Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
TACSAL.xlsx
|
CDFV2 Encrypted
|
initial sample
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\winlog[1].exe
|
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
|
downloaded
|
||
C:\Users\user\Desktop\~$TACSAL.xlsx
|
data
|
dropped
|
||
C:\Users\Public\vbc.exe
|
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\188B1E12.jpeg
|
gd-jpeg v1.0 (using IJG JPEG v80), quality = 90", baseline, precision 8, 700x990, frames 3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\9CCDB2EB.jpeg
|
gd-jpeg v1.0 (using IJG JPEG v80), quality = 90", baseline, precision 8, 700x990, frames 3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\E243FB15.emf
|
Windows Enhanced Metafile (EMF) image data version 0x10000
|
dropped
|
||
C:\Users\user\AppData\Roaming\x2nas2ex.vh2\Chrome\Default\Cookies
|
SQLite 3.x database, last written using SQLite version 3032001
|
dropped
|
||
C:\Users\user\AppData\Roaming\x2nas2ex.vh2\Firefox\Profiles\7xwghk55.default\cookies.sqlite
|
SQLite 3.x database, user version 7, last written using SQLite version 3017000
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
|
'C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE' -Embedding
|
||
C:\Users\Public\vbc.exe
|
'C:\Users\Public\vbc.exe'
|
||
C:\Users\Public\vbc.exe
|
C:\Users\Public\vbc.exe
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://suresb1sndyintercont.dns.army/receipst/winlog.exe
|
103.153.76.181
|
||
https://FTlR0ss5usK.net
|
|||
http://127.0.0.1:HTTP/1.1
|
unknown
|
||
http://DynDns.comDynDNS
|
unknown
|
||
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
|
unknown
|
||
http://us2.smtp.mailhostbox.com
|
unknown
|
||
http://www.day.com/dam/1.0
|
unknown
|
||
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha
|
unknown
|
||
http://smtp.migeulez.com
|
unknown
|
||
http://GhlhtO.com
|
unknown
|
||
https://api.ipify.org%GETMozilla/5.0
|
unknown
|
||
http://www.%s.comPA
|
unknown
|
||
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
|
unknown
|
||
https://api.ipify.org%
|
unknown
|
||
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip
|
unknown
|
There are 5 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
suresb1sndyintercont.dns.army
|
103.153.76.181
|
||
smtp.migeulez.com
|
unknown
|
||
us2.smtp.mailhostbox.com
|
208.91.199.225
|
IPs
IP
|
Domain
|
Country
|
Active
|
Malicious
|
|
---|---|---|---|---|---|
208.91.198.143
|
unknown
|
United States
|
unknown
|
||
103.153.76.181
|
unknown
|
unknown
|
unknown
|
||
208.91.199.225
|
unknown
|
United States
|
unknown
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
el5
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
MTTT
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
ReviewToken
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
F0030
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
VBAFiles
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
DefaultSheetR2L
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
UseSystemSeparators
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
ThousandsSeparator
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
DecimalSeparator
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
mr5
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
F47F9
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
F5725
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Max Display
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 1
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Max Display
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 1
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 2
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 3
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 4
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 5
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 6
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 7
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 8
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 9
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 10
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 11
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 12
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 13
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 14
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 15
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 16
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 17
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 18
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 19
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 20
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 21
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
LastPurgeTime
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
1033
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
1033
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
EXCELFiles
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
ProductFiles
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_3082
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_3082
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_1036
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_1036
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_1033
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_1033
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_3082
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_3082
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_1036
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_1036
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_1033
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_1033
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
ProductFiles
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
ProductFiles
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
ProductFiles
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
ProductFiles
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
F47F9
|
||
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
|
EquationEditorFilesIntl_1033
|
||
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
|
SavedLegacySettings
|
There are 50 hidden registries, click here to show them.
