IOCReport

loading gif

Files

File Path
Type
Category
Malicious
SecuriteInfo.com.Exploit.Siggen3.10350.15803.xls
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1251, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 01:00:00 2006, Last Saved Time/Date: Fri Feb 19 10:48:36 2021, Security: 0
initial sample
malicious
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\History.bak
SQLite 3.x database, last written using SQLite version 3032001
dropped
malicious
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data.bak
SQLite 3.x database, last written using SQLite version 3032001
dropped
malicious
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Data.bak
SQLite 3.x database, last written using SQLite version 3032001
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\10[1].jjkes
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
downloaded
malicious
C:\Users\user\BASE.BABAA
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Microsoft Cabinet archive data, 59134 bytes, 1 file
dropped
clean
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Local State.bak
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\40DE0000
data
dropped
clean
C:\Users\user\AppData\Local\Temp\CabE466.tmp
Microsoft Cabinet archive data, 59134 bytes, 1 file
dropped
clean
C:\Users\user\AppData\Local\Temp\TarE467.tmp
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Tue Oct 17 10:04:00 2017, mtime=Sat Feb 20 09:03:39 2021, atime=Sat Feb 20 09:03:39 2021, length=8192, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\SecuriteInfo.com.Exploit.Siggen3.10350.15803.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Sat Feb 20 09:03:26 2021, mtime=Sat Feb 20 09:03:39 2021, atime=Sat Feb 20 09:03:39 2021, length=168448, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Roaming\QNetMonitor7737977537\SecurityPreloadState.txt
ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Roaming\QNetMonitor7737977537\cn\aexsxmcq.txt
data
modified
clean
C:\Users\user\AppData\Roaming\QNetMonitor7737977537\en-EN\pwgrab64
data
dropped
clean
C:\Users\user\Desktop\D3DE0000
Applesoft BASIC program data, first line number 16
dropped
clean
There are 9 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\rundll32.exe
rundll32 ..\BASE.BABAA,DllRegisterServer
malicious
C:\Windows\SysWOW64\rundll32.exe
rundll32 ..\BASE.BABAA,DllRegisterServer
malicious
C:\Windows\System32\wermgr.exe
C:\Windows\system32\wermgr.exe
malicious
C:\Windows\System32\wermgr.exe
C:\Windows\system32\wermgr.exe
malicious
C:\Windows\System32\rundll32.exe
C:\Windows\system32\rundll32.EXE 'C:\Users\user\AppData\Roaming\QNetMonitor7737977537\rpBASEtx.rrd',DllRegisterServer
malicious
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
malicious
C:\Windows\System32\taskeng.exe
taskeng.exe {DA6299CA-95CA-4E9D-8945-2CC05321254C} S-1-5-18:NT AUTHORITY\System:Service:
clean

URLs

Name
IP
Malicious
http://www.chipmania.it/mails/open.php
185.81.0.78
malicious
https://116.68.162.92:443/rob60/813435_W617601.8B73F080286CDBB0F9B96995D4E87F7B/83/
116.68.162.92
malicious
http://www.windows.com/pctv.
