IOCReport

loading gif

Files

File Path
Type
Category
Malicious
TACSAL.xlsx
CDFV2 Encrypted
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\winlog[1].exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
downloaded
malicious
C:\Users\user\Desktop\~$TACSAL.xlsx
data
dropped
malicious
C:\Users\Public\vbc.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\188B1E12.jpeg
gd-jpeg v1.0 (using IJG JPEG v80), quality = 90", baseline, precision 8, 700x990, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\9CCDB2EB.jpeg
gd-jpeg v1.0 (using IJG JPEG v80), quality = 90", baseline, precision 8, 700x990, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\E243FB15.emf
Windows Enhanced Metafile (EMF) image data version 0x10000
dropped
clean
C:\Users\user\AppData\Roaming\x2nas2ex.vh2\Chrome\Default\Cookies
SQLite 3.x database, last written using SQLite version 3032001
dropped
clean
C:\Users\user\AppData\Roaming\x2nas2ex.vh2\Firefox\Profiles\7xwghk55.default\cookies.sqlite
SQLite 3.x database, user version 7, last written using SQLite version 3017000
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
'C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE' -Embedding
malicious
C:\Users\Public\vbc.exe
'C:\Users\Public\vbc.exe'
malicious
C:\Users\Public\vbc.exe
C:\Users\Public\vbc.exe
malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
clean

URLs

Name
IP
Malicious
http://suresb1sndyintercont.dns.army/receipst/winlog.exe
103.153.76.181
malicious
https://FTlR0ss5usK.net
malicious
http://127.0.0.1:HTTP/1.1
unknown
clean
http://DynDns.comDynDNS
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://us2.smtp.mailhostbox.com
unknown
clean
http://www.day.com/dam/1.0
unknown
clean
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha
unknown
clean
http://smtp.migeulez.com
unknown
clean
http://GhlhtO.com
unknown
clean
https://api.ipify.org%GETMozilla/5.0
unknown
clean
http://www.%s.comPA
unknown
clean
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
unknown
clean
https://api.ipify.org%
unknown
clean
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip
unknown
clean
There are 5 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
suresb1sndyintercont.dns.army
103.153.76.181
malicious
smtp.migeulez.com
unknown
malicious
us2.smtp.mailhostbox.com
208.91.199.225
clean

IPs

IP
Domain
Country
Active
Malicious
208.91.198.143
unknown
United States
unknown
malicious
103.153.76.181
unknown
unknown
unknown
malicious
208.91.199.225
unknown
United States
unknown
clean

