000
|
heap default
|
page read and write
|
||
700000
|
unkown
|
page read and write
|
||
850000
|
heap private
|
page read and write
|
||
4844000
|
heap private
|
page read and write
|
||
1010C000
|
unkown image
|
page readonly
|
||
730000
|
unkown
|
page read and write
|
||
12D000
|
unkown
|
page execute and read and write
|
||
864000
|
heap default
|
page read and write
|
||
3F0000
|
unkown
|
page execute and read and write
|
||
1EE0000
|
unkown
|
page read and write
|
||
59EE000
|
stack
|
page read and write
|
||
864000
|
heap default
|
page read and write
|
||
4F3C000
|
unkown
|
page read and write
|
||
518E000
|
unkown
|
page read and write
|
||
420000
|
unkown
|
page read and write
|
||
360000
|
heap default
|
page read and write
|
||
5FBD000
|
stack
|
page read and write
|
||
609000
|
heap default
|
page read and write
|
||
326000
|
stack
|
page read and write
|
||
1D0000
|
unkown
|
page read and write
|
||
530000
|
unkown
|
page read and write
|
||
2270000
|
unkown
|
page read and write
|
||
5C0000
|
unkown
|
page read and write
|
||
6A0000
|
unkown
|
page read and write
|
||
20000
|
unkown
|
page read and write
|
||
520000
|
unkown
|
page read and write
|
||
5C2D000
|
stack
|
page read and write
|
||
5D2E000
|
stack
|
page read and write
|
||
5E5F000
|
unkown
|
page read and write
|
||
2250000
|
unkown
|
page read and write
|
||
430E000
|
unkown
|
page read and write
|
||
107AB000
|
unkown image
|
page readonly
|
||
2276000
|
unkown
|
page read and write
|
||
4DA0000
|
unkown
|
page readonly
|
||
1010E000
|
unkown image
|
page readonly
|
||
4CBD000
|
unkown
|
page read and write
|
||
1EF0000
|
unkown
|
page read and write
|
||
676000
|
unkown
|
page read and write
|
||
820000
|
unkown
|
page read and write
|
||
107AB000
|
unkown image
|
page readonly
|
||
57A000
|
heap default
|
page read and write
|
||
20AE000
|
unkown
|
page read and write | page guard
|
||
1FFD000
|
stack
|
page read and write
|
||
3F0000
|
unkown
|
page read and write
|
||
420000
|
unkown
|
page read and write
|
||
100FB000
|
unkown image
|
page readonly
|
||
5C0000
|
unkown
|
page read and write
|
||
192000
|
unkown
|
page read and write
|
||
250000
|
unkown
|
page read and write
|
||
670000
|
unkown
|
page read and write
|
||
297000
|
unkown
|
page execute and read and write
|
||
510000
|
unkown
|
page read and write
|
||
5F0000
|
unkown
|
page readonly
|
||
59E000
|
heap default
|
page read and write
|
||
10702000
|
unkown image
|
page execute read
|
||
212F000
|
unkown
|
page read and write
|
||
7C0000
|
unkown
|
page read and write
|
||
555000
|
unkown
|
page read and write
|
||
422000
|
unkown
|
page execute and read and write
|
||
540000
|
unkown
|
page read and write
|
||
8CB000
|
heap default
|
page read and write
|
||
400000
|
unkown
|
page execute and read and write
|
||
2200000
|
unkown
|
page readonly
|
||
162000
|
unkown
|
page read and write
|
||
3F0000
|
unkown
|
page read and write
|
||
57D0000
|
unkown
|
page read and write
|
||
586E000
|
unkown
|
page read and write
|
||
5C1D000
|
unkown
|
page read and write
|
||
146000
|
unkown
|
page execute and read and write
|
||
585D000
|
unkown
|
page read and write
|
||
4180000
|
unkown
|
page readonly
|
||
530000
|
unkown
|
page read and write
|
||
250000
|
unkown
|
page readonly
|
||
10702000
|
unkown image
|
page execute read
|
||
500B000
|
unkown
|
page read and write
|
||
648D000
|
unkown
|
page read and write
|
||
10052000
|
unkown image
|
page execute read
|
||
5A9D000
|
unkown
|
page read and write
|
||
8D0000
|
unkown
|
page read and write
|
There are 587 hidden memdumps, click here to show them.