Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
Sample_B.exe
|
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
|
initial sample
|
||
C:\Users\user\AppData\Roaming\Windows Update.exe
|
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Roaming\Windows Update.exe:Zone.Identifier
|
ASCII text, with CRLF line terminators
|
modified
|
||
C:\Users\user\AppData\Roaming\WindowsUpdate.exe
|
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Roaming\WindowsUpdate.exe:Zone.Identifier
|
ASCII text, with CRLF line terminators
|
modified
|
||
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\3C428B1A3E5F57D887EC4B864FAC5DCC
|
data
|
dropped
|
||
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
|
Microsoft Cabinet archive data, 59134 bytes, 1 file
|
dropped
|
||
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\3C428B1A3E5F57D887EC4B864FAC5DCC
|
data
|
dropped
|
||
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_windows update.e_8def7a6b85a0513a7da3debaf0f7a2c3a14caff_0b1db1a4\Report.wer
|
data
|
modified
|
||
C:\Users\user\AppData\Local\Temp\CabAB00.tmp
|
Microsoft Cabinet archive data, 59134 bytes, 1 file
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\SysInfo.txt
|
ASCII text, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\TarAB01.tmp
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\WERA42C.tmp.WERInternalMetadata.xml
|
XML 1.0 document, Little-endian UTF-16 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Roaming\pid.txt
|
ASCII text, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Roaming\pidloc.txt
|
ASCII text, with no line terminators
|
dropped
|
There are 6 hidden files, click here to show them.
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\Sample_B.exe
|
'C:\Users\user\Desktop\Sample_B.exe'
|
||
C:\Users\user\AppData\Roaming\Windows Update.exe
|
'C:\Users\user\AppData\Roaming\Windows Update.exe'
|
||
C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe
|
C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe /stext 'C:\Users\user\AppData\Local\Temp\holdermail.txt'
|
||
C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe
|
C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe /stext 'C:\Users\user\AppData\Local\Temp\holderwb.txt'
|
||
C:\Windows\Microsoft.NET\Framework\v2.0.50727\dw20.exe
|
dw20.exe -x -s 1708
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://www.windows.com/pctv.
|
unknown
|
||
http://investor.msn.com
|
unknown
|
||
http://www.msnbc.com/news/ticker.txt
|
unknown
|
||
http://crl.entrust.net/server1.crl0
|
unknown
|
||
http://ocsp.entrust.net03
|
unknown
|
||
http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl0
|
unknown
|
||
http://pki.goog/gsr2/GTS1O1.crt0
|
unknown
|
||
http://www.diginotar.nl/cps/pkioverheid0
|
unknown
|
||
http://ocsp.pki.goog/gsr202
|
unknown
|
||
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
|
unknown
|
||
http://www.hotmail.com/oe
|
unknown
|
||
https://pki.goog/repository/0
|
unknown
|
||
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
|
unknown
|
||
http://crl.pkioverheid.nl/DomOvLatestCRL.crl0
|
unknown
|
||
http://www.icra.org/vocabulary/.
|
unknown
|
||
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
|
unknown
|
||
http://ocsp.pki.goog/gts1o1core0
|
unknown
|
||
http://investor.msn.com/
|
unknown
|
||
http://crl.pki.goog/GTS1O1core.crl0
|
unknown
|
||
http://whatismyipaddress.com/-
|
unknown
|
||
http://www.%s.comPA
|
unknown
|
||
https://login.yahoo.com/config/login
|
unknown
|
||
http://www.site.com/logs.php
|
unknown
|
||
http://whatismyipaddress.com/
|
104.16.155.36
|
||
http://crl.pki.goog/gsr2/gsr2.crl0?
|
unknown
|
||
http://www.nirsoft.net/
|
unknown
|
||
http://ocsp.entrust.net0D
|
unknown
|
||
https://secure.comodo.com/CPS0
|
unknown
|
||
http://crl.entrust.net/2048ca.crl0
|
unknown
|
There are 19 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
163.190.5.0.in-addr.arpa
|
unknown
|
||
whatismyipaddress.com
|
104.16.155.36
|
||
cdn.digicertcdn.com
|
104.18.10.39
|
||
smtp.gmail.com
|
66.102.1.108
|
IPs
IP
|
Domain
|
Country
|
Active
|
Malicious
|
|
---|---|---|---|---|---|
104.16.155.36
|
unknown
|
United States
|
unknown
|
||
66.102.1.108
|
unknown
|
United States
|
unknown
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
C:\Users\user\AppData\Roaming\Windows Update.exe
|
Hidden
|
||
C:\Users\user\Desktop\Sample_B.exe
|
FontCachePath
|
||
C:\Users\user\AppData\Roaming\Windows Update.exe
|
EnableFileTracing
|
||
C:\Users\user\AppData\Roaming\Windows Update.exe
|
EnableConsoleTracing
|
||
C:\Users\user\AppData\Roaming\Windows Update.exe
|
FileTracingMask
|
||
C:\Users\user\AppData\Roaming\Windows Update.exe
|
ConsoleTracingMask
|
||
C:\Users\user\AppData\Roaming\Windows Update.exe
|
MaxFileSize
|
||
C:\Users\user\AppData\Roaming\Windows Update.exe
|
FileDirectory
|
||
C:\Users\user\AppData\Roaming\Windows Update.exe
|
EnableFileTracing
|
||
C:\Users\user\AppData\Roaming\Windows Update.exe
|
EnableConsoleTracing
|
||
C:\Users\user\AppData\Roaming\Windows Update.exe
|
FileTracingMask
|
||
C:\Users\user\AppData\Roaming\Windows Update.exe
|
ConsoleTracingMask
|
||
C:\Users\user\AppData\Roaming\Windows Update.exe
|
MaxFileSize
|
||
C:\Users\user\AppData\Roaming\Windows Update.exe
|
FileDirectory
|
||
C:\Users\user\AppData\Roaming\Windows Update.exe
|
Windows Update
|
||
C:\Users\user\AppData\Roaming\Windows Update.exe
|
Blob
|
||
C:\Users\user\AppData\Roaming\Windows Update.exe
|
Blob
|
||
C:\Users\user\AppData\Roaming\Windows Update.exe
|
Blob
|
||
C:\Users\user\AppData\Roaming\Windows Update.exe
|
Blob
|
||
C:\Users\user\AppData\Roaming\Windows Update.exe
|
Blob
|
||
C:\Users\user\AppData\Roaming\Windows Update.exe
|
Blob
|
There are 11 hidden registries, click here to show them.
