IOCReport

loading gif

Files

File Path
Type
Category
Malicious
PO-FRE590164.xlsx
CDFV2 Encrypted
initial sample
malicious
C:\Program Files (x86)\SMTP Service\smtpsvc.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\Vbb[1].exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
downloaded
malicious
C:\Users\user\AppData\Local\Temp\tmpD9BD.tmp
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\EA860E7A-A87F-4A88-92EF-38F744458171\run.dat
data
dropped
malicious
C:\Users\user\AppData\Roaming\TrXHdHpWh.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\Desktop\~$PO-FRE590164.xlsx
data
dropped
malicious
C:\Users\Public\vbc.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\6C03033E.jpeg
gd-jpeg v1.0 (using IJG JPEG v80), quality = 90", baseline, precision 8, 700x990, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\82CE75F1.jpeg
gd-jpeg v1.0 (using IJG JPEG v80), quality = 90", baseline, precision 8, 700x990, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\F36B41B0.emf
Windows Enhanced Metafile (EMF) image data version 0x10000
dropped
clean
C:\Users\user\AppData\Local\Temp\tmp1334.tmp
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
clean
There are 2 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
'C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE' -Embedding
malicious
C:\Users\Public\vbc.exe
'C:\Users\Public\vbc.exe'
malicious
C:\Windows\SysWOW64\schtasks.exe
'C:\Windows\System32\schtasks.exe' /Create /TN 'Updates\TrXHdHpWh' /XML 'C:\Users\user\AppData\Local\Temp\tmpD9BD.tmp'
malicious
C:\Users\Public\vbc.exe
C:\Users\Public\vbc.exe
malicious
C:\Users\Public\vbc.exe
C:\Users\Public\vbc.exe
malicious
C:\Program Files (x86)\SMTP Service\smtpsvc.exe
'C:\Program Files (x86)\SMTP Service\smtpsvc.exe'
malicious
C:\Windows\SysWOW64\schtasks.exe
'C:\Windows\System32\schtasks.exe' /Create /TN 'Updates\TrXHdHpWh' /XML 'C:\Users\user\AppData\Local\Temp\tmp1334.tmp'
malicious
C:\Program Files (x86)\SMTP Service\smtpsvc.exe
C:\Program Files (x86)\SMTP Service\smtpsvc.exe
malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
clean

URLs

Name
IP
Malicious
http://nop.myq-see.com/win/Vbb.exe
198.23.207.63
clean
http://www.%s.comPA
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://www.day.com/dam/1.0
unknown
clean
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
unknown
clean

Domains

Name
IP
Malicious
nop.myq-see.com
198.23.207.63
clean

IPs

IP
Domain
Country
Active
Malicious
127.0.0.1
unknown
unknown
unknown
malicious
127.0.0.1:4009
unknown
unknown
unknown
malicious
198.23.207.63
unknown
United States
unknown
clean

Registry

Path
Value
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
7(5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
MTTT
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ReviewToken
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F0C8E
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
VBAFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DefaultSheetR2L
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
UseSystemSeparators
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ThousandsSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DecimalSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
,/5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F5496
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F6307
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 21
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
LastPurgeTime
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EXCELFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F5496
clean
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
EquationEditorFilesIntl_1033
clean
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
SavedLegacySettings
clean
C:\Users\Public\vbc.exe
SMTP Service
clean
There are 51 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
2131000
unkown
page read and write
malicious
402000
unkown
page execute and read and write
malicious
3239000
unkown
page read and write
malicious
2164000
unkown
page read and write
malicious
367A000
unkown
page read and write
malicious
23C1000