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
23DA000
|
unkown
|
page read and write
|
||
2591000
|
unkown
|
page read and write
|
||
402000
|
unkown
|
page execute and read and write
|
||
23C1000
|
unkown
|
page read and write
|
||
2618000
|
unkown
|
page read and write
|
||
33C8000
|
unkown
|
page read and write
|
||
760000
|
unkown
|
page readonly
|
||
5C7E000
|
unkown
|
page read and write
|
||
6A0000
|
unkown
|
page read and write
|
||
245000
|
unkown
|
page read and write
|
||
6A0000
|
unkown
|
page read and write
|
||
5B7E000
|
unkown
|
page read and write | page guard
|
||
B70000
|
heap private
|
page execute and read and write
|
||
1C0000
|
heap private
|
page execute and read and write
|
||
192000
|
unkown
|
page read and write
|
||
589000
|
unkown
|
page read and write
|
||
601000
|
unkown
|
page read and write
|
||
6B40000
|
heap private
|
page read and write
|
||
600000
|
unkown
|
page read and write
|
||
600000
|
unkown
|
page read and write
|
||
6A0000
|
unkown
|
page read and write
|
||
600000
|
unkown
|
page read and write
|
||
670000
|
unkown
|
page read and write
|
||
245000
|
unkown
|
page read and write
|
||
600000
|
unkown
|
page read and write
|
||
6DA000
|
heap default
|
page read and write
|
||
3A8000
|
stack
|
page read and write
|
||
604000
|
unkown
|
page read and write
|
||
63BE000
|
unkown
|
page read and write
|
||
600000
|
unkown
|
page read and write
|
||
240000
|
unkown
|
page read and write
|
||
580000
|
unkown
|
page read and write
|
||
EA000
|
unkown
|
page read and write
|
||
590000
|
unkown
|
page read and write
|
||
245000
|
unkown
|
page read and write
|
||
70A000
|
unkown
|
page read and write
|
||
110000
|
unkown
|
page read and write
|
||
600000
|
unkown
|
page read and write
|
||
606000
|
unkown
|
page read and write
|
||
695E000
|
unkown
|
page read and write
|
||
644000
|
unkown
|
page read and write
|
||
6742000
|
heap private
|
page read and write
|
||
245000
|
unkown
|
page read and write
|
||
C22000
|
unkown image
|
page execute read
|
||
580000
|
unkown
|
page read and write
|
||
163000
|
unkown
|
page execute and read and write
|
||
6A0000
|
unkown
|
page read and write
|
||
582000
|
unkown
|
page read and write
|
||
215000
|
unkown
|
page read and write
|
||
186000
|
unkown
|
page execute and read and write
|
||
6B4000
|
heap default
|
page read and write
|
||
460D000
|
unkown
|
page read and write
|
||
585000
|
unkown
|
page read and write
|
||
4AA5000
|
unkown
|
page read and write
|
||
4ABF000
|
stack
|
page read and write
|
||
4C0000
|
heap private
|
page read and write
|
||
6A0000
|
unkown
|
page read and write
|
||
240000
|
unkown
|
page read and write
|
||
33C1000
|
unkown
|
page read and write
|
||
5A0000
|
unkown
|
page read and write
|
||
BF0000
|
unkown
|
page read and write
|
||
4D0000
|
unkown
|
page read and write
|
||
6A4000
|
unkown
|
page read and write
|
||
4D0000
|
unkown
|
page read and write
|
||
889000
|
unkown
|
page read and write
|
||
680000
|
unkown
|
page read and write
|
||
7D0000
|
unkown
|
page readonly
|
||
14A000
|
unkown
|
page execute and read and write
|
||
240000
|
unkown
|
page read and write
|
||
6A0000
|
unkown
|
page read and write
|
||
96E000
|
heap default
|
page read and write
|
||
240000
|
unkown
|
page read and write
|
||
4AC0000
|
unkown
|
page read and write
|
||
590000
|
unkown
|
page read and write
|
||
4D0000
|
unkown
|
page read and write
|
||
26E4000
|
unkown
|
page read and write
|
||
5B0000
|
unkown
|
page read and write
|
||
23BF000
|
unkown
|
page read and write
|
||
280000
|
heap private
|
page read and write
|
||
AB0000
|
unkown
|
page read and write
|
||
245000
|