unknown
clean
http://109.69.4.201:443
unknown
clean
http://123.231.180.130:443
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
https://193.8.194.96/rob60/813435_W617601.8B73F080286CDBB0F9B96995D4E87F7B/64/pwgrab/DPST//3
unknown
clean
http://crl.entrust.net/server1.crl0
unknown
clean
http://ocsp.entrust.net03
unknown
clean
http://116.68.162.92:443
unknown
clean
http://crl.use
unknown
clean
https://193.8.194.96/rob60/813435_W617601.8B73F080286CDBB0F9B96995D4E87F7B/1/rznnTbpNFJV19x1x/o
unknown
clean
http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl0
unknown
clean
http://www.diginotar.nl/cps/pkioverheid0
unknown
clean
https://185.109.54.99:447/rob60/813435_W617601.8B73F080286CDBB0F9B96995D4E87F7B/5/pwgrab64/
unknown
clean
https://193.8.194.96/rob60/813435_W617601.8B73F080286CDBB0F9B96995D4E87F7B/64/pwgrab/DPST//
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://190.239.34.181:443
unknown
clean
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
https://193.8.194.96/rob60/813435_W617601.8B73F080286CDBB0F9B96995D4E87F7B/64/pwgrab/DPST//W
unknown
clean
http://crl.pkioverheid.nl/DomOvLatestCRL.crl0
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
Https://193.8.194.96/rob60/813435_W617601.8B73F080286CDBB0F9B96995D4E87F7B/1/bnfhZJn91PhwAc8eqCIkI2c
unknown
clean
https://193.8.194.96/rob60/813435_W617601.8B73F080286CDBB0F9B96995D4E87F7B/1/rznnTbpNFJV19x1x/U
unknown
clean
https://193.8.194.96/rob60/813435_W617601.8B73F080286CDBB0F9B96995D4E87F7B/1/rznnTbpNFJV19x1x/
unknown
clean
http://154.0.134.130:443
unknown
clean
http://187.95.136.38:443
unknown
clean
http://investor.msn.com/
unknown
clean
http://logo.veri
unknown
clean
http://www.%s.comPA
unknown
clean
https://193.8.194.96/rob60/813435_W617601.8B73F080286CDBB0F9B96995D4E87F7B/64/pwgrab/DEBG//e
unknown
clean
http://ocsp.entrust.net0D
unknown
clean
http://wtfismyip.com/text
95.217.228.176
clean
https://secure.comodo.com/CPS0
unknown
clean
http://servername/isapibackend.dll
unknown
clean
https://193.8.194.96/rob60/813435_W617601.8B73F080286CDBB0F9B96995D4E87F7B/1/jvvnxhpdjrND3fPr33rZPHh
unknown
clean
http://crl.entrust.net/2048ca.crl0
unknown
clean
http://45.184.189.34:443
unknown
clean
There are 31 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
38.52.17.84.dnsbl-1.uceprotect.net
unknown
malicious
www.chipmania.it
unknown
malicious
chipmania.it
185.81.0.78
clean
wtfismyip.com
95.217.228.176
clean
38.52.17.84.zen.spamhaus.org
unknown
clean
38.52.17.84.cbl.abuseat.org
unknown
clean
38.52.17.84.b.barracudacentral.org
unknown
clean
38.52.17.84.spam.dnsbl.sorbs.net
unknown
clean

IPs

IP
Domain
Country
Active
Malicious
154.0.134.130
unknown
Uganda
unknown
malicious
123.231.180.130
unknown
Indonesia
unknown
malicious
190.239.34.181
unknown
Peru
unknown
malicious
45.184.189.34
unknown
Brazil
unknown
malicious
185.109.54.99
unknown
Ukraine
unknown
malicious
193.8.194.96
unknown
United Kingdom
unknown
malicious
116.68.162.92
unknown
Indonesia
unknown
malicious
94.140.114.136
unknown
Latvia
unknown
malicious
187.95.136.38
unknown
Brazil
unknown
malicious
109.69.4.201
unknown
Albania
unknown
malicious
185.81.0.78
unknown
Italy
unknown
clean
95.217.228.176
unknown
Germany
unknown
clean
194.5.249.156
unknown
Romania
unknown
clean
There are 3 hidden IPs, click here to show them.