unkown
page read and write
malicious
33EA000
unkown
page read and write
malicious
3139000
unkown
page read and write
malicious
402000
unkown
page execute and read and write
malicious
530000
unkown
page read and write
malicious
2400000
unkown
page read and write
malicious
2231000
unkown
page read and write
malicious
20B1000
unkown
page read and write
malicious
30F9000
unkown
page read and write
malicious
33C9000
unkown
page read and write
malicious
107BE000
unkown image
page readonly
clean
23BE000
unkown
page read and write | page guard
clean
218000
unkown
page read and write
clean
8E1000
heap default
page read and write
clean
107A8000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
488000
unkown
page read and write
clean
4CA0000
unkown
page read and write
clean
476F000
unkown
page read and write
clean
570000
heap private
page execute and read and write
clean
3F0000
unkown
page read and write
clean
150000
heap default
page read and write
clean
207000
heap private
page read and write
clean
510000
unkown
page read and write
clean
530000
unkown
page read and write
clean
172000
unkown
page read and write
clean
57D0000
unkown
page read and write
clean
8A0000
heap private
page execute and read and write
clean
430000
heap private
page read and write
clean
20A0000
unkown
page read and write
clean
4840000
unkown
page read and write
clean
19B000
unkown
page execute and read and write
clean
922000
heap default
page read and write
clean
3F0000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
570000
heap default
page read and write
clean
2B0000
unkown
page execute and read and write
clean
200000
heap private
page read and write
clean
23F3000
unkown
page read and write
clean
1F0000
unkown
page read and write
clean
50E0000
unkown
page read and write
clean
500000
heap private
page read and write
clean
3E6000
unkown
page read and write
clean
60CE000
unkown
page read and write | page guard
clean
2194000
heap private
page read and write
clean
16D000
unkown
page execute and read and write
clean
AD0000
unkown
page readonly
clean
626000
heap default
page read and write
clean
670000
unkown
page read and write
clean
48F0000
unkown
page readonly
clean
107BE000
unkown image
page readonly
clean
57D0000
unkown
page read and write
clean
578E000
stack
page read and write
clean
59E000
unkown
page read and write
clean
6FC000
unkown
page read and write
clean
1010E000
unkown image
page readonly
clean
3F0000
unkown
page read and write
clean
670000
unkown
page read and write
clean
90B000
heap default
page read and write
clean
530000
unkown
page read and write
clean
10050000
unkown image
page readonly
clean
2020000
unkown
page read and write
clean
8F1000
heap default
page read and write
clean
4CE000
unkown
page read and write
clean
21C0000
heap private
page execute and read and write
clean
8F0000
unkown
page readonly
clean
4D10000
unkown
page read and write
clean
88C000
heap default
page read and write
clean
20A000
unkown
page read and write
clean
107A8000
unkown image
page readonly
clean
5E0000
heap default
page read and write
clean
58DE000
unkown
page read and write
clean
518F000
stack
page read and write
clean
5A2000
heap private
page read and write
clean
20A000
unkown
page execute and read and write
clean
489F000
unkown
page read and write
clean
3F6000
unkown
page read and write
clean
107AB000
unkown image
page readonly
clean
580000
heap private
page read and write
clean
560000
unkown
page read and write
clean
21B2000
heap private
page read and write
clean
7B0000
unkown
page read and write
clean
4840000
heap private
page read and write
clean
5BDE000
unkown
page read and write
clean
210000
unkown
page readonly
clean
48E0000
heap private
page read and write
clean
3E0000
unkown
page read and write
clean
100FB000
unkown image
page readonly
clean
5AA0000
unkown
page write copy
clean
60CF000
unkown
page read and write
clean
6F0000
unkown
page read and write
clean
207000
unkown
page execute and read and write
clean
4B0000
unkown
page read and write
clean
4BE0000
unkown
page read and write
clean
3C0000
unkown
page read and write
clean
875000
heap private
page read and write
clean
107AB000