Registry

Path
Value
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
el5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
MTTT
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ReviewToken
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F0030
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
VBAFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DefaultSheetR2L
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
UseSystemSeparators
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ThousandsSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DecimalSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
mr5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F47F9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F5725
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 21
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
LastPurgeTime
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EXCELFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F47F9
clean
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
EquationEditorFilesIntl_1033
clean
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
SavedLegacySettings
clean
There are 50 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
23DA000
unkown
page read and write
malicious
2591000
unkown
page read and write
malicious
402000
unkown
page execute and read and write
malicious
23C1000
unkown
page read and write
malicious
2618000
unkown
page read and write
malicious
33C8000
unkown
page read and write
malicious
760000
unkown
page readonly
clean
5C7E000
unkown
page read and write
clean
6A0000
unkown
page read and write
clean
245000
unkown
page read and write
clean
6A0000
unkown
page read and write
clean
5B7E000
unkown
page read and write | page guard
clean
B70000
heap private
page execute and read and write
clean
1C0000
heap private
page execute and read and write
clean
192000
unkown
page read and write
clean
589000
unkown
page read and write
clean
601000
unkown
page read and write
clean
6B40000
heap private
page read and write
clean
600000
unkown
page read and write
clean
600000
unkown
page read and write
clean
6A0000
unkown
page read and write
clean
600000
unkown
page read and write
clean
670000
unkown
page read and write
clean
245000
unkown
page read and write
clean
600000
unkown
page read and write
clean
6DA000
heap default
page read and write
clean
3A8000
stack
page read and write
clean
604000
unkown
page read and write
clean
63BE000
unkown
page read and write
clean
600000
unkown
page read and write
clean
240000
unkown
page read and write
clean
580000
unkown
page read and write
clean
EA000
unkown
page read and write
clean
590000
unkown
page read and write
clean
245000
unkown
page read and write
clean
70A000
unkown
page read and write
clean
110000
unkown
page read and write
clean
600000
unkown
page read and write
clean
606000
unkown
page read and write
clean
695E000
unkown
page read and write
clean
644000
unkown
page read and write
clean
6742000
heap private
page read and write
clean
245000
unkown
page read and write
clean
C22000
unkown image
page execute read
clean
580000
unkown
page read and write
clean
163000
unkown
page execute and read and write
clean
6A0000
unkown
page read and write
clean
582000
unkown
page read and write
clean
215000
unkown
page read and write
clean
186000
unkown
page execute and read and write
clean
6B4000
heap default
page read and write
clean
460D000
unkown
page read and write
clean
585000
unkown
page read and write
clean
4AA5000
unkown
page read and write
clean
4ABF000
stack
page read and write
clean
4C0000
heap private
page read and write
clean
6A0000
unkown
page read and write
clean
240000
unkown
page read and write
clean
33C1000
unkown
page read and write
clean
5A0000
unkown
page read and write
clean
BF0000
unkown
page read and write
clean
4D0000
unkown
page read and write
clean
6A4000
unkown
page read and write
clean
4D0000
unkown
page read and write
clean
889000
unkown
page read and write
clean
680000
unkown
page read and write
clean
7D0000
unkown
page readonly
clean
14A000
unkown
page execute and read and write
clean
240000
unkown
page read and write
clean
6A0000
unkown
page read and write
clean
96E000
heap default
page read and write
clean
240000
unkown
page read and write
clean
4AC0000
unkown
page read and write
clean
590000
unkown
page read and write
clean
4D0000
unkown
page read and write
clean
26E4000
unkown
page read and write
clean
5B0000
unkown
page read and write
clean
23BF000
unkown
page read and write
clean
280000
heap private
page read and write
clean
AB0000
unkown
page read and write
clean
245000
unkown
page read and write
clean
6DAE000
unkown
page read and write
clean
5A0000
unkown
page read and write
clean
240000
unkown
page read and write
clean
157000
unkown
page execute and read and write
clean
164000
unkown
page read and write
clean
240000
unkown
page read and write
clean
290000
unkown
page readonly
clean
240000
unkown
page read and write
clean
580000
unkown
page read and write
clean
3ED000
unkown
page read and write
clean
248000
unkown
page read and write
clean
5B0000
unkown
page read and write
clean
600000
unkown
page read and write
clean
D10000
unkown image
page readonly
clean
4AE000
unkown
page read and write
clean
C22000
unkown image
page execute read
clean
170000
unkown
page read and write
clean
604000
unkown
page read and write
clean
6F0000
unkown