Registry

Path
Value
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
}=8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
MTTT
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ReviewToken
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EC8EA
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
VBAFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DefaultSheetR2L
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
UseSystemSeparators
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ThousandsSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DecimalSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ECE28
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ECFCD
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ED385
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ED421
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} {000214E6-0000-0000-C000-000000000046} 0xFFFF
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
gm8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F4AC6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F4F0A
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
LastPurgeTime
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EXCELFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SavedLegacySettings
clean
C:\Windows\System32\wermgr.exe
@%SystemRoot%\system32\qagentrt.dll,-10
clean
C:\Windows\System32\wermgr.exe
@%SystemRoot%\System32\fveui.dll,-843
clean
C:\Windows\System32\wermgr.exe
@%SystemRoot%\System32\fveui.dll,-844
clean
C:\Windows\System32\wermgr.exe
@%SystemRoot%\System32\wuaueng.dll,-400
clean
C:\Windows\System32\wermgr.exe
Blob
clean
C:\Windows\System32\wermgr.exe
Blob
clean
C:\Windows\System32\wermgr.exe
Blob
clean
C:\Windows\System32\wermgr.exe
Blob
clean
C:\Windows\System32\wermgr.exe
Blob
clean
C:\Windows\System32\wermgr.exe
Blob
clean
C:\Windows\System32\taskeng.exe
data
clean
C:\Windows\System32\svchost.exe
SavedLegacySettings
clean
There are 107 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
180000
unkown
page execute and read and write
malicious
6C4000
unkown
page read and write
malicious
6C4000
unkown
page read and write
malicious
690000
heap default
page read and write
malicious
2198000
unkown
page read and write
malicious
2030000
unkown
page read and write
clean
2520000
unkown
page read and write
clean
1FC0000
unkown
page read and write
clean
EA0000
unkown
page readonly
clean
3206D000
heap private
page read and write
clean
1FC0000
unkown
page read and write
clean
100000
unkown
page readonly
clean
2520000
unkown
page read and write
clean
6F0000
unkown
page read and write
clean
33421000
unkown
page read and write
clean
33367000
unkown
page read and write
clean
654000
heap default
page read and write
clean
290000
unkown
page read and write
clean
43C000
unkown
page read and write
clean
32DE0000
heap private
page read and write
clean
1FD9000
heap private
page read and write
clean
356000
unkown
page read and write
clean
32EE0000
unkown
page readonly
clean
460000
unkown
page readonly
clean
3130000
unkown
page read and write
clean
334F0000
unkown
page read and write
clean
3235A000
heap private
page read and write
clean
6BA000
unkown
page read and write
clean
336C0000
heap private
page read and write
clean
6D0000
unkown
page read and write
clean
33395000
unkown
page read and write
clean
350000
heap private
page read and write
clean
1FD0000
unkown
page read and write
clean
90000
unkown
page write copy
clean
1F3F000
unkown
page read and write
clean
1496000
unkown
page readonly
clean
151000
heap default
page read and write
clean
334F0000
unkown
page read and write
clean
2730000
unkown
page read and write
clean
368000
unkown
page read and write
clean
41A000
heap default
page read and write
clean
147F000
unkown
page read and write
clean
90000
unkown
page readonly
clean
154000
heap default
page read and write
clean
6DD41000
unkown image
page execute read
clean
33356000
unkown
page read and write
clean
476000
unkown
page read and write
clean
1515000
unkown
page readonly
clean
1FB0000
unkown
page read and write
clean
32A53000
heap private
page read and write
clean
1770000
unkown
page readonly
clean
2D0000
unkown
page execute and read and write
clean
6C0000
unkown