unkown image
page readonly
clean
450000
unkown
page read and write
clean
5A0000
unkown
page read and write
clean
4950000
unkown
page readonly
clean
10702000
unkown image
page execute read
clean
3F0000
unkown
page read and write
clean
212F000
unkown
page read and write
clean
250000
unkown
page read and write
clean
100FB000
unkown image
page readonly
clean
630000
unkown
page readonly
clean
506F000
unkown
page read and write
clean
4310000
unkown
page readonly
clean
4D70000
heap private
page read and write
clean
4A0000
heap default
page read and write
clean
4D2D000
unkown
page read and write
clean
5D0000
unkown
page read and write
clean
5540000
unkown
page read and write
clean
400000
unkown
page execute and read and write
clean
520000
unkown
page readonly
clean
3F0000
unkown
page read and write
clean
FD000
unkown
page execute and read and write
clean
46C0000
unkown
page readonly
clean
43F0000
unkown
page readonly
clean
5280000
unkown
page readonly
clean
5F2E000
unkown
page read and write
clean
3F0000
unkown
page read and write
clean
5D0000
unkown
page read and write
clean
510000
unkown
page read and write
clean
2C8000
unkown
page read and write
clean
107AB000
unkown image
page readonly
clean
3231000
unkown
page read and write
clean
3E8000
unkown
page read and write
clean
5D0000
unkown
page read and write
clean
554000
heap default
page read and write
clean
7EFDF000
unkown
page read and write
clean
4D4E000
stack
page read and write
clean
250000
unkown
page read and write
clean
81E000
unkown
page read and write
clean
2E0000
unkown
page read and write
clean
28A000
unkown
page execute and read and write
clean
30B1000
unkown
page read and write
clean
4932000
heap private
page read and write
clean
130000
unkown
page read and write
clean
620E000
unkown
page read and write
clean
8E0000
heap private
page read and write
clean
5A5000
unkown
page read and write
clean
50C000
unkown
page read and write
clean
7E0000
unkown
page readonly
clean
460000
heap default
page read and write
clean
107A8000
unkown image
page readonly
clean
4A2E000
stack
page read and write
clean
5CFE000
stack
page read and write
clean
560000
unkown
page read and write
clean
560000
unkown
page read and write
clean
529000
heap private
page read and write
clean
560000
unkown
page read and write
clean
7F0000
unkown
page read and write
clean
10052000
unkown image
page execute read
clean
20B0000
unkown
page read and write
clean
4F1E000
stack
page read and write
clean
527C000
unkown
page read and write
clean
91B000
heap default
page read and write
clean
520000
unkown
page read and write
clean
100F8000
unkown image
page readonly
clean
720000
unkown
page read and write
clean
5A0000
unkown
page read and write
clean
4810000
unkown
page readonly
clean
84E000
unkown
page read and write
clean
2190000
heap private
page read and write
clean
4AD000
heap default
page read and write
clean
2030000
heap private
page read and write
clean
1ED0000
unkown
page read and write
clean
110000
unkown
page read and write
clean
483C000
unkown
page read and write
clean
570000
unkown
page read and write
clean
107BE000
unkown image
page readonly
clean
1010E000
unkown image
page readonly
clean
4F80000
unkown
page read and write
clean
520000
unkown
page read and write
clean
56BE000
unkown
page read and write
clean
10700000
unkown image
page readonly
clean
511E000
unkown
page read and write
clean
197000
unkown
page execute and read and write
clean
F0000
heap private
page execute and read and write
clean
422000
unkown
page execute and read and write
clean
107BC000
unkown image
page readonly
clean
847000
heap default
page read and write
clean
4FE0000
unkown
page read and write
clean
550000
unkown
page read and write
clean
47E000
unkown
page read and write
clean
467000
heap default
page read and write
clean
890000
heap private
page read and write
clean
3E0000
unkown
page read and write
clean
80000
unkown
page readonly
clean
574E000
unkown
page read and write
clean
676000
unkown
page read and write
clean
62B000
heap default
page read and write
clean
740000
unkown
page readonly
clean
560000
unkown
page read and write
clean
690000
heap private