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
BC2000
|
unkown image
|
page execute read
|
||
3610000
|
unkown
|
page read and write
|
||
EE2000
|
unkown image
|
page execute read
|
||
3371000
|
unkown
|
page read and write
|
||
EE2000
|
unkown image
|
page execute read
|
||
BC2000
|
unkown image
|
page execute read
|
||
2371000
|
unkown
|
page read and write
|
||
54A9000
|
unkown
|
page read and write
|
||
BA0000
|
unkown
|
page readonly
|
||
99AF000
|
stack
|
page read and write
|
||
1A0000
|
unkown
|
page read and write
|
||
B9E000
|
unkown
|
page read and write | page guard
|
||
20000
|
unkown
|
page read and write
|
||
4422000
|
heap private
|
page read and write
|
||
50D2000
|
unkown
|
page read and write
|
||
1F9000
|
stack
|
page read and write
|
||
685D000
|
unkown
|
page read and write
|
||
F9000
|
unkown
|
page read and write
|
||
A70000
|
unkown
|
page read and write
|
||
A10000
|
unkown
|
page readonly
|
||
76E2000
|
unkown
|
page readonly
|
||
76B4000
|
unkown
|
page readonly
|
||
608F000
|
stack
|
page read and write
|
||
5E0000
|
heap private
|
page read and write
|
||
6B7C000
|
unkown
|
page read and write
|
||
68EC000
|
unkown
|
page read and write
|
||
6E3E000
|
unkown
|
page read and write
|
||
F62000
|
unkown image
|
page readonly
|
||
6A60000
|
unkown
|
page read and write
|
||
F0000
|
unkown
|
page read and write
|
||
6F0B000
|
unkown
|
page read and write
|
||
7712000
|
unkown
|
page readonly
|
||
827000
|
heap private
|
page read and write
|
||
6942000
|
unkown
|
page read and write
|
||
2D2000
|
unkown
|
page read and write
|
||
6EBA000
|
unkown
|
page read and write
|
||
4790000
|
unkown
|
page read and write
|
||
6E56000
|
unkown
|
page read and write
|
||
6B8B000
|
unkown
|
page read and write
|
||
4400000
|
heap private
|
page read and write
|
||
2A9000
|
stack
|
page read and write
|
||
ED0000
|
unkown
|
page read and write
|
||
7294000
|
unkown
|
page read and write
|
||
29A000
|
unkown
|
page execute and read and write
|
||
46F0000
|
unkown
|
page read and write
|
||
6610000
|
heap private
|
page read and write
|
||
3490000
|
unkown
|
page read and write
|
||
66B2000
|
unkown
|
page read and write
|
||
36A7000
|
unkown
|
page read and write
|
||
9C0000
|
unkown
|
page readonly
|
||
6947000
|
unkown
|
page read and write
|
||
4F1000
|
unkown
|
page read and write
|
||
7A40000
|
unkown
|
page readonly
|
||
491E000
|
unkown
|
page read and write
|
||
3AB000
|
unkown
|
page read and write
|
||
47A0000
|
unkown
|
page read and write
|
||
5034000
|
unkown
|
page read and write
|
||
4370000
|
unkown
|
page read and write
|
||
505C000
|
unkown
|
page read and write
|
||
5640000
|
unkown
|
page read and write
|
||
5093000
|
unkown
|
page read and write
|
||
7725000
|
unkown
|
page readonly
|
||
6AB2000
|
unkown
|
page read and write
|
||
2E0000
|
heap private
|
page read and write
|
||
64EB000
|
unkown
|
page read and write
|
||
400000
|
unkown
|
page execute and read and write
|
||
7672000
|
unkown
|
page readonly
|
||
7694000
|
unkown
|
page readonly
|
||
33F0000
|
unkown
|
page read and write
|
||
FC000
|
unkown
|
page read and write
|
||
6553000
|
unkown
|
page read and write
|
||
7966000
|
unkown
|
page read and write
|
||
2C0000
|
unkown
|
page read and write
|
||
51EF000
|
unkown
|
page read and write
|
||
B50000
|
unkown
|
page readonly
|
||
BC0000
|
unkown image
|
page readonly
|
||
69D1000
|
unkown
|
page read and write
|
||
70000
|
unkown
|
page read and write
|
||
4700000
|
unkown
|
page read and write
|
||
6A0A000
|
unkown
|
page read and write
|
||
395000
|
unkown
|
page read and write
|
||
A10C000
|
stack
|
page read and write
|
||
3A7000
|
unkown
|
page read and write
|
||
8A0000
|
heap default
|
page read and write
|
||
4450000
|
heap private
|
page read and write
|
||
390000
|
unkown
|
page read and write
|
||
4404000
|
heap private
|
page read and write
|
||
397000
|
unkown
|
page read and write
|
||
3590000
|
unkown
|
page read and write
|
||
4490000
|
unkown
|
page read and write
|
||
7971000
|
unkown
|
page read and write
|
||
883E000
|
unkown
|
page readonly
|
||
6850000
|
unkown
|
page read and write
|
||
9BAE000
|
stack
|
page read and write
|
||
76B2000
|
unkown
|
page readonly
|
||
672A000
|
unkown
|
page read and write
|
||
54DA000
|
unkown
|
page read and write
|
||
AC0000
|
unkown
|
page read and write
|
||
7EFDF000
|
unkown
|
page read and write
|
||
6B4E000
|
unkown
|
page read and write
|
||
2100000
|
heap private
|
page read and write
|
||
43E0000
|
unkown
|
page readonly
|
||
61CB000
|
unkown
|
page read and write
|
||
93CE000
|
stack
|
page read and write