unkown
|
page read and write
|
||
6DAE000
|
unkown
|
page read and write
|
||
5A0000
|
unkown
|
page read and write
|
||
240000
|
unkown
|
page read and write
|
||
157000
|
unkown
|
page execute and read and write
|
||
164000
|
unkown
|
page read and write
|
||
240000
|
unkown
|
page read and write
|
||
290000
|
unkown
|
page readonly
|
||
240000
|
unkown
|
page read and write
|
||
580000
|
unkown
|
page read and write
|
||
3ED000
|
unkown
|
page read and write
|
||
248000
|
unkown
|
page read and write
|
||
5B0000
|
unkown
|
page read and write
|
||
600000
|
unkown
|
page read and write
|
||
D10000
|
unkown image
|
page readonly
|
||
4AE000
|
unkown
|
page read and write
|
||
C22000
|
unkown image
|
page execute read
|
||
170000
|
unkown
|
page read and write
|
||
604000
|
unkown
|
page read and write
|
||
6F0000
|
unkown
|
page read and write
|
||
603000
|
unkown
|
page read and write
|
||
240000
|
unkown
|
page read and write
|
||
C20000
|
unkown image
|
page readonly
|
||
C22000
|
unkown image
|
page execute read
|
||
26D6000
|
unkown
|
page read and write
|
||
473E000
|
unkown
|
page read and write
|
||
3A7000
|
unkown
|
page read and write
|
||
211000
|
unkown
|
page read and write
|
||
44B4000
|
heap private
|
page read and write
|
||
554F000
|
stack
|
page read and write
|
||
240000
|
unkown
|
page read and write
|
||
580000
|
unkown
|
page read and write
|
||
245000
|
unkown
|
page read and write
|
||
D10000
|
unkown image
|
page readonly
|
||
C20000
|
unkown image
|
page readonly
|
||
548D000
|
unkown
|
page read and write
|
||
585000
|
unkown
|
page read and write
|
||
8A4000
|
heap default
|
page read and write
|
||
D10000
|
unkown image
|
page readonly
|
||
601000
|
unkown
|
page read and write
|
||
6A0000
|
unkown
|
page read and write
|
||
240000
|
unkown
|
page read and write
|
||
6DC000
|
heap default
|
page read and write
|
||
A90000
|
unkown
|
page read and write
|
||
600000
|
unkown
|
page read and write
|
||
23EE000
|
unkown
|
page read and write
|
||
870000
|
unkown
|
page read and write
|
||
650000
|
unkown
|
page read and write
|
||
4440000
|
unkown
|
page read and write
|
||
5B4000
|
unkown
|
page read and write
|
||
65CE000
|
unkown
|
page read and write
|
||
5B0000
|
unkown
|
page read and write
|
||
580000
|
unkown
|
page read and write
|
||
5B0000
|
unkown
|
page read and write
|
||
20000
|
unkown
|
page read and write
|
||
6A0000
|
unkown
|
page read and write
|
||
5060000
|
unkown
|
page read and write
|
||
55F5000
|
heap private
|
page read and write
|
||
EC0000
|
unkown
|
page readonly
|
||
245000
|
unkown
|
page read and write
|
||
58DD000
|
unkown
|
page read and write
|
||
5A0000
|
unkown
|
page read and write
|
||
600000
|
unkown
|
page read and write
|
||
6A0000
|
unkown
|
page read and write
|
||
600000
|
unkown
|
page read and write
|
||
5612000
|
heap private
|
page read and write
|
||
245000
|
unkown
|
page read and write
|
||
4B0000
|
unkown
|
page read and write
|
||
240000
|
unkown
|
page read and write
|
||
860000
|
heap private
|
page read and write
|
||
AD9000
|
heap private
|
page read and write
|
||
ACE000
|
unkown
|
page read and write
|
||
5A2000
|
unkown
|
page read and write
|
||
6A0000
|
unkown
|
page read and write
|
||
600000
|
unkown
|
page read and write
|
||
580000
|
unkown
|
page read and write
|
||
6A3000
|
unkown
|
page read and write
|
||
600000
|
unkown
|
page read and write
|
||
767000
|
unkown
|
page read and write
|
||
56E0000
|
heap private
|
page read and write
|
||
580000
|
unkown
|
page read and write
|
||
600000
|
unkown
|
page read and write
|
||
760000
|
unkown
|
page read and write
|
||
590000
|
unkown
|