page read and write
clean
603000
unkown
page read and write
clean
240000
unkown
page read and write
clean
C20000
unkown image
page readonly
clean
C22000
unkown image
page execute read
clean
26D6000
unkown
page read and write
clean
473E000
unkown
page read and write
clean
3A7000
unkown
page read and write
clean
211000
unkown
page read and write
clean
44B4000
heap private
page read and write
clean
554F000
stack
page read and write
clean
240000
unkown
page read and write
clean
580000
unkown
page read and write
clean
245000
unkown
page read and write
clean
D10000
unkown image
page readonly
clean
C20000
unkown image
page readonly
clean
548D000
unkown
page read and write
clean
585000
unkown
page read and write
clean
8A4000
heap default
page read and write
clean
D10000
unkown image
page readonly
clean
601000
unkown
page read and write
clean
6A0000
unkown
page read and write
clean
240000
unkown
page read and write
clean
6DC000
heap default
page read and write
clean
A90000
unkown
page read and write
clean
600000
unkown
page read and write
clean
23EE000
unkown
page read and write
clean
870000
unkown
page read and write
clean
650000
unkown
page read and write
clean
4440000
unkown
page read and write
clean
5B4000
unkown
page read and write
clean
65CE000
unkown
page read and write
clean
5B0000
unkown
page read and write
clean
580000
unkown
page read and write
clean
5B0000
unkown
page read and write
clean
20000
unkown
page read and write
clean
6A0000
unkown
page read and write
clean
5060000
unkown
page read and write
clean
55F5000
heap private
page read and write
clean
EC0000
unkown
page readonly
clean
245000
unkown
page read and write
clean
58DD000
unkown
page read and write
clean
5A0000
unkown
page read and write
clean
600000
unkown
page read and write
clean
6A0000
unkown
page read and write
clean
600000
unkown
page read and write
clean
5612000
heap private
page read and write
clean
245000
unkown
page read and write
clean
4B0000
unkown
page read and write
clean
240000
unkown
page read and write
clean
860000
heap private
page read and write
clean
AD9000
heap private
page read and write
clean
ACE000
unkown
page read and write
clean
5A2000
unkown
page read and write
clean
6A0000
unkown
page read and write
clean
600000
unkown
page read and write
clean
580000
unkown
page read and write
clean
6A3000
unkown
page read and write
clean
600000
unkown
page read and write
clean
767000
unkown
page read and write
clean
56E0000
heap private
page read and write
clean
580000
unkown
page read and write
clean
600000
unkown
page read and write
clean
760000
unkown
page read and write
clean
590000
unkown
page read and write
clean
C20000
unkown image
page readonly
clean
C20000
unkown image
page readonly
clean
710000
unkown
page read and write
clean
4400000
heap private
page read and write
clean
5B0000
unkown
page read and write
clean
220000
unkown
page execute and read and write
clean
26C2000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
660000
unkown
page read and write
clean
5A0000
unkown
page read and write
clean
258F000
unkown
page read and write
clean
720000
heap private
page read and write
clean
248000
unkown
page read and write
clean
4C5C000
unkown
page read and write
clean
564F000
stack
page read and write
clean
600000
unkown
page read and write
clean
4C7D000
unkown
page read and write
clean
710000
unkown
page read and write
clean
580000
unkown
page readonly
clean
2729000
unkown
page read and write
clean
240000
unkown
page read and write
clean
585000
unkown
page read and write
clean
5B0000
unkown
page read and write
clean
6EE000
unkown
page read and write
clean
3591000
unkown
page read and write
clean
240000
unkown
page read and write
clean
280000
unkown
page readonly
clean
230000
heap private
page execute and read and write
clean
611000
unkown
page read and write
clean
245000
unkown
page read and write
clean
16D000
unkown
page execute and read and write
clean
13D000
unkown
page execute and read and write
clean
4C0E000
stack
page read and write
clean
4C22000
heap private
page read and write
clean
2400000
heap private
page read and write
clean
6F0000
unkown
page read and write
clean
4B0000
unkown
page read and write
clean
6A0000
unkown
page read and write
clean
245000
unkown
page read and write
clean
245000
unkown
page read and write
clean
5B0000
unkown
page read and write
clean
270000
unkown
page readonly
clean
5A1E000
stack
page read and write
clean
5B0000
unkown
page read and write
clean
4D80000
unkown
page readonly
clean
245000
unkown
page read and write
clean
5B5000
unkown
page read and write
clean
5A5000
unkown
page read and write
clean
4B0000
unkown
page read and write
clean
400000
unkown
page execute and read and write
clean
B00000
unkown
page readonly
clean
240000
unkown
page read and write
clean
760000
unkown
page read and write
clean
5B0000
unkown
page read and write
clean
580000
unkown
page read and write
clean
245000
unkown
page read and write
clean
5E0000
heap private
page read and write
clean
8A0000
heap private
page execute and read and write
clean
6F0000
unkown
page read and write
clean
20000
unkown
page read and write
clean
26FF000
unkown
page read and write
clean
601000
unkown
page read and write
clean
2A0000
unkown
page read and write
clean
5B0000
unkown
page read and write
clean
230000
unkown
page read and write
clean
240000
unkown
page read and write
clean
7D0000
unkown
page read and write
clean
600000
unkown