|
||
49EF000
|
stack
|
page read and write
|
||
6A1E000
|
unkown
|
page read and write
|
||
6E40000
|
unkown
|
page read and write
|
||
2F6000
|
unkown
|
page read and write
|
||
7EFDF000
|
unkown
|
page read and write
|
||
390000
|
unkown
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
622000
|
heap private
|
page execute and read and write
|
||
7D7D000
|
unkown
|
page readonly
|
||
18E000
|
unkown
|
page read and write
|
||
69D7000
|
unkown
|
page read and write
|
||
2531000
|
unkown
|
page read and write
|
||
505D000
|
unkown
|
page read and write
|
||
6A46000
|
unkown
|
page read and write
|
||
6A92000
|
unkown
|
page read and write
|
||
4490000
|
unkown
|
page read and write
|
||
5640000
|
unkown
|
page read and write
|
||
6E14000
|
unkown
|
page read and write
|
||
50A2000
|
unkown
|
page read and write
|
||
45FE000
|
stack
|
page read and write
|
||
579E000
|
stack
|
page read and write
|
||
58FF000
|
unkown
|
page read and write
|
||
6EF9000
|
unkown
|
page read and write
|
||
5C17000
|
unkown
|
page readonly
|
||
4630000
|
unkown
|
page readonly
|
||
5360000
|
unkown
|
page read and write
|
||
7692000
|
unkown
|
page readonly
|
||
5640000
|
unkown
|
page read and write
|
||
4490000
|
unkown
|
page read and write
|
||
3688000
|
unkown
|
page read and write
|
||
553E000
|
stack
|
page read and write
|
||
447000
|
heap default
|
page read and write
|
||
80000
|
unkown
|
page readonly
|
||
691E000
|
unkown
|
page read and write
|
||
650000
|
unkown
|
page readonly
|
||
5093000
|
unkown
|
page read and write
|
||
6D11000
|
unkown
|
page read and write
|
||
3688000
|
unkown
|
page read and write
|
||
3AE000
|
unkown
|
page read and write
|
||
5C0E000
|
stack
|
page read and write
|
||
43C0000
|
unkown
|
page readonly
|
||
50EE000
|
stack
|
page read and write
|
||
660000
|
heap private
|
page read and write
|
||
5840000
|
heap private
|
page read and write
|
||
8282000
|
unkown
|
page readonly
|
||
1F7000
|
unkown
|
page read and write | page guard
|
||
5398000
|
unkown
|
page read and write
|
||
35B0000
|
unkown
|
page read and write
|
||
7310000
|
unkown
|
page read and write
|
||
44A0000
|
unkown
|
page readonly
|
||
36C7000
|
unkown
|
page read and write
|
||
51F0000
|
unkown image
|
page readonly
|
||
390000
|
unkown
|
page read and write
|
||
6A25000
|
unkown
|
page read and write
|
||
4B0000
|
unkown
|
page readonly
|
||
5F0000
|
unkown
|
page readonly
|
||
540000
|
unkown
|
page read and write
|
||
6A8F000
|
unkown
|
page read and write
|
||
260000
|
unkown
|
page read and write
|
||
6825000
|
unkown
|
page read and write
|
||
67F4000
|
unkown
|
page read and write
|
||
6FEE000
|
unkown
|
page read and write
|
||
51E0000
|
heap private
|
page read and write
|
||
29B8000
|
unkown
|
page read and write
|
||
9CC000
|
unkown
|
page readonly
|
||
7075000
|
unkown
|
page read and write
|
||
570000
|
unkown
|
page readonly
|
||
6795000
|
unkown
|
page read and write
|
||
53F6000
|
unkown
|
page read and write
|
||
2BA000
|
unkown
|
page execute and read and write
|
||
588E000
|
unkown
|
page read and write
|
||
6DC4000
|
unkown
|
page read and write
|
||
6A0D000
|
unkown
|
page read and write
|
||
3530000
|
unkown
|
page read and write
|
||
49F0000
|
unkown
|
page readonly
|
||
5D0000
|
unkown
|
page execute and read and write
|
||
3A6000
|
unkown
|
page read and write
|
||
67EA000
|
unkown
|
page read and write
|
||
4790000
|
unkown
|
page read and write
|
||
66DB000
|
unkown
|
page read and write
|
||
4F1000
|
unkown
|
page read and write
|
||
9C7000
|
unkown
|
page readonly
|
||
44B0000
|
unkown
|
page read and write
|
||
8A000
|
unkown
|
page read and write
|
||
76AE000
|
unkown
|
page read and write
|
||
34D0000
|
unkown
|
page read and write
|
||
6D6C000
|
stack
|
page read and write
|
||
5AF000
|
unkown
|
page read and write
|
||
7EFDF000
|
unkown
|
page read and write
|
||
78DC000
|
unkown
|
page read and write
|
||
48AE000
|
unkown
|
page read and write
|
||
A10000
|
unkown
|
page read and write
|
||
565D000
|
unkown
|
page read and write
|
||
225E000
|
unkown
|
page read and write | page guard
|
||
397000
|
unkown
|
page read and write
|
||
5497000
|
unkown
|
page read and write
|
||
5604000
|
heap private
|
page read and write
|
||
4440000
|
unkown
|
page read and write
|
||
44A0000
|
unkown
|
page read and write
|
||
68BC000
|
stack
|
page read and write
|
||
50E6000
|
unkown
|
page read and write
|
||
6F16000
|
unkown
|
page read and write
|
||
4C2000
|
heap default
|
page read and write
|
||
549A000
|
unkown
|
page read and write
|
||
5460000
|
unkown
|
page read and write
|
||
2260000