page readonly
clean
1F80000
unkown
page read and write
clean
60000
unkown
page readonly
clean
14D2000
unkown
page readonly
clean
2060000
heap private
page read and write
clean
6DD40000
unkown image
page readonly
clean
343A2000
unkown
page read and write
clean
CA0000
heap private
page read and write
clean
32756000
heap private
page read and write
clean
29EE000
unkown
page read and write
clean
2F30000
unkown
page read and write
clean
2A60000
unkown
page read and write
clean
1444000
unkown
page readonly
clean
3C0000
heap default
page read and write
clean
2048000
unkown
page read and write
clean
33B30000
unkown
page readonly
clean
EE0000
unkown
page read and write
clean
740000
unkown
page readonly
clean
15A9000
unkown
page readonly
clean
139000
heap default
page read and write
clean
20000
heap private
page read and write
clean
66D000
heap default
page read and write
clean
1F80000
unkown
page read and write
clean
2529000
unkown
page read and write
clean
204B000
unkown
page read and write
clean
2A0000
unkown
page read and write
clean
1502000
unkown
page readonly
clean
6E1A4000
unkown image
page readonly
clean
1D8F000
unkown
page read and write
clean
3130000
unkown
page read and write
clean
32657000
heap private
page read and write
clean
343A6000
unkown
page read and write
clean
204A000
unkown
page read and write
clean
2529000
unkown
page read and write
clean
210000
unkown
page readonly
clean
33395000
unkown
page read and write
clean
3AA000
heap default
page read and write
clean
32A53000
heap private
page read and write
clean
331B0000
unkown
page readonly
clean
2FC0000
unkown
page read and write
clean
1FC0000
unkown
page read and write
clean
691000
unkown
page read and write
clean
33475000
heap private
page read and write
clean
667000
heap default
page read and write
clean
35E000
heap default
page read and write
clean
1B0000
unkown
page readonly
clean
2910000
unkown
page read and write
clean
1248000
unkown
page readonly
clean
1D70000
unkown
page readonly
clean
20000
unkown
page read and write
clean
33387000
unkown
page read and write
clean
2260000
heap private
page read and write
clean
6E169000
unkown image
page readonly
clean
14E5000
unkown
page readonly
clean
60000
unkown
page readonly
clean
69E000
unkown
page read and write
clean
1565000
unkown
page readonly
clean
33395000
unkown
page read and write
clean
140000
unkown
page read and write
clean
33F70000
heap private
page read and write
clean
1F40000
unkown
page readonly
clean
60000
unkown
page execute and read and write
clean
130000
unkown
page readonly
clean
27C0000
unkown
page read and write
clean
3A0000
heap default
page read and write
clean
356B0000
heap private
page read and write
clean
356C0000
unkown
page read and write
clean
333FD000
unkown
page read and write
clean
2730000
unkown
page read and write
clean
2B60000
heap private
page read and write
clean
220000
unkown
page read and write
clean
33395000
unkown
page read and write
clean
6D0000
unkown
page read and write
clean
2048000
unkown
page read and write
clean
204D000
unkown
page read and write
clean
6E18C000
unkown image
page readonly
clean
3620000
unkown
page read and write
clean
D10000
unkown
page write copy
clean
33422000
unkown
page read and write
clean
280000
unkown
page readonly
clean
627000
stack
page read and write
clean
334F0000
unkown
page read and write
clean
C90000
heap private
page read and write
clean
34395000
unkown
page read and write
clean
1FD0000
unkown
page read and write
clean
2C1E000
unkown
page read and write
clean
32954000
heap private
page read and write
clean
5A0000
unkown
page readonly
clean
31D60000
heap private
page read and write
clean
20000
unkown
page readonly
clean
1DA0000
heap private
page read and write
clean
1D0000
unkown
page read and write
clean
2950000
unkown
page read and write
clean
32D50000
heap private
page read and write
clean
D0000
unkown
page read and write
clean
17B0000
unkown
page readonly
clean
2041000
unkown
page read and write
clean
1595000
unkown
page readonly
clean
250000
unkown
page write copy
clean
35590000
unkown
page read and write
clean
330000
heap default
page read and write
clean
343B3000
unkown
page read and write
clean
18010C000
unkown
page readonly
clean
1FD0000
unkown
page read and write