page read and write
|
||
C20000
|
unkown image
|
page readonly
|
||
C20000
|
unkown image
|
page readonly
|
||
710000
|
unkown
|
page read and write
|
||
4400000
|
heap private
|
page read and write
|
||
5B0000
|
unkown
|
page read and write
|
||
220000
|
unkown
|
page execute and read and write
|
||
26C2000
|
unkown
|
page read and write
|
||
7EFDF000
|
unkown
|
page read and write
|
||
660000
|
unkown
|
page read and write
|
||
5A0000
|
unkown
|
page read and write
|
||
258F000
|
unkown
|
page read and write
|
||
720000
|
heap private
|
page read and write
|
||
248000
|
unkown
|
page read and write
|
||
4C5C000
|
unkown
|
page read and write
|
||
564F000
|
stack
|
page read and write
|
||
600000
|
unkown
|
page read and write
|
||
4C7D000
|
unkown
|
page read and write
|
||
710000
|
unkown
|
page read and write
|
||
580000
|
unkown
|
page readonly
|
||
2729000
|
unkown
|
page read and write
|
||
240000
|
unkown
|
page read and write
|
||
585000
|
unkown
|
page read and write
|
||
5B0000
|
unkown
|
page read and write
|
||
6EE000
|
unkown
|
page read and write
|
||
3591000
|
unkown
|
page read and write
|
||
240000
|
unkown
|
page read and write
|
||
280000
|
unkown
|
page readonly
|
||
230000
|
heap private
|
page execute and read and write
|
||
611000
|
unkown
|
page read and write
|
||
245000
|
unkown
|
page read and write
|
||
16D000
|
unkown
|
page execute and read and write
|
||
13D000
|
unkown
|
page execute and read and write
|
||
4C0E000
|
stack
|
page read and write
|
||
4C22000
|
heap private
|
page read and write
|
||
2400000
|
heap private
|
page read and write
|
||
6F0000
|
unkown
|
page read and write
|
||
4B0000
|
unkown
|
page read and write
|
||
6A0000
|
unkown
|
page read and write
|
||
245000
|
unkown
|
page read and write
|
||
245000
|
unkown
|
page read and write
|
||
5B0000
|
unkown
|
page read and write
|
||
270000
|
unkown
|
page readonly
|
||
5A1E000
|
stack
|
page read and write
|
||
5B0000
|
unkown
|
page read and write
|
||
4D80000
|
unkown
|
page readonly
|
||
245000
|
unkown
|
page read and write
|
||
5B5000
|
unkown
|
page read and write
|
||
5A5000
|
unkown
|
page read and write
|
||
4B0000
|
unkown
|
page read and write
|
||
400000
|
unkown
|
page execute and read and write
|
||
B00000
|
unkown
|
page readonly
|
||
240000
|
unkown
|
page read and write
|
||
760000
|
unkown
|
page read and write
|
||
5B0000
|
unkown
|
page read and write
|
||
580000
|
unkown
|
page read and write
|
||
245000
|
unkown
|
page read and write
|
||
5E0000
|
heap private
|
page read and write
|
||
8A0000
|
heap private
|
page execute and read and write
|
||
6F0000
|
unkown
|
page read and write
|
||
20000
|
unkown
|
page read and write
|
||
26FF000
|
unkown
|
page read and write
|
||
601000
|
unkown
|
page read and write
|
||
2A0000
|
unkown
|
page read and write
|
||
5B0000
|
unkown
|
page read and write
|
||
230000
|
unkown
|
page read and write
|
||
240000
|
unkown
|
page read and write
|
||
7D0000
|
unkown
|
page read and write
|
||
600000
|
unkown
|
page read and write
|
||
580000
|
unkown
|
page read and write
|
||
980000
|
unkown
|
page readonly
|
||
5B0000
|
unkown
|
page read and write
|
||
197000
|
unkown
|
page execute and read and write
|
||
5B0000
|
unkown
|
page read and write
|
||
600000
|
unkown
|
page read and write
|
||
5A0000
|
unkown
|
page read and write
|
||
8C0000
|
heap default
|
page read and write
|
||
245000
|
unkown
|
page read and write
|
||
52B2000
|
unkown
|
page read and write
|
||
5F0000
|
unkown
|
page read and write
|
||
23BE000
|
unkown
|
page read and write | page guard
|
||
5DEC000
|
unkown
|
page read and write
|
||
5A0000
|
unkown
|
page read and write