|
unkown
|
page readonly
|
||
64D0000
|
unkown
|
page read and write
|
||
6A54000
|
unkown
|
page read and write
|
||
71E6000
|
unkown
|
page read and write
|
||
A5D000
|
unkown
|
page read and write
|
||
35F0000
|
unkown
|
page read and write
|
||
3B9000
|
unkown
|
page read and write
|
||
18E000
|
unkown
|
page read and write
|
||
76F5000
|
unkown
|
page readonly
|
||
F0000
|
unkown
|
page readonly
|
||
4490000
|
unkown
|
page read and write
|
||
6C08000
|
unkown
|
page read and write
|
||
77B2000
|
unkown
|
page readonly
|
||
6940000
|
unkown
|
page read and write
|
||
27A000
|
unkown
|
page execute and read and write
|
||
51E5000
|
heap private
|
page read and write
|
||
4C0000
|
unkown
|
page readonly
|
||
6A51000
|
unkown
|
page read and write
|
||
6DF3000
|
unkown
|
page read and write
|
||
54A1000
|
unkown
|
page read and write
|
||
50E6000
|
unkown
|
page read and write
|
||
550000
|
unkown
|
page execute and read and write
|
||
2A7000
|
unkown
|
page read and write | page guard
|
||
9A0000
|
unkown
|
page read and write
|
||
5077000
|
unkown
|
page read and write
|
||
69BE000
|
unkown
|
page read and write
|
||
6E78000
|
unkown
|
page read and write
|
||
A10000
|
unkown
|
page readonly
|
||
79E0000
|
unkown
|
page readonly
|
||
5640000
|
unkown
|
page read and write
|
||
6BB8000
|
unkown
|
page read and write
|
||
36C7000
|
unkown
|
page read and write
|
||
37C000
|
heap default
|
page read and write
|
||
B9F000
|
unkown
|
page read and write
|
||
578E000
|
unkown
|
page read and write
|
||
33B0000
|
unkown
|
page read and write
|
||
6E8B000
|
unkown
|
page read and write
|
||
6E05000
|
unkown
|
page read and write
|
||
5EEE000
|
stack
|
page read and write
|
||
ED0000
|
unkown
|
page read and write
|
||
6DFE000
|
unkown
|
page read and write
|
||
143000
|
heap default
|
page read and write
|
||
7321000
|
unkown
|
page read and write
|
||
67C8000
|
unkown
|
page read and write
|
||
69BA000
|
unkown
|
page read and write
|
||
604000
|
heap private
|
page execute and read and write
|
||
7835000
|
unkown
|
page readonly
|
||
6D6B000
|
unkown
|
page read and write
|
||
5ADB000
|
unkown
|
page read and write
|
||
5640000
|
unkown
|
page read and write
|
||
4490000
|
unkown
|
page read and write
|
||
867F000
|
unkown
|
page readonly
|
||
5640000
|
unkown
|
page read and write
|
||
44C0000
|
heap private
|
page read and write
|
||
3A6000
|
unkown
|
page read and write
|
||
6939000
|
unkown
|
page read and write
|
||
D0000
|
heap default
|
page read and write
|
||
67F0000
|
unkown
|
page read and write
|
||
477E000
|
unkown
|
page read and write
|
||
53C4000
|
unkown
|
page read and write
|
||
6C92000
|
unkown
|
page read and write
|
||
3410000
|
unkown
|
page read and write
|
||
6884000
|
unkown
|
page read and write
|
||
990000
|
unkown
|
page read and write
|
||
7C72000
|
unkown
|
page readonly
|
||
4BB000
|
heap default
|
page read and write
|
||
6CD9000
|
unkown
|
page read and write
|
||
790000
|
unkown
|
page readonly
|
||
927B000
|
stack
|
page read and write
|
||
6527000
|
unkown
|
page read and write
|
||
66B0000
|
heap private
|
page read and write
|
||
2A6000
|
unkown
|
page read and write
|
||
11A000
|
unkown
|
page execute and read and write
|
||
53A0000
|
heap private
|
page read and write
|
||
505C000
|
unkown
|
page read and write
|
||
74B8000
|
unkown
|
page readonly
|
||
5640000
|
unkown
|
page read and write
|
||
7819000
|
unkown
|
page readonly
|
||
5640000
|
unkown
|
page read and write
|
||
650000
|
heap private
|
page read and write
|
||
5C9E000
|
unkown
|
page read and write
|
||
A80000
|
heap private
|
page execute and read and write
|
||
7DDA000
|
unkown
|
page readonly
|
||
9860000
|
heap private
|
page execute and read and write
|
||
6A17000
|
unkown
|
page read and write
|
||
6E35000
|
unkown
|
page read and write
|
||
77E2000
|
unkown
|
page readonly
|
||
613E000
|
stack
|
page read and write
|
||
2DB000
|
unkown
|
page execute and read and write
|
||
50F0000
|
unkown
|
page write copy
|
||
8DA0000
|
unkown
|
page readonly
|
||
77B9000
|
unkown
|
page readonly
|
||
543C000
|
unkown
|
page read and write
|
||
79A2000
|
unkown
|
page readonly
|
||
EE0000
|
unkown image
|
page readonly
|
||
970A000
|
stack
|
page read and write
|
||
2B6000
|
unkown
|
page execute and read and write
|
||
324000
|
heap default
|
page read and write
|
||
6EC5000
|
unkown
|
page read and write
|
||
C42000
|
unkown image
|
page readonly
|
||
4490000
|
unkown
|
page read and write
|
||
658E000
|
unkown
|
page read and write
|
||
51EE000
|
unkown
|
page read and write | page guard
|
||
307000
|
heap default