page read and write
clean
10700000
unkown image
page readonly
clean
550000
unkown
page read and write
clean
2102000
unkown
page read and write
clean
170000
unkown
page read and write
clean
21B000
unkown
page execute and read and write
clean
107A8000
unkown image
page readonly
clean
2E0000
unkown
page read and write
clean
1E4000
unkown
page read and write
clean
10050000
unkown image
page readonly
clean
5D0000
unkown
page read and write
clean
565E000
unkown
page read and write
clean
164000
unkown
page read and write
clean
520000
unkown
page read and write
clean
255000
unkown
page read and write
clean
E0000
unkown
page read and write
clean
47C0000
unkown
page read and write
clean
530000
unkown
page read and write
clean
1F0E000
unkown
page read and write
clean
520000
unkown
page read and write
clean
6A0000
unkown
page read and write
clean
4FFE000
unkown
page read and write
clean
3F0000
unkown
page execute and read and write
clean
100F8000
unkown image
page readonly
clean
880000
heap default
page read and write
clean
23BF000
unkown
page read and write
clean
622000
heap default
page read and write
clean
3F5000
unkown
page read and write
clean
10700000
unkown image
page readonly
clean
22BE000
unkown
page read and write
clean
1E3000
unkown
page execute and read and write
clean
20A0000
unkown
page read and write
clean
464F000
unkown
page read and write
clean
270000
unkown
page readonly
clean
100F8000
unkown image
page readonly
clean
3930000
unkown
page read and write
clean
23F5000
unkown
page read and write
clean
88A000
heap default
page read and write
clean
100F8000
unkown image
page readonly
clean
550000
unkown
page read and write
clean
7A0000
unkown
page read and write
clean
80000
unkown
page readonly
clean
540000
unkown
page readonly
clean
20AF000
unkown
page read and write
clean
520000
heap private
page read and write
clean
510000
unkown
page read and write
clean
1010E000
unkown image
page readonly
clean
150000
heap private
page read and write
clean
56C000
unkown
page read and write
clean
410000
unkown
page read and write
clean
100FB000
unkown image
page readonly
clean
107BE000
unkown image
page readonly
clean
7C0000
unkown
page readonly
clean
678000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
50BE000
unkown
page read and write
clean
10052000
unkown image
page execute read
clean
5D7E000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
42CF000
stack
page read and write
clean
5D0000
unkown
page read and write
clean
4690000
unkown
page readonly
clean
80000
unkown
page readonly
clean
535000
unkown
page read and write
clean
484000
heap default
page read and write
clean
21F0000
heap private
page execute and read and write
clean
3E0000
unkown
page read and write
clean
13D000
unkown
page execute and read and write
clean
107AB000
unkown image
page readonly
clean
17D000
unkown
page execute and read and write
clean
5E0000
unkown
page readonly
clean
5540000
unkown
page read and write
clean
4E50000
heap private
page execute and read and write
clean
4FD000
unkown
page read and write
clean
100000
unkown
page read and write
clean
10700000
unkown image
page readonly
clean
43C0000
unkown
page readonly
clean
100000
unkown
page read and write
clean
740000
unkown
page read and write
clean
5A8E000
stack
page read and write
clean
107BC000
unkown image
page readonly
clean
207000
stack
page read and write
clean
710000
heap private
page read and write
clean
1F7D000
unkown
page read and write
clean
57D000
heap default
page read and write
clean
10700000
unkown image
page readonly
clean
5E5E000
unkown
page read and write | page guard
clean
F3000
unkown
page execute and read and write
clean
1ED000
unkown
page execute and read and write
clean
847000
heap default
page read and write
clean
5C0000
unkown
page execute and read and write
clean
540000
unkown
page read and write
clean
710000
unkown
page read and write
clean
53A000
heap default
page read and write
clean
670000
unkown
page read and write
clean
7F0000
unkown
page read and write
clean
2010000
unkown
page read and write
clean
530000
unkown
page read and write
clean
10050000
unkown image
page readonly
clean
5DE000
unkown
page read and write