|
||
240000
|
unkown
|
page read and write
|
||
7BF000
|
unkown
|
page read and write
|
||
610000
|
unkown
|
page read and write
|
||
4E70000
|
unkown
|
page readonly
|
||
5B0000
|
unkown
|
page read and write
|
||
270000
|
unkown
|
page read and write
|
||
6D0000
|
heap default
|
page read and write
|
||
4E0000
|
heap default
|
page read and write
|
||
940000
|
heap default
|
page read and write
|
||
580000
|
unkown
|
page read and write
|
||
6A0000
|
unkown
|
page read and write
|
||
245000
|
unkown
|
page read and write
|
||
887000
|
heap default
|
page read and write
|
||
5DF0000
|
unkown
|
page readonly
|
||
580000
|
unkown
|
page read and write
|
||
700000
|
unkown
|
page read and write
|
||
240000
|
unkown
|
page read and write
|
||
585000
|
unkown
|
page read and write
|
||
4ACC000
|
unkown
|
page read and write
|
||
133000
|
unkown
|
page read and write
|
||
80000
|
unkown
|
page readonly
|
||
6A0000
|
unkown
|
page read and write
|
||
19B000
|
unkown
|
page execute and read and write
|
||
5B0000
|
unkown
|
page read and write
|
||
44AE000
|
unkown
|
page read and write
|
||
44B0000
|
heap private
|
page read and write
|
||
600000
|
unkown
|
page read and write
|
||
5250000
|
unkown
|
page read and write
|
||
620000
|
heap default
|
page read and write
|
||
6A0000
|
unkown
|
page read and write
|
||
600000
|
unkown
|
page read and write
|
||
130000
|
unkown
|
page read and write
|
||
585000
|
unkown
|
page read and write
|
||
15B000
|
unkown
|
page execute and read and write
|
||
3F0000
|
unkown
|
page execute and read and write
|
||
580000
|
unkown
|
page read and write
|
||
240000
|
unkown
|
page read and write
|
||
4AC4000
|
unkown
|
page read and write
|
||
195000
|
unkown
|
page execute and read and write
|
||
66A000
|
unkown
|
page read and write
|
||
63E000
|
unkown
|
page read and write
|
||
4C00000
|
heap private
|
page read and write
|
||
580000
|
unkown
|
page read and write
|
||
840000
|
unkown
|
page execute and read and write
|
||
4E6E000
|
unkown
|
page read and write
|
||
BB0000
|
unkown
|
page readonly
|
||
5B0000
|
unkown
|
page read and write
|
||
7C7000
|
heap private
|
page read and write
|
||
17D000
|
unkown
|
page execute and read and write
|
||
55F0000
|
heap private
|
page read and write
|
||
57BE000
|
stack
|
page read and write
|
||
60A000
|
unkown
|
page read and write
|
||
240000
|
unkown
|
page read and write
|
||
6A0000
|
unkown
|
page read and write
|
||
5BB000
|
unkown
|
page read and write
|
||
585000
|
unkown
|
page read and write
|
||
754000
|
heap default
|
page read and write
|
||
240000
|
unkown
|
page read and write
|
||
5A0000
|
unkown
|
page read and write
|
||
A80000
|
unkown
|
page read and write
|
||
4D3F000
|
unkown
|
page read and write
|
||
600000
|
unkown
|
page read and write
|
||
5C0000
|
heap private
|
page execute and read and write
|
||
450000
|
unkown
|
page read and write
|
||
6A7000
|
unkown
|
page read and write
|
||
5A0000
|
unkown
|
page read and write
|
||
180000
|
unkown
|
page read and write
|
||
6F0000
|
unkown
|
page read and write
|
||
7EFDF000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
5A0000
|
unkown
|
page read and write
|
||
600000
|
unkown
|
page read and write
|
||
610000
|
unkown
|
page read and write
|
||
290000
|
unkown
|
page read and write
|
||
600000
|
unkown
|
page read and write
|
||
240000
|
unkown
|
page read and write
|
||
123000
|
unkown
|
page execute and read and write
|
||
270B000
|
unkown
|
page read and write
|
||
19A000
|
unkown
|
page read and write
|
||
580000
|
unkown
|
page read and write
|
||
4A7C000
|
unkown
|
page read and write
|
||
979000
|
heap default
|
