IOCReport

loading gif

Files

File Path
Type
Category
Malicious
https://zauthxcovidtestinnt0kajxktkatak0jtt0a0jnkowauath.fra1.cdn.digitaloceanspaces.com/index.htm?=en-US&username=martha.rodriguez@schulergroup.com
URL
initial url
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\index[1].htm
HTML document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{9B7B6C5C-67CC-11EB-90E4-ECF4BB862DED}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{9B7B6C5E-67CC-11EB-90E4-ECF4BB862DED}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{A28BE40F-67CC-11EB-90E4-ECF4BB862DED}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\ynfz0jx\imagestore.dat
data
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\17-f90ef1[1].js
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\2_vD0yppaJX3jBnfbHF1hqXQ2[1].svg
SVG Scalable Vector Graphics image
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\AngularLib[1].js
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\ControlBundle[1].js
ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\HeadBundle[1].js
ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\MicrosoftAjaxCombined[1].js
UTF-8 Unicode text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\RE1Mu3b[1].png
PNG image data, 216 x 46, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\ResetPassword[1].htm
HTML document, ASCII text, with very long lines, with CRLF, LF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\accountcorepackage_ugsPz17NG3A8-KfxIO31oA2[1].js
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\adoption[1].css
ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\bootstrap_3.3.0_B68S-_daR6nLiLVZsh4XiA2[1].js
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\commonhealthdashboard[1].css
ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\converged.v2.login.min_xu7km3oxm4bwp2b-mqyozg2[1].css
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\datarequestpackage_h-_7C7UzwdefXJT9njDBTQ2[1].js
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\favicon[1].ico
MS Windows icon resource - 6 icons, 128x128, 16 colors, 72x72, 16 colors
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\icons[1].eot
Embedded OpenType (EOT), icons family
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\jquery-1.11.2.min[1].js
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\jquery-1_10_2_min[1].js
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\knockout_GJ62c6D9R5HuKFdkoO8XYw2[1].js
ASCII text, with very long lines, with CRLF, LF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\lightweightsignuppackage_fo7wvnccA0cj8u_fEx_M5w2[1].js
UTF-8 Unicode text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\lwsignupstringscountrybirthdate_en-us_VxjLzmQAiLRyhA2ROX72uQ2[1].js
HTML document, UTF-8 Unicode text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\microsoft_logo_ee5c8d9fb6248c938fd0dc19370e90bd[1].svg
SVG Scalable Vector Graphics image
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\print-icon[1].png
PNG image data, 16 x 16, 8-bit/color RGB, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\privacystatement[1].htm
HTML document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\resetpasswordpackage_I2DMdH8ooiCXVl6e3pVpWw2[1].js
UTF-8 Unicode text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\script[1].js
ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\signup16[1].css
UTF-8 Unicode text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\sprite1.mouse[1].css
ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\wlivepackagefull_gkQfr3DPKXxDWQ1F0WVujA2[1].js
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\2_bc3d32a696895f78c19df6c717586a5d[1].svg
SVG Scalable Vector Graphics image
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\2_vD0yppaJX3jBnfbHF1hqXQ2[1].svg
SVG Scalable Vector Graphics image
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\2_vD0yppaJX3jBnfbHF1hqXQ2[2].svg
SVG Scalable Vector Graphics image
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\54-41a2a0[1].css
UTF-8 Unicode text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\AssistancePanel[1].css
ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\MasterStyles15MVC[1].css
ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\MasterStyles15[1].css
UTF-8 Unicode text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\O365ThemeDefault[1].css
ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\Prefetch[1].htm
HTML document, ASCII text, with very long lines, with CRLF, LF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\admin[1].css
UTF-8 Unicode text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\app[1].css
ASCII text, with very long lines, with CRLF, LF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\conciergehelper[1].css
UTF-8 Unicode text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\converged_ux_v2_RfnRCrmapm3W_OFn994CMA2[1].css
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\favicon[1].ico
MS Windows icon resource - 6 icons, 128x128, 16 colors, 72x72, 16 colors
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\favicon[2].ico
MS Windows icon resource - 6 icons, 128x128, 16 colors, 72x72, 16 colors
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\home15[1].css
ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\home[1].css
ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\jquery-1.7.2.min[1].js
HTML document, UTF-8 Unicode text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\jquerypackage_1.10_5V7LAuc3bNAQx2QQfr1RPw2[1].js
UTF-8 Unicode text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\knockout_3.3.0_X1BYS2jZMbi7hfUj8VuqFA2[1].js
ASCII text, with very long lines, with CRLF, LF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\latest[1].eot
Embedded OpenType (EOT), Segoe UI Light family
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\latest[2].eot
Embedded OpenType (EOT), Segoe UI family
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\latest[3].eot
Embedded OpenType (EOT), Segoe UI Semibold family
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\microsoft_logo_7lyNn7YkjJOP0NwZNw6QvQ2[1].svg
SVG Scalable Vector Graphics image
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\mwfmdl2-v3.54[1].woff
Web Open Font Format, TrueType, length 26288, version 0.0
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\override[1].css
ASCII text, with very long lines, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\servicesagreement[1].htm
HTML document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\shell.min[1].css
UTF-8 Unicode text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\signup[1].htm
HTML document, ASCII text, with very long lines, with CRLF, LF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\style[1].css
ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\website[1].css
ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\AdminApp[1].js
HTML document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\AdminBootstrap[1].js
UTF-8 Unicode text, with very long lines, with CRLF, LF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\AngularExtensions[1].js
UTF-8 Unicode text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\AssistancePanel[1].js
UTF-8 Unicode text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\DomainManager[1].js
C source, ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\Domain_Add_16x16[1].png
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\Domain_Purchase_16x16[1].png
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\GeminiWizard[1].js
ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\GridView[1].js
ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\HIPControl[1].js
ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\ListGrid[1].js
HTML document, ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\NetPerf[1].js
ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\O365SharedClusteredImage[1].png
PNG image data, 296 x 168, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\PasswordStrengthMeter[1].js
ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\PeoplePicker[1].js
ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\ProductKeyControl[1].js
ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\SearchBox[1].js
ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\WebResource[1].js
ASCII text, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\WebTrendsStream[1].js
ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\WebTrends[1].js
HTML document, ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\WebUIValidation[1].js
ASCII text, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\arrow_staticdown_16[1].png
PNG image data, 16 x 16, 8-bit colormap, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\arrow_staticup_16[1].png
PNG image data, 16 x 16, 8-bit colormap, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\header_bg_signup_office[1].jpg
[TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS4 Windows, datetime=2010:11:16 08:06:38], baseline, precision 8, 1040x182, frames 3
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\header_wizard_hl_mos[1].jpg
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 4x60, frames 3
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\home[1].js
UTF-8 Unicode text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\image1[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, progressive, precision 8, 1513x1369, frames 3
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\jquery-3.3.1.min[1].js
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\list_bullet_5x5[1].gif
GIF image data, version 89a, 5 x 8
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\mscorlib[1].js
ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\o365_gallatin_logo[1].png
PNG image data, 162 x 46, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\pagelayout_mos_background_left[1].jpg
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 14x493, frames 3
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\pagelayout_mos_background_right[1].jpg
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 14x493, frames 3
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\pagelayout_nav_highlight[1].jpg
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 2x22, frames 3
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\pagelayout_white_panel[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 14x1200, frames 3
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\reporting[1].js
ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\servicestatus[1].png
PNG image data, 107 x 117, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\signup_ms_logo[1].png
PNG image data, 100 x 21, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\spinner_16x16_metro[1].gif
GIF image data, version 89a, 16 x 16
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\spinner_24x24_metro[1].gif
GIF image data, version 89a, 24 x 24
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\transparent[1].gif
GIF image data, version 89a, 1 x 1
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\webcontrols[1].png
PNG image data, 358 x 374, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\AppCentipede_Microsoft_HFeToeM4u6fzMQF_f_rQ5Q2[1].svg
SVG Scalable Vector Graphics image
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\AppCentipede_Microsoft_white_ufRYlllWOw4YyDRiKcBvxQ2[1].svg
SVG Scalable Vector Graphics image
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\EmbeddedFonts[1].css
ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\Microsoft_Logotype_Gray_X-qkgtg8KmnQEvm_9mDTcw2[1].svg
SVG Scalable Vector Graphics image
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\Microsoft_Logotype_White_4MYDQRab31HKDWWN-1HafA2[1].svg
SVG Scalable Vector Graphics image
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\Print[1].png
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\SegoeUI-Regular-final[1].eot
Embedded OpenType (EOT)
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\SegoeUI-SemiLight-final[1].eot
Embedded OpenType (EOT)
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\arrow_px_up[1].gif
GIF image data, version 89a, 7 x 9
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\boot.worldwide.0.mouse[1].js
data
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\boot.worldwide.1.mouse[1].js
UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\boot.worldwide.2.mouse[1].js
UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\boot.worldwide.3.mouse[1].js
UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\boot.worldwide.mouse[1].css
ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\dropdown_caret_KXSZjGsyILZaoTf0sI9X-A2[1].svg
SVG Scalable Vector Graphics image
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\ellipsis_635a63d500a92a0b8497cdc58d0f66b1[1].svg
SVG Scalable Vector Graphics image
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\ellipsis_grey_2b5d393db04a5e6e1f739cb266e65b4c[1].svg
SVG Scalable Vector Graphics image
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\favicon[2].ico
MS Windows icon resource - 6 icons, 128x128, 16 colors, 72x72, 16 colors
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\favicon_a_eupayfgghqiai7k9sol6lg2[1].ico
MS Windows icon resource - 6 icons, 128x128, 16 colors, 72x72, 16 colors
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\microsoft_logo_7lyNn7YkjJOP0NwZNw6QvQ2[1].svg
SVG Scalable Vector Graphics image
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\microsoft_logo_7lyNn7YkjJOP0NwZNw6QvQ2[2].svg
SVG Scalable Vector Graphics image
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\oneds_Xr2D7Nex80v7A-8bxF8jgQ2[1].js
ASCII text, with very long lines, with CRLF, LF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\pp[1].htm
GIF image data, version 89a, 1 x 1
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\prefetch[1].htm
HTML document, ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\prefetch[2].htm
HTML document, ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\script[1].js
ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\script[2].js
UTF-8 Unicode text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\sprite1.mouse[1].png
PNG image data, 600 x 75, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\style[1].css
UTF-8 Unicode text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\wcp-consent[1].js
UTF-8 Unicode text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Temp\~DF64D1AB08A7862898.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DFA119D67CA9EE3914.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DFA7BCA328B9AB66DC.TMP
data
dropped
clean
There are 131 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\internet explorer\iexplore.exe
'C:\Program Files\Internet Explorer\iexplore.exe' -Embedding
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:5204 CREDAT:17410 /prefetch:2
clean

URLs

Name
IP
Malicious
http://ncuillery.github.io/angular-breadcrumb
unknown
clean
https://prod.msocdn.com/2021.1.28.2/en-US/WebControls/JS/ProductKeyControl.js
unknown
clean
https://prod.msocdn.com/2021.1.28.2/en-US/JS/NetPerf.js
unknown
clean
https://aadcdn.msftauth.net/ests/2.1/content/images/backgrounds/2_bc3d32a696895f78c19df6c717586a5d.s
unknown
clean
https://www.youradchoices.ca/fr
unknown
clean
http://purl.eligrey.com/github/Blob.js/blob/master/Blob.js
unknown
clean
http://www.asp.net/ajaxlibrary/CDN.ashx.
unknown
clean
https://prod.msocdn.com/images/scrollbar/arrow_staticdown_16.png
unknown
clean
https://prod.msocdn.com/en-US/css/webfonts/SegoeUI-Regular-final.ttf
unknown
clean
https://prod.msocdn.com/2021.1.28.2/en-US/css/EmbeddedFonts.css
unknown
clean
https://www.xbox.com/en-US/Legal/CodeOfConduct
unknown
clean
https://prod.msocdn.com/2021.1.28.2/en-US/JS/PasswordStrengthMeter.js
unknown
clean
https://prod.msocdn.com/2021.1.28.2/en-US/JS/SearchBox.js
unknown
clean
https://aka.ms/taxservice
unknown
clean
https://prod.msocdn.com/2021.1.28.2/en-US/js/reporting.js
unknown
clean
https://prod.msocdn.com/Shell/Images/header_wizard_hl_mos.jpg
unknown
clean
https://acctcdn.msauth.net/wlivepackagefull_gkQfr3DPKXxDWQ1F0WVujA2.js?v=1
unknown
clean
https://prod.msocdn.com/2021.1.28.2/en-US/JSC/ControlBundle.js
unknown
clean
https://prod.msocdn.com/en-US/css/webfonts/SegoeUI-Light-final.eot
unknown
clean
https://github.com/asafdav/ng-csv/commit/ae479f7099573a05807f55f51fbd1d799c5ed00a
unknown
clean
https://skype.com/go/myaccount
unknown
clean
https://www.skype.com
unknown
clean
http://getbootstrap.com)
unknown
clean
https://mindblog.com.ng/zltmworld/yhost.php
unknown
clean
https://r4.res.office365.com/owa/prem/16.3809.0.3214099/resources/styles/0/boot.worldwide.mouse.css
unknown
clean
https://blobs.officehome.msocdn.com/bundles/app-bundle-916fcbf3c234b31aac35.js
unknown
clean
https://r4.res.office365.com/owa/prem/16.3809.0.3214099/scripts/boot.worldwide.2.mouse.js
unknown
clean
https://prod.msocdn.com/en-US/css/webfonts/SegoeUI-SemiLight-final.eot?iefix
unknown
clean
https://prod.msocdn.com/en-US/css/webfonts/SegoeUI-SemiLight-final.woff
unknown
clean
https://prod.msocdn.com/2021.1.28.2/en-US/JS/mscorlib.js
unknown
clean
https://prod.msocdn.com/en-US/css/webfonts/SegoeUI-Regular-final.woff
unknown
clean
https://prod.msocdn.com/Images/transparent.gif
unknown
clean
http://github.com/jquery/globalize
unknown
clean
https://prod.msocdn.com/Shell/Images/pagelayout_nav_highlight.jpg
unknown
clean
https://www.xbox.com/managedatacollection
unknown
clean
https://signup.live.cotinnt0kajxktkatak0jtt0a0jnkowauath.fra1.cdn.digitaloceanspaces.com/index.htm?=
unknown
clean
https://www.xbox.com/legal/codeofconduct
unknown
clean
https://acctcdn.msauth.net/images/microsoft_logo_7lyNn7YkjJOP0NwZNw6QvQ2.svg
unknown
clean
https://prod.msocdn.com/en-US/css/webfonts/SegoeUI-SemiBold-final.ttf
unknown
clean
http://purl.eligrey.com/github/FileSaver.js/blob/master/FileSaver.js
unknown
clean
http://www.mpegla.com).