|
page read and write
|
||
668E000
|
unkown
|
page read and write
|
||
3BB000
|
unkown
|
page read and write
|
||
1F6000
|
unkown
|
page read and write
|
||
7B01000
|
unkown
|
page readonly
|
||
67F7000
|
unkown
|
page read and write
|
||
640000
|
unkown
|
page execute and read and write
|
||
2C2000
|
unkown
|
page execute and read and write
|
||
8255000
|
unkown
|
page readonly
|
||
36A7000
|
unkown
|
page read and write
|
||
2050000
|
unkown
|
page readonly
|
||
12A000
|
unkown
|
page read and write
|
||
6A67000
|
unkown
|
page read and write
|
||
3B1000
|
unkown
|
page read and write
|
||
8D000
|
unkown
|
page read and write
|
||
6E97000
|
unkown
|
page read and write
|
||
2E7000
|
heap private
|
page read and write
|
||
670000
|
unkown
|
page readonly
|
||
69C3000
|
unkown
|
page read and write
|
||
43D0000
|
unkown
|
page read and write
|
||
299E000
|
unkown
|
page read and write
|
||
4AE000
|
unkown
|
page read and write
|
||
561000
|
unkown
|
page read and write
|
||
600000
|
heap private
|
page execute and read and write
|
||
640000
|
unkown
|
page readonly
|
||
6670000
|
unkown
|
page read and write
|
||
5540000
|
unkown
|
page read and write
|
||
4FF0000
|
unkown
|
page read and write
|
||
2AA000
|
unkown
|
page execute and read and write
|
||
54A2000
|
unkown
|
page read and write
|
||
6FF9000
|
unkown
|
page read and write
|
||
4798000
|
unkown
|
page read and write
|
||
66F0000
|
unkown
|
page read and write
|
||
677D000
|
unkown
|
page read and write
|
||
523E000
|
unkown
|
page read and write
|
||
542D000
|
unkown
|
page read and write
|
||
58FE000
|
unkown
|
page read and write | page guard
|
||
478E000
|
unkown
|
page read and write
|
||
6DAE000
|
unkown
|
page read and write
|
||
430000
|
unkown
|
page readonly
|
||
3450000
|
unkown
|
page read and write
|
||
47FD000
|
unkown
|
page read and write
|
||
538E000
|
unkown
|
page read and write
|
||
E9000
|
unkown
|
page read and write
|
||
5AB000
|
unkown
|
page readonly
|
||
634A000
|
unkown
|
page read and write
|
||
7796000
|
unkown
|
page readonly
|
||
36C7000
|
unkown
|
page read and write
|
||
3688000
|
unkown
|
page read and write
|
||
1C0000
|
unkown
|
page readonly
|
||
5421000
|
unkown
|
page read and write
|
||
666E000
|
unkown
|
page read and write
|
||
69C6000
|
unkown
|
page read and write
|
||
4E7000
|
heap default
|
page read and write
|
||
44B0000
|
unkown
|
page read and write
|
||
C42000
|
unkown image
|
page readonly
|
||
810000
|
unkown
|
page readonly
|
||
950A000
|
stack
|
page read and write
|
||
5640000
|
unkown
|
page read and write
|
||
36C7000
|
unkown
|
page read and write
|
||
BC0000
|
unkown image
|
page readonly
|
||
5600000
|
heap private
|
page read and write
|
||
29BA000
|
unkown
|
page read and write
|
||
1C0000
|
unkown
|
page readonly
|
||
34B0000
|
unkown
|
page read and write
|
||
5EC000
|
heap private
|
page read and write
|
||
62FE000
|
stack
|
page read and write
|
||
3470000
|
unkown
|
page read and write
|
||
5640000
|
unkown
|
page read and write
|
||
20000
|
unkown
|
page read and write
|
||
7799000
|
unkown
|
page readonly
|
||
46F0000
|
unkown
|
page read and write
|
||
43E0000
|
unkown
|
page read and write
|
||
777A000
|
unkown
|
page read and write
|
||
6A20000
|
unkown
|
page read and write
|
||
4700000
|
unkown
|
page read and write
|
||
3430000
|
unkown
|
page read and write
|
||
7EF40000
|
unkown
|
page execute and read and write
|
||
560B000
|
heap private
|
page read and write
|
||
390000
|
unkown
|
page read and write
|
||
300000
|
heap default
|
page read and write
|
||
310000
|
heap default
|
page read and write
|
||
690F000
|
unkown
|
page read and write
|
||
67BC000
|
unkown
|
page read and write
|
||
500D000
|
unkown
|
page read and write
|
||
4F9E000
|
unkown
|
page read and write | page guard
|
||
6C7E000
|
unkown
|
page read and write
|
||
6632000
|
unkown
|
page read and write
|
||
58A0000
|
unkown
|
page read and write
|
||
4810000
|
heap private
|
page read and write
|
||
28A000
|
unkown
|
page execute and read and write
|
||
A70000
|
unkown
|
page read and write
|
||
3550000
|
unkown
|
page read and write
|
||
6AAB000
|
unkown
|
page read and write
|
||
C6000
|
heap default
|
page read and write
|
||
6E54000
|
unkown
|
page read and write
|
||
2B4000
|
heap private
|
page read and write
|
||
F6000
|
unkown
|
page read and write
|
||
35D0000
|
unkown
|
page read and write
|
||
3687000
|
unkown
|
page read and write
|
||
64E0000
|
unkown
|
page read and write
|
||
BD000
|
heap default
|
page read and write
|
||
6A97000
|
unkown
|
page read and write
|
||
47A0000
|
unkown
|