page read and write
|
||
240000
|
unkown
|
page read and write
|
||
53DE000
|
unkown
|
page read and write
|
||
245000
|
unkown
|
page read and write
|
||
600000
|
unkown
|
page read and write
|
||
580000
|
unkown
|
page read and write
|
||
4640000
|
unkown
|
page readonly
|
||
250000
|
unkown
|
page read and write
|
||
8CD000
|
heap default
|
page read and write
|
||
2670000
|
unkown
|
page read and write
|
||
4910000
|
unkown
|
page read and write
|
||
587E000
|
unkown
|
page read and write
|
||
600000
|
unkown
|
page read and write
|
||
4AA5000
|
unkown
|
page read and write
|
||
770000
|
unkown
|
page read and write
|
||
5B0000
|
unkown
|
page read and write
|
||
585000
|
unkown
|
page read and write
|
||
44D2000
|
heap private
|
page read and write
|
||
A70000
|
unkown
|
page read and write
|
||
245000
|
unkown
|
page read and write
|
||
245000
|
unkown
|
page read and write
|
||
240000
|
unkown
|
page read and write
|
||
C22000
|
unkown image
|
page execute read
|
||
240000
|
unkown
|
page read and write
|
||
C20000
|
unkown image
|
page readonly
|
||
AA0000
|
unkown
|
page read and write
|
||
590000
|
unkown
|
page read and write
|
||
580000
|
unkown
|
page read and write
|
||
26D0000
|
unkown
|
page read and write
|
||
B1D000
|
unkown
|
page read and write
|
||
AD0000
|
heap private
|
page read and write
|
||
4740000
|
unkown
|
page readonly
|
||
6F0000
|
unkown
|
page read and write
|
||
5A0000
|
unkown
|
page read and write
|
||
600000
|
unkown
|
page read and write
|
||
600000
|
unkown
|
page read and write
|
||
746000
|
heap private
|
page read and write
|
||
580000
|
unkown
|
page read and write
|
||
53FE000
|
unkown
|
page read and write
|
||
124000
|
unkown
|
page read and write
|
||
524E000
|
stack
|
page read and write
|
||
B10000
|
unkown
|
page readonly
|
||
5A0000
|
unkown
|
page read and write
|
||
2A0000
|
unkown
|
page read and write
|
||
580000
|
unkown
|
page read and write
|
||
2673000
|
unkown
|
page read and write
|
||
152000
|
unkown
|
page read and write
|
||
585000
|
unkown
|
page read and write
|
||
245000
|
unkown
|
page read and write
|
||
271E000
|
unkown
|
page read and write
|
||
728000
|
heap private
|
page read and write
|
||
580000
|
unkown
|
page read and write
|
||
220000
|
unkown
|
page execute and read and write
|
||
25E5000
|
unkown
|
page read and write
|
||
6730000
|
heap private
|
page read and write
|
||
80000
|
unkown
|
page read and write
|
||
4C04000
|
heap private
|
page read and write
|
||
52AE000
|
unkown
|
page read and write
|
||
590000
|
unkown
|
page read and write
|
||
5B0000
|
unkown
|
page read and write
|
||
147000
|
unkown
|
page execute and read and write
|
||
6F0000
|
unkown
|
page read and write
|
||
585000
|
unkown
|
page read and write
|
||
245000
|
unkown
|
page read and write
|
||
136000
|
unkown
|
page read and write
|
||
5B0000
|
unkown
|
page read and write
|
||
580000
|
unkown
|
page read and write
|
||
5251000
|
unkown
|
page read and write
|
||
240000
|
unkown
|
page read and write
|
||
245000
|
unkown
|
page read and write
|
||
580000
|
unkown
|
page read and write
|
||
5A0000
|
unkown
|
page read and write
|
||
245000
|
unkown
|
page read and write
|
||
880000
|
unkown
|
page read and write
|
||
240000
|
unkown
|
page read and write
|
||
4A70000
|
unkown
|
page read and write
|
||
4A6E000
|
unkown
|
page read and write
|
||
580000
|
unkown
|
page read and write
|
||
240000
|
unkown
|
page read and write
|
||
790000
|
unkown
|
page readonly
|
||
600000
|
unkown
|
page read and write
|
||
240000
|
unkown
|
page read and write
|
||
710000
|
unkown
|
page read and write
|
||
601000
|
unkown
|
page read and write
|
||