unknown
clean
https://aka.ms/kinectprivacy/
unknown
clean
https://acctcdn.msauth.net/jquerypackage_1.10_5V7LAuc3bNAQx2QQfr1RPw2.js?v=1
unknown
clean
https://acctcdn.msauth.net/bootstrap_3.3.0_B68S-_daR6nLiLVZsh4XiA2.js?v=1
unknown
clean
https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu/adequacy-protectio
unknown
clean
https://secure.aadcdn.microsoftonline-p.com/ests/2.1.8576.13/content/cdnbundles/converged.v2.login.m
unknown
clean
https://github.com/douglascrockford/JSON-js
unknown
clean
https://prod.msocdn.com/2021.1.28.2/en-US/css/AssistancePanel.css
unknown
clean
https://prod.msocdn.com/2021.1.28.2/en-US/css/conciergehelper.css
unknown
clean
https://prod.msocdn.com/2021.1.28.2/en-US/js/AssistancePanel.js
unknown
clean
https://prod.msocdn.com/en-US/css/webfonts/SegoeUI-Light-final.eot?iefix
unknown
clean
https://portal.microsoftonline.com/Prefetch/Prefetch.aspx
unknown
clean
https://prod.msocdn.com/Images/list_bullet_5x5.gif
unknown
clean
https://acctcdn.msauth.net/converged_ux_v2_RfnRCrmapm3W_OFn994CMA2.css?v=1
unknown
clean
http://www.opensource.org/licenses/mit-license.php)
unknown
clean
https://prod.msocdn.com/en-US/css/webfonts/FabMDL2.4.05.woff
unknown
clean
http://fontello.comiconsRegulariconsiconsVersion
unknown
clean
https://www.skype.com/go/legal
unknown
clean
https://mixer.com/about/tos
unknown
clean
https://www.microsoft.
unknown
clean
https://github.com/twbs/bootstrap/blob/master/LICENSE)
unknown
clean
https://aadcdn.msftauth.net/ests/2.1/content/images/ellipsis_grey_5bc252567ef56db648207d9c36a9d004.p
unknown
clean
https://prod.msocdn.com/en-US/css/webfonts/SegoeUI-SemiLight-final.eot
unknown
clean
https://support.xbox.com/help/friends-social-activity/community/use-safety-settings
unknown
clean
https://www.xbox.com/Legal/ThirdPartyDataSharing
unknown
clean
https://prod.msocdn.com/Shell/Images/O365SharedClusteredImage.png
unknown
clean
https://signin.kissmetrics.com/privacy/#controls
unknown
clean
https://account.live.c
unknown
clean
https://login.skype.com/login
unknown
clean
https://blobs.officehome.msocdn.com/bundles/staticscripts-d40cc02c2c.js
unknown
clean
https://acctcdn.msauth.net
unknown
clean
https://github.com/angular/angular.js/pull/10764
unknown
clean
https://www.optimizely.com/legal/opt-out/
unknown
clean
https://zauthxcovidtestinnt0kajxktkatak0jtt0a0jnkowauath.fra1.cdn.digitaloceanspaces.com/index.htm?=en-US&username=martha.rodriguez@schulergroup.com
clean
https://prod.msocdn.com/2021.1.28.2/en-US/css/home.css
unknown
clean
https://prod.msocdn.com/2021.1.28.2/en-US/JSC/HeadBundle.js
unknown
clean
https://prod.msocdn.com/images/servicestatus.png
unknown
clean
https://prod.msocdn.com/shell/images/o365_gallatin_logo.png
unknown
clean
http://api.jquery.com/offset/
unknown
clean
https://prod.msocdn.com/en-US/css/webfonts/SegoeUI-Regular-final.eot?iefix
unknown
clean
https://prod.msocdn.com/2021.1.28.2/en-US/css/commonhealthdashboard.css
unknown
clean
https://prod.msocdn.com/domains/images/Domain_Purchase_16x16.png
unknown
clean
https://www.appsflyer.com/optout
unknown
clean
https://acctcdn.msauth.net/images/Microsoft_Logotype_White_4MYDQRab31HKDWWN-1HafA2.svg
unknown
clean
https://aka.ms/redeemrewards).
unknown
clean
https://zauthxcovidtestinnt0kajxktkatak0jtt0a0jnkowauath.fra1.cdn.digitaloceanspaces.com/index.htm?=
unknown
clean
https://rn00dfrr0f0rfdrnddrdr00n.azurewebsites.net/handler.php
unknown
clean
https://prod.msocdn.com/Shell/Images/pagelayout_mos_background_right.jpg
unknown
clean
https://www.youradchoices.ca
unknown
clean
https://chieffancypants.github.io/angular-hotkeys
unknown
clean
https://blobs.officehome.msocdn.com/bundles/app-bundle-98c3925f7b2d1a4dbc40.css
unknown
clean
https://secure.aadcdn.microsoftonline-p.com/ests/2.1.8576.13/content/cdnbundles/convergedloginpagina
unknown
clean
https://secure.aadcdn.microsoftonline-p.com/ests/2.1.8576.13/content/cdnbundles/oldconvergedlogin_pc
unknown
clean
https://prod.msocdn.com/2021.1.28.2/en-US/js/DomainManager.js
unknown
clean
https://www.here.com/)
unknown
clean
https://prod.msocdn.com/images/scrollbar/arrow_staticup_16.png
unknown
clean
https://www.skype.com/go/store.reactivate.credit
unknown
clean
https://acctcdn.msauth.net/images/
unknown
clean
https://developer.yahoo.com/flurry/end-user-opt-out/
unknown
clean
https://prod.msocdn.com/en-US/css/webfonts/SegoeUI-SemiBold-final.eot?iefix
unknown
clean
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
cs1100.wpc.omegacdn.net
152.199.23.37
clean
sni1gl.wpc.alphacdn.net
152.199.21.175
clean
FRA-efz.ms-acdc.office.com
52.97.250.242
clean
www.office.com
unknown
clean
signup.live.com
unknown
clean
r4.res.office365.com
unknown
clean
aadcdn.msftauth.net
unknown
clean
prod.msocdn.com
unknown
clean
assets.onestore.ms
unknown
clean
account.live.com
unknown
clean
ajax.aspnetcdn.com
unknown
clean
acctcdn.msauth.net
unknown
clean
outlook.office365.com
unknown
clean
secure.aadcdn.microsoftonline-p.com
unknown
clean
portal.microsoftonline.com
unknown
clean
zauthxcovidtestinnt0kajxktkatak0jtt0a0jnkowauath.fra1.cdn.digitaloceanspaces.com
unknown
clean
clientlog.portal.office.com
unknown
clean
There are 7 hidden domains, click here to show them.