page read and write
clean
580000
unkown
page read and write
clean
980000
unkown
page readonly
clean
5B0000
unkown
page read and write
clean
197000
unkown
page execute and read and write
clean
5B0000
unkown
page read and write
clean
600000
unkown
page read and write
clean
5A0000
unkown
page read and write
clean
8C0000
heap default
page read and write
clean
245000
unkown
page read and write
clean
52B2000
unkown
page read and write
clean
5F0000
unkown
page read and write
clean
23BE000
unkown
page read and write | page guard
clean
5DEC000
unkown
page read and write
clean
5A0000
unkown
page read and write
clean
240000
unkown
page read and write
clean
7BF000
unkown
page read and write
clean
610000
unkown
page read and write
clean
4E70000
unkown
page readonly
clean
5B0000
unkown
page read and write
clean
270000
unkown
page read and write
clean
6D0000
heap default
page read and write
clean
4E0000
heap default
page read and write
clean
940000
heap default
page read and write
clean
580000
unkown
page read and write
clean
6A0000
unkown
page read and write
clean
245000
unkown
page read and write
clean
887000
heap default
page read and write
clean
5DF0000
unkown
page readonly
clean
580000
unkown
page read and write
clean
700000
unkown
page read and write
clean
240000
unkown
page read and write
clean
585000
unkown
page read and write
clean
4ACC000
unkown
page read and write
clean
133000
unkown
page read and write
clean
80000
unkown
page readonly
clean
6A0000
unkown
page read and write
clean
19B000
unkown
page execute and read and write
clean
5B0000
unkown
page read and write
clean
44AE000
unkown
page read and write
clean
44B0000
heap private
page read and write
clean
600000
unkown
page read and write
clean
5250000
unkown
page read and write
clean
620000
heap default
page read and write
clean
6A0000
unkown
page read and write
clean
600000
unkown
page read and write
clean
130000
unkown
page read and write
clean
585000
unkown
page read and write
clean
15B000
unkown
page execute and read and write
clean
3F0000
unkown
page execute and read and write
clean
580000
unkown
page read and write
clean
240000
unkown
page read and write
clean
4AC4000
unkown
page read and write
clean
195000
unkown
page execute and read and write
clean
66A000
unkown
page read and write
clean
63E000
unkown
page read and write
clean
4C00000
heap private
page read and write
clean
580000
unkown
page read and write
clean
840000
unkown
page execute and read and write
clean
4E6E000
unkown
page read and write
clean
BB0000
unkown
page readonly
clean
5B0000
unkown
page read and write
clean
7C7000
heap private
page read and write
clean
17D000
unkown
page execute and read and write
clean
55F0000
heap private
page read and write
clean
57BE000
stack
page read and write
clean
60A000
unkown
page read and write
clean
240000
unkown
page read and write
clean
6A0000
unkown
page read and write
clean
5BB000
unkown
page read and write
clean
585000
unkown
page read and write
clean
754000
heap default
page read and write
clean
240000
unkown
page read and write
clean
5A0000
unkown
page read and write
clean
A80000
unkown
page read and write
clean
4D3F000
unkown
page read and write
clean
600000
unkown
page read and write
clean
5C0000
heap private
page execute and read and write
clean
450000
unkown
page read and write
clean
6A7000
unkown
page read and write
clean
5A0000
unkown
page read and write
clean
180000
unkown
page read and write
clean
6F0000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
450000
unkown
page read and write
clean
5A0000
unkown
page read and write
clean
600000
unkown
page read and write
clean
610000
unkown
page read and write
clean
290000
unkown
page read and write
clean
600000
unkown
page read and write
clean
240000
unkown
page read and write
clean
123000
unkown
page execute and read and write
clean
270B000
unkown
page read and write
clean
19A000
unkown
page read and write
clean
580000
unkown
page read and write
clean
4A7C000
unkown
page read and write
clean
979000
heap default
page read and write
clean
240000
unkown
page read and write
clean
53DE000
unkown
page read and write
clean
245000
unkown
page read and write
clean
600000
unkown
page read and write
clean
580000
unkown
page read and write
clean
4640000
unkown
page readonly
clean
250000
unkown
page read and write
clean
8CD000
heap default
page read and write
clean
2670000
unkown
page read and write
clean
4910000
unkown
page read and write
clean
587E000
unkown
page read and write
clean
600000
unkown
page read and write
clean
4AA5000
unkown
page read and write
clean
770000
unkown
page read and write
clean
5B0000
unkown
page read and write
clean
585000
unkown
page read and write
clean
44D2000
heap private
page read and write
clean
A70000
unkown
page read and write
clean
245000
unkown
page read and write
clean
245000
unkown
page read and write
clean
240000
unkown
page read and write
clean
C22000
unkown image
page execute read
clean
240000
unkown
page read and write
clean
C20000
unkown image
page readonly
clean
AA0000
unkown
page read and write
clean
590000
unkown
page read and write
clean
580000
unkown
page read and write
clean
26D0000
unkown
page read and write
clean
B1D000
unkown
page read and write
clean
AD0000
heap private
page read and write
clean
4740000
unkown
page readonly
clean
6F0000
unkown
page read and write
clean
5A0000
unkown
page read and write
clean
600000
unkown
page read and write
clean
600000