600000
|
unkown
|
page read and write
|
||
245000
|
unkown
|
page read and write
|
||
3B8000
|
unkown
|
page read and write
|
||
545E000
|
unkown
|
page read and write
|
||
182000
|
unkown
|
page read and write
|
||
890000
|
unkown
|
page read and write
|
||
6A5000
|
unkown
|
page read and write
|
||
C20000
|
unkown image
|
page readonly
|
||
4A9E000
|
unkown
|
page read and write
|
||
A0000
|
unkown
|
page read and write
|
||
1D0000
|
heap private
|
page read and write
|
||
850000
|
unkown
|
page read and write
|
||
520000
|
unkown
|
page readonly
|
||
585000
|
unkown
|
page read and write
|
||
240000
|
unkown
|
page read and write
|
||
600000
|
unkown
|
page read and write
|
||
5A0D000
|
unkown
|
page read and write
|
||
245000
|
unkown
|
page read and write
|
||
600000
|
unkown
|
page read and write
|
||
26CC000
|
unkown
|
page read and write
|
||
24B000
|
unkown
|
page read and write
|
||
D10000
|
unkown image
|
page readonly
|
||
460000
|
unkown
|
page read and write
|
||
610000
|
unkown
|
page read and write
|
||
697000
|
heap default
|
page read and write
|
||
F0000
|
unkown
|
page readonly
|
||
600000
|
unkown
|
page read and write
|
||
5A10000
|
unkown
|
page read and write
|
||
4D70000
|
heap private
|
page read and write
|
||
245000
|
unkown
|
page read and write
|
||
47E000
|
unkown
|
page read and write
|
||
610000
|
unkown
|
page read and write
|
||
7C0000
|
heap private
|
page read and write
|
||
585000
|
unkown
|
page read and write
|
||
5A5000
|
unkown
|
page read and write
|
||
600000
|
unkown
|
page read and write
|
||
240000
|
unkown
|
page read and write
|
||
580000
|
unkown
|
page read and write
|
||
700000
|
unkown
|
page execute and read and write
|
||
560000
|
unkown
|
page read and write
|
||
240000
|
unkown
|
page read and write
|
||
5AE000
|
unkown
|
page read and write
|
||
51BE000
|
unkown
|
page read and write
|
||
690000
|
heap default
|
page read and write
|
||
5B7F000
|
unkown
|
page read and write
|
||
4AA0000
|
unkown
|
page read and write
|
||
5A0000
|
unkown
|
page readonly
|
||
18A000
|
unkown
|
page execute and read and write
|
||
523E000
|
unkown
|
page read and write
|
||
250000
|
unkown
|
page read and write
|
||
6F0000
|
unkown
|
page read and write
|
||
8E0000
|
unkown
|
page readonly
|
||
245000
|
unkown
|
page read and write
|
||
210000
|
unkown
|
page read and write
|
||
530000
|
unkown
|
page read and write
|
||
580000
|
unkown
|
page read and write
|
||
A60000
|
unkown
|
page readonly
|
||
250000
|
unkown
|
page read and write
|
||
2702000
|
unkown
|
page read and write
|
||
585000
|
unkown
|
page read and write
|
||
4C60000
|
unkown
|
page read and write
|
||
26E8000
|
unkown
|
page read and write
|
||
4B0000
|
unkown
|
page read and write
|
||
26A9000
|
unkown
|
page read and write
|
||
5470000
|
unkown
|
page read and write
|
||
7E0000
|
unkown
|
page read and write
|
||
463E000
|
stack
|
page read and write
|
||
582000
|
unkown
|
page read and write
|
||
5B0000
|
unkown
|
page read and write
|
||
580000
|
unkown
|
page read and write
|
||
585000
|
unkown
|
page read and write
|
||
880000
|
heap default
|
page read and write
|
||
621D000
|
unkown
|
page read and write
|
||
B6E000
|
unkown
|
page read and write
|
||
600000
|
unkown
|
page read and write
|
||
64CE000
|
unkown
|
page read and write
|
||
540000
|
heap private
|
page execute and read and write
|
||
560000
|
unkown
|
page read and write
|
||
12D000
|
unkown
|
page execute and read and write
|
||
22C0000
|
unkown
|
page write copy
|
||
2724000
|
unkown
|
page read and write
|
||
5B0000
|
unkown
|
page read and write
|
There are 483 hidden memdumps, click here to show them.