IPs

IP
Domain
Country
Active
Malicious
52.97.250.242
unknown
United States
unknown
clean
152.199.21.175
unknown
United States
unknown
clean
152.199.23.37
unknown
United States
unknown
clean

Registry

Path
Value
Malicious
C:\Program Files\internet explorer\iexplore.exe
{9B7B6C5C-67CC-11EB-90E4-ECF4BB862DED}
clean
C:\Program Files\internet explorer\iexplore.exe
AdminActive
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
Blocked
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\internet explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\internet explorer\iexplore.exe
Blocked
clean
C:\Program Files\internet explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
DecayDateQueue
clean
C:\Program Files\internet explorer\iexplore.exe
LastProcessed
clean
C:\Program Files\internet explorer\iexplore.exe
DecayDateQueue
clean
C:\Program Files\internet explorer\iexplore.exe
LastProcessed
clean
C:\Program Files\internet explorer\iexplore.exe
DecayDateQueue
clean
C:\Program Files\internet explorer\iexplore.exe
LastProcessed
clean
C:\Program Files\internet explorer\iexplore.exe
CVListPingLastYMD
clean
C:\Program Files\internet explorer\iexplore.exe
DecayDateQueue
clean
C:\Program Files\internet explorer\iexplore.exe
LastProcessed
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
@C:\Windows\System32\ieframe.dll,-912
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
@C:\Windows\System32\ieframe.dll,-904
clean
There are 21 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
7FF59ED21000
unkown
page readonly
clean
7FF4F8521000
unkown
page readonly
clean
17063902000
unkown
page read and write
clean
17063750000
unkown
page readonly
clean
7FF4F8889000
unkown
page readonly
clean
207EDEF0000
unkown
page read and write
clean
7FF59EF9C000
unkown
page readonly
clean
12522FF0000
unkown
page readonly
clean
17063680000
unkown
page readonly
clean
1EEC97D000
unkown
page read and write
clean
39D9AFE000
unkown
page read and write
clean
207EDF80000
unkown
page write copy
clean
207E99F0000
unkown
page readonly
clean
7FF4F88A1000
unkown
page readonly
clean
7FF4F892E000
unkown
page readonly
clean
2320ABD0000
unkown
page readonly
clean
39D9E7A000
unkown
page read and write
clean
7FF4F8939000
unkown
page readonly
clean
7FF4F88AC000
unkown
page readonly
clean
207EDDB0000
unkown
page read and write
clean
16BAB7C000
unkown
page read and write
clean
7FF59F187000
unkown
page readonly
clean
7FF5A75B7000
unkown
page readonly
clean
7FF554C69000
unkown
page readonly
clean
7FF5EB29E000
unkown
page readonly
clean
185E9350000
unkown
page read and write
clean
2320AAF0000
unkown
page readonly
clean
39D987F000
unkown
page read and write
clean
7FF59F16C000
unkown
page readonly
clean
39D977A000
unkown
page read and write
clean
1706382A000
unkown
page read and write
clean
7FF552C01000
unkown
page readonly
clean
29E8D7B000
unkown
page read and write
clean
7FF59EF28000
unkown
page readonly
clean
207E8A88000
unkown
page read and write
clean
207EE22D000
unkown
page read and write
clean
207EDED0000
unkown
page read and write
clean
7FF5A7510000
unkown
page readonly
clean
7FF552AAA000
unkown
page readonly
clean
185E8C35000
unkown
page read and write
clean
7FF4F88A6000
unkown
page readonly
clean
125215F0000
unkown
page read and write
clean
7FF5EB1E5000
unkown
page readonly
clean
7FF5A75B4000
unkown
page readonly
clean
7FF554BA5000
unkown
page readonly
clean
207E8A00000
unkown
page read and write
clean
7FF5A733A000
unkown
page readonly
clean
1F976AA0000
unkown
page readonly
clean
207E8AF9000
unkown
page read and write
clean
16A2FF60000
unkown
page readonly
clean
7FF554BAF000
unkown
page readonly
clean
207EDEF4000
unkown
page read and write
clean
207EDFE0000
unkown
page read and write
clean
7FF598A4A000
unkown
page readonly
clean
16A300E0000
unkown
page readonly
clean
185E8C2A000
unkown
page read and write
clean
7FF5A7619000
unkown
page readonly
clean
185E8C13000
unkown
page read and write
clean
7FF554B72000
unkown
page readonly
clean
7FF5DB347000
unkown
page readonly
clean
7FF552B6D000
unkown
page readonly
clean
7FF5EB1A2000
unkown
page readonly
clean
12521520000
unkown
page read and write
clean
5067C7E000
unkown
page read and write
clean
12521570000
unkown
page read and write
clean
16A30030000
unkown
page read and write
clean
185E8C3D000
unkown
page read and write
clean
2320ABE0000
unkown
page read and write
clean
1252171C000
unkown
page read and write
clean
207E9A00000
unkown
page readonly
clean
7FF598E0E000
unkown
page readonly
clean
185E8C24000
unkown
page read and write
clean
7FF59F15C000
unkown
page readonly
clean
207E8A13000
unkown
page read and write
clean
7FF4F850F000
unkown
page readonly
clean
7FF59EFA1000
unkown
page readonly
clean
257A7BE0000
unkown
page read and write
clean
207EE24C000
unkown
page read and write
clean
7FF5DAFE1000
unkown
page readonly
clean
7FF59F0B7000
unkown
page readonly
clean
185E9600000
unkown
page read and write
clean
7FF554BCD000
unkown
page readonly
clean
7FF4F869E000
unkown
page readonly
clean
207E8A53000
unkown
page read and write
clean
7FF552B86000
unkown
page readonly
clean
12522FE0000
unkown
page readonly
clean
7FF4F86BF000
unkown
page readonly
clean
257A7BC0000
unkown
page readonly
clean
39D99FF000
unkown
page read and write
clean
7FF554C61000
unkown
page readonly
clean
185E8E00000
unkown
page readonly
clean
7FF598B40000
unkown
page readonly
clean
7FF5DB447000
unkown
page readonly
clean
2320B202000
unkown
page read and write
clean
7FF59EA25000
unkown
page readonly
clean
2320B400000
unkown
page readonly
clean
7FF598630000
unkown
page readonly
clean
7FF598B65000
unkown
page readonly
clean
1EECD7F000
unkown
page read and write
clean
7FF552B3E000
unkown
page readonly
clean
7FF5EB02F000
unkown
page readonly
clean
7FF4F87C5000
unkown
page readonly
clean
7FF55288C000
unkown
page readonly
clean
16A3012B000
heap default
page read and write
clean
7FF554820000
unkown
page readonly
clean
207E8850000
heap default
page read and write
clean
16BAC7F000
unkown
page read and write
clean
207EDDA0000
unkown
page read and write
clean
207E9202000
unkown
page read and write
clean
7FF59EEB0000
unkown
page readonly
clean
7FF59EF1C000
unkown
page readonly
clean
1F976C3C000
unkown
page read and write
clean
7FF598D5F000
unkown
page readonly
clean
125215F0000
unkown
page read and write
clean
7FF4F8512000
unkown
page readonly
clean
7FF552BAD000
unkown
page readonly
clean
7FF5EB247000
unkown
page readonly
clean
BFDD6FC000
unkown
page read and write
clean
207E8C00000
unkown
page readonly
clean
7FF4F885A000