clean
680000
unkown
page read and write
clean
4F50000
heap private
page read and write
clean
5540000
unkown
page readonly
clean
4C1E000
unkown
page read and write
clean
5050000
unkown
page read and write
clean
440000
unkown
page read and write
clean
460000
heap private
page execute and read and write
clean
4E20000
heap private
page execute and read and write
clean
4C90000
heap private
page read and write
clean
520000
unkown
page read and write
clean
550000
unkown
page read and write
clean
2D0000
unkown
page read and write
clean
29B000
unkown
page execute and read and write
clean
A60000
unkown
page readonly
clean
47BC000
unkown
page read and write
clean
A70000
unkown
page readonly
clean
5100000
heap private
page read and write
clean
91E000
heap default
page read and write
clean
2010000
unkown
page read and write
clean
638E000
unkown
page read and write
clean
43ED000
stack
page read and write
clean
2020000
unkown
page read and write
clean
2000000
unkown
page read and write
clean
33C1000
unkown
page read and write
clean
1E0000
unkown
page execute and read and write
clean
556000
unkown
page read and write
clean
10052000
unkown image
page execute read
clean
3B6000
unkown
page read and write
clean
540000
unkown
page read and write
clean
3E6000
unkown
page read and write
clean
240000
unkown
page read and write
clean
10700000
unkown image
page readonly
clean
550000
unkown
page read and write
clean
530000
unkown
page read and write
clean
4C6D000
unkown
page read and write
clean
1CA000
unkown
page read and write
clean
21E2000
unkown
page read and write
clean
536E000
stack
page read and write
clean
107BC000
unkown image
page readonly
clean
510000
unkown
page read and write
clean
480000
unkown
page read and write
clean
287000
unkown
page execute and read and write
clean
417C000
unkown
page read and write
clean
41EE000
unkown
page read and write
clean
10702000
unkown image
page execute read
clean
150000
unkown
page read and write
clean
50DD000
unkown
page read and write
clean
2070000
unkown
page readonly
clean
10700000
unkown image
page readonly
clean
123000
unkown
page execute and read and write
clean
5150000
unkown
page readonly
clean
610000
unkown
page read and write
clean
8D0000
unkown
page read and write
clean
2F0000
heap private
page read and write
clean
40B0000
unkown
page readonly
clean
540000
unkown
page read and write
clean
597E000
stack
page read and write
clean
3E0000
unkown
page read and write
clean
10050000
unkown image
page readonly
clean
10D000
unkown
page execute and read and write
clean
21BF000
stack
page read and write
clean
660000
unkown
page readonly
clean
1FD000
unkown
page execute and read and write
clean
14A000
unkown
page execute and read and write
clean
525000
unkown
page read and write
clean
107BE000
unkown image
page readonly
clean
124000
unkown
page read and write
clean
480000
unkown
page read and write
clean
107BE000
unkown image
page readonly
clean
4A0000
unkown
page read and write
clean
8E0000
unkown
page readonly
clean
7FE000
unkown
page read and write
clean
5A0000
unkown
page read and write
clean
5D2000
unkown
page read and write
clean
280000
heap private
page execute and read and write
clean
507F000
stack
page read and write
clean
217000
unkown
page execute and read and write
clean
107BC000
unkown image
page readonly
clean
670000
unkown
page read and write
clean
5D0000
unkown
page read and write
clean
520000
unkown
page read and write
clean
670000
unkown
page read and write
clean
550000
unkown
page read and write
clean
83E000
unkown
page read and write
clean
20000
unkown
page read and write
clean
840000
heap default
page read and write
clean
800000
unkown
page readonly
clean
720000
unkown
page readonly
clean
3E0000
unkown
page read and write
clean
187000
unkown
page execute and read and write
clean
620000
unkown
page write copy
clean
48A0000
unkown
page readonly
clean
680000
unkown
page readonly
clean
57CF000
stack
page read and write
clean
2C0000
unkown
page read and write
clean
8E9000
heap private
page read and write
clean
5120000
heap private
page execute and read and write
clean
670000
unkown
page read and write
clean
2010000