unkown
page read and write
clean
746000
heap private
page read and write
clean
580000
unkown
page read and write
clean
53FE000
unkown
page read and write
clean
124000
unkown
page read and write
clean
524E000
stack
page read and write
clean
B10000
unkown
page readonly
clean
5A0000
unkown
page read and write
clean
2A0000
unkown
page read and write
clean
580000
unkown
page read and write
clean
2673000
unkown
page read and write
clean
152000
unkown
page read and write
clean
585000
unkown
page read and write
clean
245000
unkown
page read and write
clean
271E000
unkown
page read and write
clean
728000
heap private
page read and write
clean
580000
unkown
page read and write
clean
220000
unkown
page execute and read and write
clean
25E5000
unkown
page read and write
clean
6730000
heap private
page read and write
clean
80000
unkown
page read and write
clean
4C04000
heap private
page read and write
clean
52AE000
unkown
page read and write
clean
590000
unkown
page read and write
clean
5B0000
unkown
page read and write
clean
147000
unkown
page execute and read and write
clean
6F0000
unkown
page read and write
clean
585000
unkown
page read and write
clean
245000
unkown
page read and write
clean
136000
unkown
page read and write
clean
5B0000
unkown
page read and write
clean
580000
unkown
page read and write
clean
5251000
unkown
page read and write
clean
240000
unkown
page read and write
clean
245000
unkown
page read and write
clean
580000
unkown
page read and write
clean
5A0000
unkown
page read and write
clean
245000
unkown
page read and write
clean
880000
unkown
page read and write
clean
240000
unkown
page read and write
clean
4A70000
unkown
page read and write
clean
4A6E000
unkown
page read and write
clean
580000
unkown
page read and write
clean
240000
unkown
page read and write
clean
790000
unkown
page readonly
clean
600000
unkown
page read and write
clean
240000
unkown
page read and write
clean
710000
unkown
page read and write
clean
601000
unkown
page read and write
clean
600000
unkown
page read and write
clean
245000
unkown
page read and write
clean
3B8000
unkown
page read and write
clean
545E000
unkown
page read and write
clean
182000
unkown
page read and write
clean
890000
unkown
page read and write
clean
6A5000
unkown
page read and write
clean
C20000
unkown image
page readonly
clean
4A9E000
unkown
page read and write
clean
A0000
unkown
page read and write
clean
1D0000
heap private
page read and write
clean
850000
unkown
page read and write
clean
520000
unkown
page readonly
clean
585000
unkown
page read and write
clean
240000
unkown
page read and write
clean
600000
unkown
page read and write
clean
5A0D000
unkown
page read and write
clean
245000
unkown
page read and write
clean
600000
unkown
page read and write
clean
26CC000
unkown
page read and write
clean
24B000
unkown
page read and write
clean
D10000
unkown image
page readonly
clean
460000
unkown
page read and write
clean
610000
unkown
page read and write
clean
697000
heap default
page read and write
clean
F0000
unkown
page readonly
clean
600000
unkown
page read and write
clean
5A10000
unkown
page read and write
clean
4D70000
heap private
page read and write
clean
245000
unkown
page read and write
clean
47E000
unkown
page read and write
clean
610000
unkown
page read and write
clean
7C0000
heap private
page read and write
clean
585000
unkown
page read and write
clean
5A5000
unkown
page read and write
clean
600000
unkown
page read and write
clean
240000
unkown
page read and write
clean
580000
unkown
page read and write
clean
700000
unkown
page execute and read and write
clean
560000
unkown
page read and write
clean
240000
unkown
page read and write
clean
5AE000
unkown
page read and write
clean
51BE000
unkown
page read and write
clean
690000
heap default
page read and write
clean
5B7F000
unkown
page read and write
clean
4AA0000
unkown
page read and write
clean
5A0000
unkown
page readonly
clean
18A000
unkown
page execute and read and write
clean
523E000
unkown
page read and write
clean
250000
unkown
page read and write
clean
6F0000
unkown
page read and write
clean
8E0000
unkown
page readonly
clean
245000
unkown
page read and write
clean
210000
unkown
page read and write
clean
530000
unkown
page read and write
clean
580000
unkown
page read and write
clean
A60000
unkown
page readonly
clean
250000
unkown
page read and write
clean
2702000
unkown
page read and write
clean
585000
unkown
page read and write
clean
4C60000
unkown
page read and write
clean
26E8000
unkown
page read and write
clean
4B0000
unkown
page read and write
clean
26A9000
unkown
page read and write
clean
5470000
unkown
page read and write
clean
7E0000
unkown
page read and write
clean
463E000
stack
page read and write
clean
582000
unkown
page read and write
clean
5B0000
unkown
page read and write
clean
580000
unkown
page read and write
clean
585000
unkown
page read and write
clean
880000
heap default
page read and write
clean
621D000
unkown
page read and write
clean
B6E000
unkown
page read and write
clean
600000
unkown
page read and write
clean
64CE000
unkown
page read and write
clean
540000
heap private
page execute and read and write
clean
560000
unkown
page read and write
clean
12D000
unkown
page execute and read and write
clean
22C0000
unkown
page write copy
clean
2724000
unkown
page read and write
clean
5B0000
unkown
page read and write
clean
There are 483 hidden memdumps, click here to show them.