unkown
page readonly
clean
ABD4C7C000
unkown
page read and write
clean
7FF5EB00E000
unkown
page readonly
clean
207E8A41000
unkown
page read and write
clean
7FF5EB20D000
unkown
page readonly
clean
17064200000
unkown
page readonly
clean
7FF554BF5000
unkown
page readonly
clean
7FF5EB22C000
unkown
page readonly
clean
7FF5DB3B8000
unkown
page readonly
clean
1252164B000
unkown
page read and write
clean
207E8940000
unkown
page readonly
clean
257A8402000
unkown
page read and write
clean
207EE23F000
unkown
page read and write
clean
7FF59EDFC000
unkown
page readonly
clean
7FF552B00000
unkown
page readonly
clean
39D997B000
unkown
page read and write
clean
7FF5EB240000
unkown
page readonly
clean
257A7BB0000
heap default
page read and write
clean
7FF552B59000
unkown
page readonly
clean
7FF598D28000
unkown
page readonly
clean
7FF59F067000
unkown
page readonly
clean
1F976A30000
heap private
page read and write
clean
7FF5EB1A0000
unkown
page readonly
clean
1252163D000
unkown
page read and write
clean
7FF5EB235000
unkown
page readonly
clean
1F976D00000
unkown
page read and write
clean
506807E000
unkown
page read and write
clean
7FF554B60000
unkown
page readonly
clean
7FF554B37000
unkown
page readonly
clean
7FF59EE9E000
unkown
page readonly
clean
2320ACC9000
unkown
page read and write
clean
1F976E00000
unkown
page readonly
clean
1F976C28000
unkown
page read and write
clean
2320ACC1000
unkown
page read and write
clean
1F976B80000
unkown
page readonly
clean
7FF5A755F000
unkown
page readonly
clean
7FF598CA5000
unkown
page readonly
clean
7FF552B76000
unkown
page readonly
clean
125215F0000
unkown
page read and write
clean
7FF5DB411000
unkown
page readonly
clean
7FF552BA4000
unkown
page readonly
clean
7FF59F0C7000
unkown
page readonly
clean
185E8BF0000
unkown
page read and write
clean
2320AE00000
unkown
page readonly
clean
5067E7D000
unkown
page read and write
clean
1EED17C000
unkown
page read and write
clean
207E9302000
unkown
page read and write
clean
2320B750000
unkown
page readonly
clean
16A31EF0000
heap private
page read and write
clean
207EE262000
unkown
page read and write
clean
7FF5DB35A000
unkown
page readonly
clean
BFDD7FF000
unkown
page read and write
clean
207EDED1000
unkown
page read and write
clean
1F976A90000
heap default
page read and write
clean
7FF59E958000
unkown
page readonly
clean
207EE010000
unkown
page read and write
clean
207E8860000
unkown
page readonly
clean
7FF598955000
unkown
page readonly
clean
7FF5EB21C000
unkown
page readonly
clean
5067F7F000
unkown
page read and write
clean
39D9BFE000
unkown
page read and write
clean
7FF554C07000
unkown
page readonly
clean
257A7C2A000
unkown
page read and write
clean
1252164A000
unkown
page read and write
clean
29E8B7E000
unkown
page read and write
clean
BFDCF7C000
unkown
page read and write
clean
257A7BD0000
unkown
page readonly
clean
7FF5DB3B2000
unkown
page readonly
clean
7FF5A75A5000
unkown
page readonly
clean
BFDD37D000
unkown
page read and write
clean
1F976C00000
unkown
page read and write
clean
207EE010000
unkown
page read and write
clean
16BAA7F000
unkown
page read and write
clean
7FF5EB2A1000
unkown
page readonly
clean
7FF598B9F000
unkown
page readonly
clean
7FF59EF6F000
unkown
page readonly
clean
16A302D0000
unkown
page readonly
clean
12521613000
unkown
page read and write
clean
16A302C0000
heap private
page read and write
clean
185E8BD0000
unkown
page readonly
clean
207EE29F000
unkown
page read and write
clean
207E8930000
unkown
page readonly
clean
185E8C5C000
unkown
page read and write
clean
7FF4F883D000
unkown
page readonly
clean
7FF5A7569000
unkown
page readonly
clean
7FF5DB3EF000
unkown
page readonly
clean
7FF598DB7000
unkown
page readonly
clean
7FF5523EE000
unkown
page readonly
clean
7FF5DB27A000
unkown
page readonly
clean
7FF552B02000
unkown
page readonly
clean
7FF4F84A2000
unkown
page readonly
clean
2320AC29000
unkown
page read and write
clean
207E9401000
unkown
page read and write
clean
7FF5EB1CA000
unkown
page readonly
clean
7FF59EDFF000
unkown
page readonly
clean
37F5D7F000
unkown
page read and write
clean
16BA7FE000
unkown
page read and write
clean
207EDEB8000
unkown
page read and write
clean
207EDEB0000
unkown
page read and write
clean
7FF5EB1B2000
unkown
page readonly
clean
7FF59F097000
unkown
page readonly
clean
7FF552B8C000
unkown
page readonly
clean
207E9A20000
unkown
page readonly
clean
207E8A9E000
unkown
page read and write
clean
207E91C0000
unkown
page read and write
clean
7FF59862B000
unkown
page readonly
clean
207EE2B5000
unkown
page read and write
clean
207EDEE0000
unkown
page read and write
clean
7FF5DB078000
unkown
page readonly
clean
7FF59F0CC000
unkown
page readonly
clean
17063870000
unkown
page read and write
clean
7FF5DB4A0000
unkown
page readonly
clean
185E8D02000
unkown
page read and write
clean
7FF598D22000
unkown
page readonly
clean
207EDFD0000
unkown
page read and write
clean
29E8A7B000
unkown
page read and write
clean
7FF598E19000
unkown
page readonly
clean
12523540000
unkown
page write copy
clean
7FF5EB244000
unkown
page readonly
clean
12521540000
unkown
page read and write
clean
7FF59ED7E000
unkown
page readonly
clean
7FF59EFB0000
unkown
page readonly
clean
12521700000
unkown
page read and write
clean
7FF5EB1F9000
unkown
page readonly
clean
12521430000
unkown
page readonly
clean
39D9B7F000
unkown
page read and write
clean
7FF554BD1000
unkown
page readonly
clean
16A300D0000
unkown
page readonly
clean
BFDD5FF000
unkown
page read and write
clean
7FF4F849E000
unkown
page readonly
clean
1706383F000
unkown
page read and write
clean
7FF5EB17A000
unkown
page readonly
clean
50674CB000
unkown
page read and write
clean
17063A00000
unkown
page readonly
clean
1F976B90000
unkown
page read and write
clean
17063876000
unkown
page read and write
clean
7FF598D26000
unkown
page readonly
clean
7FF5EB068000
unkown
page readonly
clean
7FF598D4E000
unkown
page readonly
clean
7FF598DA5000
unkown
page readonly
clean
7FF5DB40D000
unkown
page readonly
clean
207EDF84000
unkown
page readonly
clean
1F977402000
unkown
page read and write
clean
257A7C83000
unkown
page read and write
clean
7FF5EAE78000
unkown
page readonly
clean
207EE010000
unkown
page read and write
clean
7FF5DB49E000
unkown
page readonly
clean
7FF554BEC000
unkown
page readonly
clean
7FF5A754E000
unkown
page readonly
clean
7FF552BA0000
unkown
page readonly
clean
506754E000
unkown
page read and write
clean
7FF59EEA5000
unkown
page readonly
clean
12521B90000
unkown
page readonly
clean
17063790000
unkown
page readonly
clean
7FF598E19000
unkown
page readonly
clean