page read and write
|
||
4A2F000
|
stack
|
page read and write
|
||
280000
|
unkown
|
page read and write
|
||
9A0000
|
unkown
|
page read and write
|
||
5058000
|
unkown
|
page read and write
|
||
72E5000
|
unkown
|
page read and write
|
||
45B000
|
unkown
|
page read and write
|
||
1A2000
|
unkown
|
page execute and read and write
|
||
6880000
|
unkown
|
page read and write
|
||
6B40000
|
unkown
|
page read and write
|
||
6856000
|
unkown
|
page read and write
|
||
225F000
|
unkown
|
page read and write
|
||
BC0000
|
unkown image
|
page readonly
|
||
464000
|
heap default
|
page read and write
|
||
44B0000
|
unkown
|
page read and write
|
||
548000
|
unkown
|
page read and write
|
||
3570000
|
unkown
|
page read and write
|
||
6E48000
|
unkown
|
page read and write
|
||
395000
|
unkown
|
page read and write
|
||
535E000
|
stack
|
page read and write
|
||
5640000
|
unkown
|
page read and write
|
||
67C5000
|
unkown
|
page read and write
|
||
6A5E000
|
stack
|
page read and write
|
||
709A000
|
unkown
|
page read and write
|
||
F5000
|
unkown
|
page read and write
|
||
8918000
|
unkown
|
page readonly
|
||
5640000
|
unkown
|
page read and write
|
||
7805000
|
unkown
|
page readonly
|
||
AD0000
|
unkown
|
page readonly
|
||
540D000
|
unkown
|
page read and write
|
||
20B0000
|
heap private
|
page read and write
|
||
393000
|
heap default
|
page read and write
|
||
548F000
|
unkown
|
page read and write
|
||
2F0000
|
unkown
|
page read and write
|
||
5077000
|
unkown
|
page read and write
|
||
738F000
|
unkown
|
page read and write
|
||
6A01000
|
unkown
|
page read and write
|
||
6E83000
|
unkown
|
page read and write
|
||
2122000
|
heap private
|
page read and write
|
||
7772000
|
unkown
|
page readonly
|
||
60000
|
unkown
|
page readonly
|
||
66D0000
|
unkown
|
page read and write
|
||
EE0000
|
unkown image
|
page readonly
|
||
6EB7000
|
unkown
|
page read and write
|
||
33D0000
|
unkown
|
page read and write
|
||
AD0000
|
unkown
|
page read and write
|
||
7785000
|
unkown
|
page readonly
|
||
6F01000
|
unkown
|
page read and write
|
||
4A30000
|
unkown
|
page readonly
|
||
A60000
|
unkown
|
page read and write
|
||
5290000
|
heap private
|
page read and write
|
||
6632000
|
heap private
|
page read and write
|
||
44B0000
|
unkown
|
page read and write
|
||
50D2000
|
unkown
|
page read and write
|
||
28C000
|
unkown
|
page execute and read and write
|
||
43BD000
|
unkown
|
page read and write
|
||
3FC000
|
heap default
|
page read and write
|
||
474C000
|
unkown
|
page read and write
|
||
5094000
|
unkown
|
page read and write
|
||
69D9000
|
unkown
|
page read and write
|
||
2B0000
|
heap private
|
page read and write
|
||
54B2000
|
unkown
|
page read and write
|
||
391000
|
unkown
|
page read and write
|
||
660000
|
unkown
|
page readonly
|
||
6DFB000
|
unkown
|
page read and write
|
||
5497000
|
unkown
|
page read and write
|
||
87000
|
heap default
|
page read and write
|
||
6B09000
|
unkown
|
page read and write
|
||
68DF000
|
unkown
|
page read and write
|
||
5058000
|
unkown
|
page read and write
|
||
6682000
|
unkown
|
page read and write
|
||
5DCE000
|
stack
|
page read and write
|
||
5640000
|
unkown
|
page read and write
|
||
6A65000
|
unkown
|
page read and write
|
||
3BC000
|
unkown
|
page read and write
|
||
50B6000
|
unkown
|
page read and write
|
||
82D000
|
heap private
|
page read and write
|
||
6BC7000
|
unkown
|
page read and write
|
||
7755000
|
unkown
|
page readonly
|
||
57CE000
|
unkown
|
page read and write
|
||
12A000
|
unkown
|
page read and write
|
||
2A2000
|
unkown
|
page execute and read and write
|
||
A6D000
|
unkown
|
page read and write
|
||
64DE000
|
stack
|
page read and write
|
||
8818000
|
unkown
|
page readonly
|
||
67BA000
|
unkown
|
page read and write
|
||
440000
|
heap default
|
page read and write
|
||
5640000
|
unkown
|
page read and write
|
||
681D000
|
unkown
|
page read and write
|
||
67C1000
|
unkown
|
page read and write
|
||
6A60000
|
unkown
|
page read and write
|
||
4D0000
|
unkown
|
page read and write
|
||
E0000
|
unkown
|
page read and write
|
||
6AD0000
|
unkown
|
page read and write
|
||
69FF000
|
unkown
|
page read and write
|
||
5427000
|
unkown
|
page read and write
|
||
D0000
|
unkown
|
page readonly
|
||
653F000
|
unkown
|
page read and write
|
||
860000
|
heap default
|
page read and write
|
||
34F0000
|
unkown
|
page read and write
|
||
FE000
|
unkown
|
page read and write
|
||
AF0000
|
unkown
|
page readonly
|
||
2582000
|
unkown
|
page read and write
|
||
50B6000
|
unkown
|
page read and write
|
||
6EFB000
|
unkown
|
page read and write
|
||
658000
|