clean
1FB0000
unkown
page read and write
clean
256000
unkown
page read and write
clean
691000
unkown
page read and write
clean
3439E000
unkown
page read and write
clean
271B000
unkown
page read and write
clean
2629000
heap private
page read and write
clean
6D0000
unkown
page read and write
clean
32D56000
heap private
page read and write
clean
280000
heap private
page read and write
clean
2910000
unkown
page read and write
clean
CA4000
heap private
page read and write
clean
800000
unkown
page readonly
clean
E0000
unkown
page read and write
clean
1FB0000
unkown
page read and write
clean
3090000
unkown
page read and write
clean
31C0000
unkown
page read and write
clean
210000
unkown
page readonly
clean
2520000
unkown
page read and write
clean
6F1000
unkown
page read and write
clean
2264000
heap private
page read and write
clean
90000
unkown
page readonly
clean
3337E000
unkown
page read and write
clean
2BB0000
unkown
page read and write
clean
33395000
unkown
page read and write
clean
23AC000
unkown
page read and write
clean
1F57000
unkown
page readonly
clean
32D8C000
heap private
page read and write
clean
1FBF000
unkown
page read and write
clean
36E000
heap default
page read and write
clean
3630000
unkown
page read and write
clean
EC0000
unkown
page readonly
clean
6B0000
unkown
page readonly
clean
2F30000
unkown
page read and write
clean
180000
unkown
page read and write
clean
35590000
unkown
page read and write
clean
1342000
unkown
page readonly
clean
33376000
unkown
page read and write
clean
17B000
unkown
page read and write
clean
383000
heap default
page read and write
clean
2AB0000
unkown
page read and write
clean
300000
unkown
page execute and read and write
clean
DEF000
unkown
page read and write
clean
33395000
unkown
page read and write
clean
1FC0000
unkown
page read and write
clean
33385000
unkown
page read and write
clean
180000
unkown
page read and write
clean
2F0000
unkown
page execute and read and write
clean
33D17000
unkown
page readonly
clean
13D000
unkown
page read and write
clean
1FD0000
heap private
page read and write
clean
3368F000
unkown
page read and write
clean
2520000
unkown
page read and write
clean
333AB000
unkown
page read and write
clean
1FC0000
unkown
page read and write
clean
3000000
unkown
page read and write
clean
1579000
unkown
page readonly
clean
2148000
unkown
page read and write
clean
104000
heap private
page read and write
clean
7EFDF000
unkown
page read and write
clean
5E0000
unkown
page readonly
clean
2330000
heap private
page read and write
clean
1FC0000
unkown
page read and write
clean
3630000
unkown
page read and write
clean
33385000
unkown
page read and write
clean
1C0000
unkown
page execute and read and write
clean
1FC0000
unkown
page read and write
clean
33395000
unkown
page read and write
clean
34371000
unkown
page read and write
clean
29C0000
unkown
page read and write
clean
20CF000
unkown
page read and write
clean
101000
unkown
page read and write
clean
14C6000
unkown
page readonly
clean
850000
unkown
page readonly
clean
1CD0000
heap private
page read and write
clean
440000
unkown
page read and write
clean
244000
heap private
page read and write
clean
3214C000
heap private
page read and write
clean
3406C000
unkown
page read and write
clean
22C000
unkown
page read and write
clean
150D000
unkown
page read and write
clean
1FB0000
unkown
page read and write
clean
1FB0000
unkown
page read and write
clean
430000
unkown
page read and write
clean
32D51000
heap private
page read and write
clean
100000
unkown
page read and write
clean
1800DC000
unkown
page readonly
clean
87000
heap default
page read and write
clean
1FE0000
unkown
page readonly
clean
70000
unkown
page read and write
clean
33330000
unkown
page read and write
clean
420000
unkown
page readonly
clean
35590000
unkown
page read and write
clean
2550000
heap private
page read and write
clean
334F0000
unkown
page read and write
clean
200F000
heap private
page read and write
clean
180000
unkown
page read and write
clean
337000
heap default
page read and write
clean
265F000
heap private
page read and write
clean
222E000
unkown
page read and write
clean
335FD000
unkown
page read and write
clean
327000
heap default
page read and write
clean
34371000
unkown