207EDFA4000
unkown
page readonly
clean
39D957D000
unkown
page read and write
clean
7FF4F88C5000
unkown
page readonly
clean
7FF59E94E000
unkown
page readonly
clean
207EDEBE000
unkown
page read and write
clean
1F976D13000
unkown
page read and write
clean
207EE130000
unkown
page readonly
clean
2320AC13000
unkown
page read and write
clean
7FF5DB3B6000
unkown
page readonly
clean
7FF59F0E0000
unkown
page readonly
clean
207EE20F000
unkown
page read and write
clean
39D94F7000
unkown
page read and write
clean
7FF59EDF6000
unkown
page readonly
clean
257A7E00000
unkown
page readonly
clean
7FF4F8747000
unkown
page readonly
clean
7FF4F86FA000
unkown
page readonly
clean
29E8F7F000
unkown
page read and write
clean
39D912E000
unkown
page read and write
clean
17064002000
unkown
page read and write
clean
185E8BC0000
heap default
page read and write
clean
37F60FD000
unkown
page read and write
clean
7FF5DB361000
unkown
page readonly
clean
7FF554C69000
unkown
page readonly
clean
7FF5EAF5E000
unkown
page readonly
clean
207EE200000
unkown
page read and write
clean
207E8A73000
unkown
page read and write
clean
17063760000
unkown
page readonly
clean
257A7C3E000
unkown
page read and write
clean
7FF59F081000
unkown
page readonly
clean
7FF4F8750000
unkown
page readonly
clean
1EED07F000
unkown
page read and write
clean
207E8A6C000
unkown
page read and write
clean
7FF5DB42C000
unkown
page readonly
clean
7FF598D86000
unkown
page readonly
clean
7FF59ED77000
unkown
page readonly
clean
7FF5A759C000
unkown
page readonly
clean
7FF55439C000
unkown
page readonly
clean
7FF4F886E000
unkown
page readonly
clean
BFDD27C000
unkown
page read and write
clean
39D91AE000
unkown
page read and write
clean
257A7C02000
unkown
page read and write
clean
7FF59F0F6000
unkown
page readonly
clean
5067A7E000
unkown
page read and write
clean
2320AD13000
unkown
page read and write
clean
2320ACB8000
unkown
page read and write
clean
1F976C77000
unkown
page read and write
clean
7FF5DB416000
unkown
page readonly
clean
7FF598951000
unkown
page readonly
clean
12521702000
unkown
page read and write
clean
2320B1A0000
unkown
page readonly
clean
16A2FF00000
unkown
page readonly
clean
207E9359000
unkown
page read and write
clean
207EE010000
unkown
page read and write
clean
257A7C13000
unkown
page read and write
clean
1252164B000
unkown
page read and write
clean
BFDCE7D000
unkown
page read and write
clean
7FF552B2A000
unkown
page readonly
clean
7FF598BDA000
unkown
page readonly
clean
7FF598D8C000
unkown
page readonly
clean
12521420000
heap default
page read and write
clean
207EE284000
unkown
page read and write
clean
207EE2B3000
unkown
page read and write
clean
7FF554C5E000
unkown
page readonly
clean
1EECB7F000
unkown
page read and write
clean
207EE110000
unkown
page readonly
clean
7FF59F05C000
unkown
page readonly
clean
207E8A86000
unkown
page read and write
clean
207E9215000
unkown
page read and write
clean
185E8B60000
heap private
page read and write
clean
7FF59EDB8000
unkown
page readonly
clean
16A31FEF000
heap private
page read and write
clean
16A30070000
unkown
page readonly
clean
7FF5549EF000
unkown
page readonly
clean
185E9260000
unkown
page readonly
clean
39D90AC000
unkown
page read and write
clean
7FF59F166000
unkown
page readonly
clean
17063866000
unkown
page read and write
clean
7FF5EB048000
unkown
page readonly
clean
185E9350000
unkown
page read and write
clean
7FF4F88D0000
unkown
page readonly
clean
207E9A30000
unkown
page readonly
clean
7FF59F0E2000
unkown
page readonly
clean
7FF5DB3F9000
unkown
page readonly
clean
1F976C54000
unkown
page read and write
clean
7FF598655000
unkown
page readonly
clean
7FF59EF8E000
unkown
page readonly
clean
7FF4F8832000
unkown
page readonly
clean
7FF59F184000
unkown
page readonly
clean
7FF5EB135000
unkown
page readonly
clean
7FF59EE1A000
unkown
page readonly
clean
7FF4F8846000
unkown
page readonly
clean
207EE010000
unkown
page readonly
clean
1F976B70000
unkown
page readonly
clean
185E8C02000
unkown
page read and write
clean
16A30660000
unkown
page readonly
clean
207E9318000
unkown
page read and write
clean
2320AA10000
heap default
page read and write
clean
7FF59F0D8000
unkown
page readonly
clean
BFDCBEE000
unkown
page read and write
clean
125215B0000
unkown
page read and write
clean
1F976C13000
unkown
page read and write
clean
7FF4F8848000
unkown
page readonly
clean
207EDFA7000
unkown
page readonly
clean
257A7ED0000
unkown
page readonly
clean
37F5B7E000
unkown
page read and write
clean
506827E000
unkown
page read and write
clean
7FF59EF0B000
unkown
page readonly
clean
7FF552AAE000
unkown
page readonly
clean
7FF59F0C3000
unkown
page readonly
clean
16A300F0000
heap default
page read and write
clean
2320AB00000
unkown
page readonly
clean
16BA77C000
unkown
page read and write
clean
37F61FF000
unkown
page read and write
clean
207E9313000
unkown
page read and write
clean
1EECE7C000
unkown
page read and write
clean
7FF59ED60000
unkown
page readonly
clean
7FF4F8828000
unkown
page readonly
clean
207EDD90000
unkown
page read and write
clean
207EDEE0000
unkown
page read and write
clean
207EE288000
unkown
page read and write
clean
29E8E7B000
unkown
page read and write
clean
7FF59ED25000
unkown
page readonly
clean
2320AD02000
unkown
page read and write
clean
207E9300000
unkown
page read and write
clean
1F976C79000
unkown
page read and write
clean
17063813000
unkown
page read and write
clean
7FF554B78000
unkown
page readonly
clean
7FF4F8939000
unkown
page readonly
clean
7FF5EAF65000
unkown
page readonly
clean
207E8950000
unkown
page read and write
clean
7FF598AE0000
unkown
page readonly
clean
7FF5A758C000
unkown
page readonly
clean
7FF554834000
unkown
page readonly
clean
207EDED4000
unkown
page read and write
clean
17063802000
unkown
page read and write
clean
207E8A8D000
unkown
page read and write
clean
207EDEB0000
unkown
page read and write
clean
7FF5EB079000
unkown
page readonly
clean
185E8BE0000
unkown
page readonly
clean
7FF552BFE000
unkown
page readonly
clean
BFDD1FE000
unkown
page read and write
clean
207EDFB4000
unkown
page write copy
clean
207E9A40000
unkown
page readonly
clean
7FF5DB435000
unkown
page readonly
clean
7FF554B2B000
unkown
page readonly
clean
7FF554C04000
unkown
page readonly
clean
7FF5A739F000
unkown
page readonly
clean
7FF5DB3A0000
unkown
page readonly
clean
7FF4F8930000
unkown
page readonly
clean
207E9A50000
unkown
page readonly
clean
7FF5A7611000
unkown
page readonly
clean
7FF4F8664000
unkown
page readonly
clean
207E8AB7000
unkown
page read and write
clean
7FF598DB4000
unkown
page readonly
clean