unkown
page readonly
clean
585E000
unkown
page read and write
clean
107BC000
unkown image
page readonly
clean
10700000
unkown image
page readonly
clean
163000
unkown
page execute and read and write
clean
214C000
unkown
page read and write
clean
5C0000
unkown
page read and write
clean
4914000
heap private
page read and write
clean
4B60000
unkown
page read and write
clean
260000
unkown
page readonly
clean
670000
unkown
page read and write
clean
400000
unkown
page read and write
clean
670000
unkown
page read and write
clean
57FE000
unkown
page read and write
clean
76E000
unkown
page read and write
clean
584000
heap private
page read and write
clean
47FD000
unkown
page read and write
clean
5540000
unkown
page read and write
clean
548000
unkown
page read and write
clean
550000
unkown
page read and write
clean
10702000
unkown image
page execute read
clean
3F0000
unkown
page read and write
clean
30D9000
unkown
page read and write
clean
530000
unkown
page read and write
clean
10700000
unkown image
page readonly
clean
4F20000
heap private
page execute and read and write
clean
1F7000
unkown
page read and write
clean
857000
heap private
page read and write
clean
670000
unkown
page read and write
clean
3131000
unkown
page read and write
clean
540000
unkown
page read and write
clean
556000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
3F8000
stack
page read and write
clean
4540000
unkown
page readonly
clean
23DD000
unkown
page read and write
clean
16B000
unkown
page execute and read and write
clean
2278000
unkown
page read and write
clean
20000
unkown
page read and write
clean
3D0000
unkown
page write copy
clean
528E000
stack
page read and write
clean
550000
unkown
page read and write
clean
530000
unkown
page read and write
clean
47E000
unkown
page read and write
clean
550000
unkown
page read and write
clean
167000
unkown
page execute and read and write
clean
4910000
heap private
page read and write
clean
600000
heap default
page read and write
clean
520000
unkown
page read and write
clean
557000
unkown
page read and write
clean
1F0000
unkown
page read and write
clean
10702000
unkown image
page execute read
clean
1010C000
unkown image
page readonly
clean
212E000
unkown
page read and write | page guard
clean
107A8000
unkown image
page readonly
clean
F0000
unkown
page read and write
clean
1010C000
unkown image
page readonly
clean
8D0000
unkown
page read and write
clean
4A30000
unkown
page readonly
clean
10050000
unkown image
page readonly
clean
3E0000
unkown
page read and write
clean
1010C000
unkown image
page readonly
clean
730000
unkown
page read and write
clean
5B70000
heap private
page read and write
clean
10050000
unkown image
page readonly
clean
5A0000
unkown
page read and write
clean
530000
unkown
page read and write
clean
4862000
heap private
page read and write
clean
5B0000
heap private
page read and write
clean
550000
unkown
page read and write
clean
5E7000
heap default
page read and write
clean
790000
unkown
page read and write
clean
292000
unkown
page read and write
clean
5B1E000
stack
page read and write
clean
5AFD000
unkown
page read and write
clean
550000
unkown
page read and write
clean
840000
heap default
page read and write
clean
6EE000
unkown
page read and write
clean
18A000
unkown
page execute and read and write
clean
7EFDF000
unkown
page read and write
clean
530000
heap default
page read and write
clean
562000
unkown
page read and write
clean
680000
unkown
page read and write
clean
453F000
stack
page read and write
clean
2070000
unkown
page read and write
clean
5290000
unkown
page readonly
clean
5D0000
unkown
page read and write
clean
537000
heap default
page read and write
clean
1ED0000
unkown
page readonly
clean
4A0000
unkown
page read and write
clean
4880000
unkown
page readonly
clean
226A000
unkown
page read and write
clean
4F7E000
stack
page read and write
clean
250000
unkown
page read and write
clean
670000
unkown
page read and write
clean
7D0000
unkown
page read and write
clean
225000
heap private
page read and write
clean
880000
heap default
page read and write
clean
7BE000
unkown
page read and write
clean
20000
unkown
page read and write