page read and write
clean
333B9000
unkown
page read and write
clean
A37000
unkown
page readonly
clean
860000
unkown
page readonly
clean
115000
heap default
page read and write
clean
35590000
unkown
page read and write
clean
691000
unkown
page read and write
clean
3338A000
unkown
page read and write
clean
1FC0000
unkown
page read and write
clean
1E9C000
unkown
page read and write
clean
6DD40000
unkown image
page readonly
clean
2D60000
heap private
page read and write
clean
466000
unkown
page read and write
clean
1526000
unkown
page readonly
clean
2BB0000
unkown
page read and write
clean
2A8E000
unkown
page read and write
clean
60000
unkown
page read and write
clean
2980000
unkown
page read and write
clean
4C0000
unkown
page readonly
clean
37E000
heap default
page read and write
clean
32459000
heap private
page read and write
clean
5A0000
unkown
page readonly
clean
343A0000
unkown
page read and write
clean
25BC000
unkown
page read and write
clean
3620000
unkown
page read and write
clean
110000
unkown
page read and write
clean
3640000
unkown
page read and write
clean
33421000
unkown
page read and write
clean
530000
unkown
page readonly
clean
BD000
heap default
page read and write
clean
105000
unkown
page read and write
clean
14B5000
unkown
page readonly
clean
2520000
unkown
page read and write
clean
1F80000
unkown
page read and write
clean
284000
heap private
page read and write
clean
19F000
unkown
page read and write
clean
34070000
unkown
page readonly
clean
36C0000
unkown
page read and write
clean
1404000
unkown
page readonly
clean
3FE000
heap default
page read and write
clean
343B3000
unkown
page read and write
clean
32756000
heap private
page read and write
clean
33422000
unkown
page read and write
clean
333A0000
unkown
page read and write
clean
3E0000
heap default
page read and write
clean
334F0000
unkown
page read and write
clean
35590000
unkown
page read and write
clean
333A6000
unkown
page read and write
clean
3BA000
unkown
page read and write
clean
434000
unkown
page read and write
clean
180000
unkown
page read and write
clean
2529000
unkown
page read and write
clean
43C000
unkown
page read and write
clean
33395000
unkown
page read and write
clean
130000
heap private
page read and write
clean
1549000
unkown
page readonly
clean
347000
heap default
page read and write
clean
3AC000
unkown
page read and write
clean
1FD0000
unkown
page read and write
clean
15A2000
unkown
page readonly
clean
1DC7000
unkown
page readonly
clean
111000
unkown
page read and write
clean
1424000
unkown
page readonly
clean
1FC0000
unkown
page read and write
clean
37D000
unkown
page read and write
clean
14A2000
unkown
page readonly
clean
2070000
heap private
page read and write
clean
2282000
heap private
page read and write
clean
3C7000
heap default
page read and write
clean
1472000
unkown
page readonly
clean
33470000
heap private
page read and write
clean
3334F000
unkown
page read and write
clean
421000
heap default
page read and write
clean
33422000
unkown
page read and write
clean
203C000
unkown
page read and write
clean
FB000
unkown
page read and write
clean
1BE0000
unkown
page readonly
clean
3205D000
heap private
page read and write
clean
2033000
unkown
page read and write
clean
15C5000
unkown
page readonly
clean
334F0000
unkown
page read and write
clean
20000
unkown
page readonly
clean
2043000
unkown
page read and write
clean
3338C000
unkown
page read and write
clean
28D0000
unkown
page read and write
clean
416000
heap default
page read and write
clean
10001000
unkown
page execute and read and write
clean
1FC0000
unkown
page read and write
clean
1542000
unkown
page readonly
clean
1FB0000
unkown
page read and write
clean
34370000
unkown
page read and write
clean
33385000
unkown
page read and write
clean
33740000
unkown
page readonly
clean
378000
unkown
page read and write
clean
540000
unkown
page readonly
clean
420000
unkown
page readonly
clean
266000
unkown
page read and write
clean
6F2000
unkown
page read and write
clean
EB000
unkown
page read and write
clean
314000
heap private
page read and write
clean
D0000
unkown
page read and write
clean
6F2000
unkown
page read and write
clean
2A10000
unkown
page read and write
clean
80000
heap default
page read and write
clean