2320AC43000
unkown
page read and write
clean
7FF59EF4E000
unkown
page readonly
clean
7FF5A7555000
unkown
page readonly
clean
7FF552BA7000
unkown
page readonly
clean
7FF4F889D000
unkown
page readonly
clean
207E8A2A000
unkown
page read and write
clean
7FF59862D000
unkown
page readonly
clean
1252165B000
unkown
page read and write
clean
7FF59F175000
unkown
page readonly
clean
2320AC70000
unkown
page read and write
clean
7FF59F12F000
unkown
page readonly
clean
207EDF80000
unkown
page read and write
clean
7FF4F880A000
unkown
page readonly
clean
17063770000
unkown
page read and write
clean
12521510000
unkown
page readonly
clean
7FF4F8842000
unkown
page readonly
clean
7FF5DB4A9000
unkown
page readonly
clean
7FF59F0F2000
unkown
page readonly
clean
7FF5A7596000
unkown
page readonly
clean
39D967B000
unkown
page read and write
clean
7FF552B16000
unkown
page readonly
clean
16BAAFD000
unkown
page read and write
clean
185E8C00000
unkown
page read and write
clean
1252165B000
unkown
page read and write
clean
7FF55281C000
unkown
page readonly
clean
39D9C7F000
unkown
page read and write
clean
7FF4F887F000
unkown
page readonly
clean
7FF552B45000
unkown
page readonly
clean
12523200000
unkown
page readonly
clean
207E8B02000
unkown
page read and write
clean
5067D7E000
unkown
page read and write
clean
7FF5DB426000
unkown
page readonly
clean
7FF4F8875000
unkown
page readonly
clean
207E9200000
unkown
page read and write
clean
16A31D10000
heap private
page read and write
clean
207E8B13000
unkown
page read and write
clean
7FF5EB2A9000
unkown
page readonly
clean
7FF598B80000
unkown
page readonly
clean
12521500000
unkown
page readonly
clean
7FF552C09000
unkown
page readonly
clean
7FF5DAFE5000
unkown
page readonly
clean
207E8A71000
unkown
page read and write
clean
7FF598D55000
unkown
page readonly
clean
7FF598554000
unkown
page readonly
clean
7FF5A75B0000
unkown
page readonly
clean
16A300C0000
unkown
page readonly
clean
7FF5DB3A2000
unkown
page readonly
clean
207EE100000
unkown
page read and write
clean
7FF598DB2000
unkown
page readonly
clean
506797E000
unkown
page read and write
clean
7FF59F151000
unkown
page readonly
clean
185E9350000
unkown
page read and write
clean
29E907E000
unkown
page read and write
clean
7FF598E11000
unkown
page readonly
clean
1EECF7D000
unkown
page read and write
clean
1F976D02000
unkown
page read and write
clean
ABD4CFE000
unkown
page read and write
clean
7FF5DB3E5000
unkown
page readonly
clean
37F5AFE000
unkown
page read and write
clean
7FF5DB444000
unkown
page readonly
clean
7FF5DB4A9000
unkown
page readonly
clean
7FF5EB226000
unkown
page readonly
clean
12521600000
unkown
page read and write
clean
207EE060000
unkown
page readonly
clean
7FF5DB210000
unkown
page readonly
clean
7FF59F180000
unkown
page readonly
clean
16A301F0000
unkown
page readonly
clean
7FF5989BD000
unkown
page readonly
clean
7FF4F87AC000
unkown
page readonly
clean
7FF59F1E0000
unkown
page readonly
clean
7FF5A7586000
unkown
page readonly
clean
207E8A98000
unkown
page read and write
clean
7FF598BE9000
unkown
page readonly
clean
7FF4F88BC000
unkown
page readonly
clean
39DA07F000
unkown
page read and write
clean
7FF552B7C000
unkown
page readonly
clean
7FF5EAF70000
unkown
page readonly
clean
37F5FFE000
unkown
page read and write
clean
185E8ED0000
unkown
page readonly
clean
7FF5EB18C000
unkown
page readonly
clean
7FF598D08000
unkown
page readonly
clean
7FF59EE97000
unkown
page readonly
clean
7FF554885000
unkown
page readonly
clean
207E9D90000
unkown
page read and write
clean
7FF598C27000
unkown
page readonly
clean
7FF4F881C000
unkown
page readonly
clean
257A7C64000
unkown
page read and write
clean
12523002000
unkown
page read and write
clean
125213C0000
heap private
page read and write
clean
7FF59EFB9000
unkown
page readonly
clean
207E8A76000
unkown
page read and write
clean
BFDCB6C000
unkown
page read and write
clean
7FF5EB1EF000
unkown
page readonly
clean
1252162A000
unkown
page read and write
clean
12521713000
unkown
page read and write
clean
207EE21F000
unkown
page read and write
clean
207E9A10000
unkown
page readonly
clean
7FF552AB4000
unkown
page readonly
clean
7FF5DB41C000
unkown
page readonly
clean
7FF59E9FF000
unkown
page readonly
clean
7FF4F8830000
unkown
page readonly
clean
7FF4F88D7000
unkown
page readonly
clean
7FF598D96000
unkown
page readonly
clean
207EDFB7000
unkown
page write copy
clean
37F5CFF000
unkown
page read and write
clean
16BABFE000
unkown
page read and write
clean
7FF4F88B6000
unkown
page readonly
clean
1706385B000
unkown
page read and write
clean
257A8260000
unkown
page readonly
clean
2320B1B0000
unkown
page write copy
clean
207EE0F0000
unkown
page readonly
clean
7FF552B1A000
unkown
page readonly
clean
7FF4F87B7000
unkown
page readonly
clean
12521800000
unkown
page readonly
clean
1EECC7F000
unkown
page read and write
clean
7FF5A6D50000
unkown
page readonly
clean
7FF59F1E9000
unkown
page readonly
clean
7FF5DB38C000
unkown
page readonly
clean
207E8960000
unkown
page read and write
clean
1EEC87B000
unkown
page read and write
clean
7FF5DB0DE000
unkown
page readonly
clean
BFDD0FF000
unkown
page read and write
clean
7FF554BB9000
unkown
page readonly
clean
37F5A7B000
unkown
page read and write
clean
7FF59F1E9000
unkown
page readonly
clean
2320AC00000
unkown
page read and write
clean
12521668000
unkown
page read and write
clean
506847E000
unkown
page read and write
clean
37F5F7D000
unkown
page read and write
clean
7FF5A7528000
unkown
page readonly
clean
7FF552C09000
unkown
page readonly
clean
5067B7C000
unkown
page read and write
clean
7FF598BB8000
unkown
page readonly
clean
1F977600000
unkown
page readonly
clean
7FF5EB216000
unkown
page readonly
clean
7FF5EA9EE000
unkown
page readonly
clean
7FF59EE6C000
unkown
page readonly
clean
17063670000
heap default
page read and write
clean
7FF59F0F8000
unkown
page readonly
clean
7FF59F0A1000
unkown
page readonly
clean
7FF552B18000
unkown
page readonly
clean
7FF59F055000
unkown
page readonly
clean
207EDFC0000
unkown
page read and write
clean
7FF59F14D000
unkown
page readonly
clean
7FF5A757D000
unkown
page readonly
clean
7FF5DB398000
unkown
page readonly
clean
7FF5EAF57000
unkown
page readonly
clean
257A7D02000
unkown
page read and write
clean
207E89E0000
unkown
page read and write
clean
207E9910000
unkown
page read and write
clean
ABD507F000
unkown
page read and write
clean
17063913000
unkown
page read and write
clean
1EEC8FD000
unkown
page read and write
clean
7FF598D9C000
unkown
page readonly
clean
7FF4F86D8000
unkown
page readonly
clean
16A300FB000
heap default