clean
107BC000
unkown image
page readonly
clean
107A8000
unkown image
page readonly
clean
2664000
unkown
page read and write
clean
4FDE000
stack
page read and write
clean
750000
heap private
page execute and read and write
clean
9B000
unkown
page read and write
clean
568000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
66C000
unkown
page read and write
clean
5D0000
unkown
page readonly
clean
560000
unkown
page read and write
clean
43DE000
stack
page read and write
clean
4E4E000
unkown
page read and write
clean
4820000
heap private
page read and write
clean
102000
unkown
page read and write
clean
F4000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
12A000
unkown
page read and write
clean
607000
heap default
page read and write
clean
88C000
heap default
page read and write
clean
700000
unkown
page read and write
clean
850000
heap private
page read and write
clean
4844000
heap private
page read and write
clean
1010C000
unkown image
page readonly
clean
730000
unkown
page read and write
clean
12D000
unkown
page execute and read and write
clean
864000
heap default
page read and write
clean
3F0000
unkown
page execute and read and write
clean
1EE0000
unkown
page read and write
clean
59EE000
stack
page read and write
clean
864000
heap default
page read and write
clean
4F3C000
unkown
page read and write
clean
518E000
unkown
page read and write
clean
420000
unkown
page read and write
clean
360000
heap default
page read and write
clean
5FBD000
stack
page read and write
clean
609000
heap default
page read and write
clean
326000
stack
page read and write
clean
1D0000
unkown
page read and write
clean
530000
unkown
page read and write
clean
2270000
unkown
page read and write
clean
5C0000
unkown
page read and write
clean
6A0000
unkown
page read and write
clean
20000
unkown
page read and write
clean
520000
unkown
page read and write
clean
5C2D000
stack
page read and write
clean
5D2E000
stack
page read and write
clean
5E5F000
unkown
page read and write
clean
2250000
unkown
page read and write
clean
430E000
unkown
page read and write
clean
107AB000
unkown image
page readonly
clean
2276000
unkown
page read and write
clean
4DA0000
unkown
page readonly
clean
1010E000
unkown image
page readonly
clean
4CBD000
unkown
page read and write
clean
1EF0000
unkown
page read and write
clean
676000
unkown
page read and write
clean
820000
unkown
page read and write
clean
107AB000
unkown image
page readonly
clean
57A000
heap default
page read and write
clean
20AE000
unkown
page read and write | page guard
clean
1FFD000
stack
page read and write
clean
3F0000
unkown
page read and write
clean
420000
unkown
page read and write
clean
100FB000
unkown image
page readonly
clean
5C0000
unkown
page read and write
clean
192000
unkown
page read and write
clean
250000
unkown
page read and write
clean
670000
unkown
page read and write
clean
297000
unkown
page execute and read and write
clean
510000
unkown
page read and write
clean
5F0000
unkown
page readonly
clean
59E000
heap default
page read and write
clean
10702000
unkown image
page execute read
clean
212F000
unkown
page read and write
clean
7C0000
unkown
page read and write
clean
555000
unkown
page read and write
clean
422000
unkown
page execute and read and write
clean
540000
unkown
page read and write
clean
8CB000
heap default
page read and write
clean
400000
unkown
page execute and read and write
clean
2200000
unkown
page readonly
clean
162000
unkown
page read and write
clean
3F0000
unkown
page read and write
clean
57D0000
unkown
page read and write
clean
586E000
unkown
page read and write
clean
5C1D000
unkown
page read and write
clean
146000
unkown
page execute and read and write
clean
585D000
unkown
page read and write
clean
4180000
unkown
page readonly
clean
530000
unkown
page read and write
clean
250000
unkown
page readonly
clean
10702000
unkown image
page execute read
clean
500B000
unkown
page read and write
clean
648D000
unkown
page read and write
clean
10052000
unkown image
page execute read
clean
5A9D000
unkown
page read and write
clean
8D0000
unkown
page read and write
clean
There are 587 hidden memdumps, click here to show them.