230000
unkown
page read and write
clean
E0000
unkown
page read and write
clean
1529000
unkown
page readonly
clean
27B0000
heap private
page read and write
clean
CDB000
heap private
page read and write
clean
740000
unkown
page readonly
clean
20000
unkown
page read and write
clean
1790000
unkown
page readonly
clean
6AC000
unkown
page read and write
clean
EDC000
unkown
page read and write
clean
1FB0000
unkown
page read and write
clean
1D0000
unkown
page read and write
clean
33331000
unkown
page read and write
clean
29A0000
unkown
page read and write
clean
140000
unkown
page readonly
clean
240000
heap private
page read and write
clean
630000
heap default
page read and write
clean
2043000
unkown
page read and write
clean
340000
heap default
page read and write
clean
6BA000
unkown
page read and write
clean
3206E000
heap private
page read and write
clean
2520000
unkown
page read and write
clean
FA000
heap default
page read and write
clean
3630000
unkown
page read and write
clean
2520000
unkown
page read and write
clean
28DB000
unkown
page read and write
clean
152D000
unkown
page readonly
clean
34395000
unkown
page read and write
clean
33422000
unkown
page read and write
clean
2620000
heap private
page read and write
clean
180001000
unkown
page execute read
clean
2540000
unkown
page read and write
clean
2046000
unkown
page read and write
clean
180106000
unkown
page read and write
clean
104000
heap default
page read and write
clean
32DF3000
heap private
page read and write
clean
32C51000
heap private
page read and write
clean
1442000
unkown
page readonly
clean
334AB000
heap private
page read and write
clean
310000
heap private
page read and write
clean
6E18A000
unkown image
page read and write
clean
691000
unkown
page read and write
clean
2230000
unkown
page readonly
clean
6D0000
unkown
page read and write
clean
130000
unkown
page readonly
clean
21C000
unkown
page read and write
clean
204C000
unkown
page read and write
clean
1C6000
unkown
page read and write
clean
31F5E000
heap private
page read and write
clean
3000000
unkown
page read and write
clean
1F80000
unkown
page read and write
clean
43C000
unkown
page read and write
clean
2980000
unkown
page read and write
clean
E20000
heap private
page read and write
clean
C7E000
unkown
page read and write
clean
2043000
unkown
page read and write
clean
1485000
unkown
page readonly
clean
110000
unkown
page execute and read and write
clean
640000
unkown
page readonly
clean
370000
unkown
page execute and read and write
clean
134000
heap private
page read and write
clean
2041000
unkown
page read and write
clean
637000
heap default
page read and write
clean
320000
heap default
page read and write
clean
FC000
heap default
page read and write
clean
3630000
unkown
page read and write
clean
100000
heap private
page read and write
clean
33385000
unkown
page read and write
clean
20000
unkown
page readonly
clean
1572000
unkown
page readonly
clean
1F50000
heap private
page read and write
clean
20C000
unkown
page read and write
clean
3332C000
unkown
page read and write
clean
1422000
unkown
page readonly
clean
691000
unkown
page read and write
clean
1FC0000
unkown
page read and write
clean
2150000
unkown
page read and write
clean
333DE000
unkown
page read and write
clean
423000
heap default
page read and write
clean
3620000
unkown
page read and write
clean
1B40000
unkown
page readonly
clean
320000
unkown
page read and write
clean
252A000
unkown
page read and write
clean
2520000
unkown
page read and write
clean
FE0000
unkown
page readonly
clean
60000
unkown
page execute and read and write
clean
14F6000
unkown
page readonly
clean
E29000
heap private
page read and write
clean
1F2000
stack
page read and write
clean
2B10000
unkown
page read and write
clean
2035000
unkown
page read and write
clean
E9000
unkown
page read and write
clean
1242000
unkown
page readonly
clean
3630000
unkown
page read and write
clean
1732000
unkown
page readonly
clean
1FC0000
unkown
page read and write
clean
1402000
unkown
page readonly
clean
2850000
unkown
page read and write
clean
3339B000
unkown
page read and write
clean
1FB0000
unkown
page read and write
clean
3BD000
heap default
page read and write
clean
There are 452 hidden memdumps, click here to show them.