page read and write
clean
7FF5A7619000
unkown
page readonly
clean
207E89F0000
unkown
page read and write
clean
207EDFF0000
unkown
page read and write
clean
257A7C30000
unkown
page read and write
clean
7FF4F8586000
unkown
page readonly
clean
7FF598D10000
unkown
page readonly
clean
7FF5EB1B8000
unkown
page readonly
clean
12521718000
unkown
page read and write
clean
BFDD3FB000
unkown
page read and write
clean
2320B300000
unkown
page read and write
clean
ABD4F7E000
unkown
page read and write
clean
ABD4D7E000
unkown
page read and write
clean
7FF59EFA8000
unkown
page readonly
clean
7FF5DB1D7000
unkown
page readonly
clean
7FF5EB1B6000
unkown
page readonly
clean
37F5E7E000
unkown
page read and write
clean
16A30050000
unkown
page read and write
clean
7FF554823000
unkown
page readonly
clean
17063854000
unkown
page read and write
clean
207E89C1000
unkown
page read and write
clean
7FF598D7D000
unkown
page readonly
clean
7FF4F875C000
unkown
page readonly
clean
125215F0000
unkown
page read and write
clean
1252168C000
unkown
page read and write
clean
BFDD4FD000
unkown
page read and write
clean
50678FB000
unkown
page read and write
clean
207EE000000
unkown
page read and write
clean
7FF598A7D000
unkown
page readonly
clean
7FF59F139000
unkown
page readonly
clean
29E8AFE000
unkown
page read and write
clean
17063D90000
unkown
page readonly
clean
17063610000
heap private
page read and write
clean
2320AA20000
unkown
page readonly
clean
506817F000
unkown
page read and write
clean
7FF59F156000
unkown
page readonly
clean
7FF55237A000
unkown
page readonly
clean
7FF5A753A000
unkown
page readonly
clean
7FF59F11E000
unkown
page readonly
clean
7FF554BDC000
unkown
page readonly
clean
7FF554B62000
unkown
page readonly
clean
1F977190000
unkown
page readonly
clean
7FF554BD6000
unkown
page readonly
clean
1252167D000
unkown
page read and write
clean
39D9F7C000
unkown
page read and write
clean
207EE295000
unkown
page read and write
clean
7FF4F856E000
unkown
page readonly
clean
7FF598D12000
unkown
page readonly
clean
207E9830000
unkown
page read and write
clean
7FF598AD5000
unkown
page readonly
clean
ABD517F000
unkown
page read and write
clean
207EE070000
unkown
page readonly
clean
7FF554B9E000
unkown
page readonly
clean
207E9318000
unkown
page read and write
clean
7FF5EB198000
unkown
page readonly
clean
207E9800000
unkown
page readonly
clean
7FF59F10A000
unkown
page readonly
clean
7FF598D69000
unkown
page readonly
clean
7FF5DB357000
unkown
page readonly
clean
7FF552883000
unkown
page readonly
clean
207E8F90000
unkown
page readonly
clean
207E89E3000
unkown
page read and write
clean
17063800000
unkown
page read and write
clean
7FF59F1DE000
unkown
page readonly
clean
7FF5EB1DE000
unkown
page readonly
clean
207EE050000
unkown
page readonly
clean
7FF554BE6000
unkown
page readonly
clean
506837E000
unkown
page read and write
clean
207E87F0000
heap private
page read and write
clean
7FF5A7526000
unkown
page readonly
clean
7FF552BB2000
unkown
page readonly
clean
16A31BA0000
heap private
page read and write
clean
39D9A7F000
unkown
page read and write
clean
257A7C00000
unkown
page read and write
clean
7FF59EDED000
unkown
page readonly
clean
207E8A56000
unkown
page read and write
clean
2320A9B0000
heap private
page read and write
clean
7FF598D04000
unkown
page readonly
clean
7FF552B95000
unkown
page readonly
clean
7FF59F0AB000
unkown
page readonly
clean
7FF5A6D52000
unkown
page readonly
clean
16A30080000
unkown
page readonly
clean
7FF5DB3DE000
unkown
page readonly
clean
50675CD000
unkown
page read and write
clean
7FF4F88D4000
unkown
page readonly
clean
257A7B50000
heap private
page read and write
clean
7FF552B71000
unkown
page readonly
clean
207E9359000
unkown
page read and write
clean
185E9402000
unkown
page read and write
clean
16A321F0000
heap private
page read and write
clean
1252165A000
unkown
page read and write
clean
7FF59F125000
unkown
page readonly
clean
1F976C02000
unkown
page read and write
clean
7FF554827000
unkown
page readonly
clean
7FF5EB2A9000
unkown
page readonly
clean
7FF5A760E000
unkown
page readonly
clean
16A302C5000
heap private
page read and write
clean
39D9D7B000
unkown
page read and write
clean
There are 671 hidden memdumps, click here to show them.

DOM / HTML

URL
Malicious
https://zauthxcovidtestinnt0kajxktkatak0jtt0a0jnkowauath.fra1.cdn.digitaloceanspaces.com/index.htm?=en-US&username=martha.rodriguez@schulergroup.com
malicious
https://privacy.microsoft.com/en-US/privacystatement
clean
https://signup.live.com/signup?ru=https%3a%2f%2flogin.live.com%2foauth20_authorize.srf%3flc%3d1033%26response_type%3dcode%26client_id%3d51483342-085c-4d86-bf88-cf50c7252078%26scope%3dopenid%2bprofile%2bemail%2boffline_access%26response_mode%3dform_post%26redirect_uri%3dhttps%253a%252f%252flogin.microsoftonline.com%252fcommon%252ffederation%252foauth2%26state%3drQIIAeNisNLJKCkpKLbS1y_ILypJzNHLzUwuyi_OTyvJz8vJzEvVS87P1csvSs9MAbGKhLgE5N-HsRnaz3GZ3Nb0o0aAj2MWI2d8TmYZWOUqRmXCxulfYGR8wch4i0nQvyjdMyW82C01JbUosSQzP-8Ci8ArFh4DZisODi4BBgkGBYYfLIyLWIG2Rik0X16_dbXTrqAUuYQeZ4ZTrPpRVd4W-b7mmV4ppv5hlW6-lqaluRYWHrl5XtppBkXhQUUhmQElZWVGAaGBtqZWhhPYhCawMZ1iY_jAxtjBznCAk_EWl4iRgaGlroGRroGJgoGllZGRlbFRFAA1%26estsfed%3d1%26lw%3d1%26fl%3deasi2%26fci%3dhttps%253a%252f%252fportal.microsoftonline.com.orgid.com%26mkt%3dEN-US%26uaid%3d0656ef1f3f31449c938682f87c100e08&mkt=EN-US&uiflavor=web&lw=1&fl=easi2&client_id=51483342-085c-4d86-bf88-cf50c7252078&uaid=0656ef1f3f31449c938682f87c100e08&suc=https%3a%2f%2fportal.microsoftonline.com.orgid.com&lic=1
clean
https://account.live.com/ResetPassword.aspx?wreply=https://login.live.com/oauth20_authorize.srf%3fresponse_type%3dcode%26client_id%3d51483342-085c-4d86-bf88-cf50c7252078%26scope%3dopenid%2bprofile%2bemail%2boffline_access%26response_mode%3dform_post%26redirect_uri%3dhttps%253a%252f%252flogin.microsoftonline.com%252fcommon%252ffederation%252foauth2%26state%3drQIIAeNisNLJKCkpKLbS1y_ILypJzNHLzUwuyi_OTyvJz8vJzEvVS87P1csvSs9MAbGKhLgEOhzkFBYXR3m11Zle3FvBmjCLkTM-J7MMrHIVozJh4_QvMDK-YGS8xSToX5TumRJe7JaaklqUWJKZn3eBReAVC48BsxUHB5cAgwSDAsMPFsZFrEBb40pDQg3r0t0nbto2zWOTN8MpVv2oKm-LfF_zTK8UU_-wSjdfS9PSXAsLj9w8L-00g6LwoKKQzICSsjKjgNBAWwsrwwlsQhPYmE6xMXxgY-xgZzjAyXiLS8TIwNBS18BI18BEwcDCysTCytgkCgA1%26estsfed%3d1%26uaid%3d201e408873a34a5a867e35d1bd780560%26fci%3dhttps%253a%252f%252fportal.microsoftonline.com.orgid.com%26username%3d%26contextid%3d34A42CC81359F79A%26bk%3d1549270157&id=293577&uiflavor=web&client_id=1E00004417ACAE&mkt=EN-US&lc=1033&bk=1549270157
clean
https://www.microsoft.com/en-US/servicesagreement/
clean