heap private
|
page read and write
|
||
7110000
|
unkown
|
page readonly
|
||
6FAC000
|
unkown
|
page read and write
|
||
43F0000
|
unkown
|
page execute and read and write
|
||
779D000
|
unkown
|
page readonly
|
||
6EC2000
|
unkown
|
page read and write
|
||
100000
|
unkown
|
page read and write
|
||
692C000
|
unkown
|
page read and write
|
||
7983000
|
unkown
|
page read and write
|
||
50A2000
|
unkown
|
page read and write
|
||
3688000
|
unkown
|
page read and write
|
||
7EFDF000
|
unkown
|
page read and write
|
||
29A0000
|
unkown
|
page read and write
|
||
C8000
|
heap default
|
page read and write
|
||
F62000
|
unkown image
|
page readonly
|
||
4463000
|
heap private
|
page read and write
|
||
12C0000
|
heap private
|
page read and write
|
||
36A7000
|
unkown
|
page read and write
|
||
7742000
|
unkown
|
page readonly
|
||
8D7F000
|
unkown
|
page readonly
|
||
46E0000
|
unkown
|
page read and write
|
||
8D000
|
unkown
|
page read and write
|
||
54A8000
|
unkown
|
page read and write
|
||
7130000
|
unkown
|
page readonly
|
||
5640000
|
unkown
|
page read and write
|
||
25A000
|
unkown
|
page read and write
|
||
6823000
|
unkown
|
page read and write
|
||
6ED8000
|
unkown
|
page read and write
|
||
5640000
|
unkown
|
page read and write
|
||
5640000
|
unkown
|
page read and write
|
||
7A00000
|
unkown
|
page readonly
|
||
654E000
|
unkown
|
page read and write
|
||
55AE000
|
unkown
|
page read and write
|
||
7766000
|
unkown
|
page readonly
|
||
796B000
|
unkown
|
page read and write
|
||
12A000
|
unkown
|
page read and write
|
||
7674000
|
unkown
|
page readonly
|
||
5A30000
|
unkown
|
page readonly
|
||
7F0000
|
unkown
|
page readonly
|
||
6F03000
|
unkown
|
page read and write
|
||
6AAF000
|
unkown
|
page read and write
|
||
46F0000
|
unkown
|
page read and write
|
||
6AFA000
|
unkown
|
page read and write
|
||
50B6000
|
unkown
|
page read and write
|
||
5890000
|
unkown
|
page read and write
|
||
3A6000
|
unkown
|
page read and write
|
||
27D000
|
unkown
|
page read and write
|
||
65A1000
|
unkown
|
page read and write
|
||
7A20000
|
unkown
|
page readonly
|
||
6ECD000
|
unkown
|
page read and write
|
||
65BE000
|
unkown
|
page read and write
|
||
43C0000
|
unkown
|
page read and write
|
||
640000
|
heap default
|
page read and write
|
||
5E8000
|
heap private
|
page read and write
|
||
7EF40000
|
unkown
|
page execute and read and write
|
||
6EBD000
|
unkown
|
page read and write
|
||
77E9000
|
unkown
|
page readonly
|
||
4E0000
|
unkown
|
page execute and read and write
|
||
4700000
|
unkown
|
page read and write
|
||
47A0000
|
unkown
|
page read and write
|
||
685A000
|
unkown
|
page read and write
|
||
112000
|
unkown
|
page execute and read and write
|
||
3B9000
|
unkown
|
page read and write
|
||
48A000
|
heap default
|
page read and write
|
||
6E80000
|
unkown
|
page read and write
|
||
7812000
|
unkown
|
page readonly
|
||
E70000
|
unkown
|
page readonly
|
||
4E7E000
|
unkown
|
page read and write
|
||
679A000
|
unkown
|
page read and write
|
||
6A99000
|
unkown
|
page read and write
|
||
600000
|
heap private
|
page execute and read and write
|
||
55FD000
|
unkown
|
page read and write
|
||
146000
|
heap default
|
page read and write
|
||
ED000
|
heap default
|
page read and write
|
||
5640000
|
unkown
|
page read and write
|
||
67D1000
|
unkown
|
page read and write
|
||
6A5E000
|
unkown
|
page read and write
|
||
B1E000
|
unkown
|
page read and write
|
||
661E000
|
unkown
|
page read and write
|
||
75B2000
|
unkown
|
page readonly
|
||
77D5000
|
unkown
|
page readonly
|
||
5608000
|
heap private
|
page read and write
|
||
6BF5000
|
unkown
|
page read and write
|
||
1F0000
|
unkown
|
page read and write
|
||
88A4000
|
unkown
|
page readonly
|
||
300000
|
unkown
|
page readonly
|
||
58C000
|
unkown
|
page readonly
|
||
54EB000
|
unkown
|
page read and write
|
||
47B0000
|
unkown
|
page read and write
|
||
9D0A000
|
stack
|
page read and write
|
||
7987000
|
unkown
|
page read and write
|
||
69DB000
|
unkown
|
page read and write
|
||
2B0000
|
heap private
|
page read and write
|
||
292000
|
unkown
|
page read and write
|
||
5C10000
|
heap private
|
page read and write
|
||
72BA000
|
unkown
|
page read and write
|
||
6AA5000
|
unkown
|
page read and write
|
||
9A0000
|
unkown
|
page read and write
|
||
500000
|
heap private
|
page execute and read and write
|
||
2CB000
|
unkown
|
page execute and read and write
|
||
6C4C000
|
unkown
|
page read and write
|
||
7F0000
|
unkown
|
page read and write
|
||
3AE000
|
unkown
|
page read and write
|
||
6A48000
|
unkown
|
page read and write
|
||
390000
|
unkown
|
page read and write
|
||
4DE0000
|
unkown
|
page read and write
|
||
6C38000
|
unkown
|
page read and write
|
||
5640000
|
unkown
|
page read and write
|
||
272000
|
unkown
|
page execute and read and write
|
||
2C2000
|
unkown
|
page read and write
|
||
2C7000
|
unkown
|
page execute and read and write
|
||
7E0000
|
unkown
|
page readonly
|
||
692E000
|
unkown
|
page read and write
|
||
6A8B000
|
unkown
|
page read and write
|
||
395000
|
unkown
|
page read and write
|
||
561000
|
unkown
|
page read and write
|
||
A20000
|
unkown
|
page read and write
|
||
6615000
|
heap private
|
page read and write
|
||
50D2000
|
unkown
|
page read and write
|
||
6E12000
|
unkown
|
page read and write
|
||
180000
|
unkown
|
page readonly
|
||
F0000
|
unkown
|
page read and write
|
||
6A6C000
|
unkown
|
page read and write
|
||
8F87000
|
unkown
|
page readonly
|
||
8625000
|
unkown
|
page readonly
|
||
2D7000
|
unkown
|
page execute and read and write
|
||
53AC000
|
heap private
|
page read and write
|
||
600000
|
heap default
|
page read and write
|
||
12A000
|
unkown
|
page read and write
|
||
3531000
|
unkown
|
page read and write
|
||
53E6000
|
unkown
|
page read and write
|
||
53E9000
|
unkown
|
page read and write
|
||
282000
|
unkown
|
page execute and read and write
|
||
6A06000
|
unkown
|
page read and write
|
||
68D4000
|
unkown
|
page read and write
|
||
50E6000
|
unkown
|
page read and write
|
||
50A2000
|
unkown
|
page read and write
|
||
3510000
|
unkown
|
page read and write
|
||
6A4C000
|
unkown
|
page read and write
|
||
66EF000
|
unkown
|
page read and write
|
||
9FE000
|
unkown
|
page read and write
|
||
462D000
|
stack
|
page read and write
|
||
ED0000
|
unkown
|
page read and write
|
||
4FB000
|
heap default
|
page read and write
|
||
3A0000
|
heap default
|
page read and write
|
||
6A7D000
|
unkown
|
page read and write
|
||
68E6000
|
unkown
|
page read and write
|
||
390000
|
unkown
|
page read and write
|
||
5640000
|
unkown
|
page read and write
|
||
7706000
|
unkown
|
page readonly
|
||
2104000
|
heap private
|
page read and write
|
||
673E000
|
unkown
|
page read and write
|
||
2F0000
|
unkown
|
page read and write
|
||
6620000
|
unkown
|
page read and write
|
||
3A6000
|
unkown
|
page read and write
|
||
C70000
|
unkown
|
page readonly
|
||
5FFE000
|
stack
|
page read and write
|
||
4F9F000
|
unkown
|
page read and write
|
||
2584000
|
unkown
|
page read and write
|
||
5640000
|
unkown
|
page read and write
|
||
EE0000
|
unkown image
|
page readonly
|
||
6BCD000
|
unkown
|
page read and write
|
||
3AE000
|
unkown
|
page read and write
|
||
47FC000
|
unkown
|
page read and write
|
||
A70000
|
unkown
|
page read and write
|
||
4850000
|
unkown
|
page readonly
|
||
64D1000
|
unkown
|
page read and write
|
||
5079000
|
unkown
|
page read and write
|
||
72D0000
|
unkown
|
page read and write
|
||
2CA000
|
unkown
|
page execute and read and write
|
||
69DE000
|
unkown
|
page read and write
|
||
54A0000
|
unkown
|
page read and write
|
||
881B000
|
unkown
|
page readonly
|
||
595E000
|
unkown
|
page read and write
|
||
297000
|
unkown
|
page execute and read and write
|
||
4FEE000
|
stack
|
page read and write
|
||
4710000
|
unkown
|
page readonly
|
||
4830000
|
heap private
|
page read and write
|
||
9F6D000
|
stack
|
page read and write
|
||
9EB000
|
unkown
|
page readonly
|
||
587000
|
unkown
|
page readonly
|
||
4700000
|
unkown
|
page readonly
|
||
AEF000
|
unkown
|
page read and write
|
||
E10000
|
unkown
|
page readonly
|
||
820000
|
heap private
|
page read and write
|
||
981E000
|
stack
|
page read and write
|
||
882E000
|
unkown
|
page readonly
|
||
639E000
|
unkown
|
page read and write
|
||
BAE000
|
unkown
|
page read and write
|
||
7736000
|
unkown
|
page readonly
|
||
5640000
|
unkown
|
page read and write
|
||
36A7000
|
unkown
|
page read and write
|
||
618C000
|
unkown
|
page read and write
|
||
74B2000
|
unkown
|
page readonly
|
||
2B2000
|
unkown
|
page read and write
|
||
120000
|
heap default
|
page read and write
|
||
580000
|
unkown
|
page readonly
|
||
80000
|
heap default
|
page read and write
|
||
72D7000
|
unkown
|
page read and write
|
||
6A4E000
|
unkown
|
page read and write
|
||
6779000
|
unkown
|
page read and write
|
||
400000
|
unkown
|
page execute and read and write
|
||
569E000
|
unkown
|
page read and write
|
||
54A6000
|
unkown
|
page read and write
|
||
A70000
|
unkown
|
page read and write
|
||
681F000
|
unkown
|
page read and write
|
||
4600000
|
unkown
|
page readonly
|
||
7035000
|
unkown
|
page read and write
|
There are 718 hidden memdumps, click here to show them.