IOCReport

loading gif

Files

File Path
Type
Category
Malicious
document-1915351743.xls
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1251, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 01:00:00 2006, Last Saved Time/Date: Thu Feb 18 09:52:57 2021, Security: 0
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\1802[1].gif
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
downloaded
malicious
C:\Users\user\idefje.ekfd
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
malicious
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Microsoft Cabinet archive data, 59134 bytes, 1 file
dropped
clean
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
data
dropped
clean
C:\Users\user\AppData\Local\Temp\Cab742.tmp
Microsoft Cabinet archive data, 59134 bytes, 1 file
dropped
clean
C:\Users\user\AppData\Local\Temp\ECFE0000
data
dropped
clean
C:\Users\user\AppData\Local\Temp\Tar743.tmp
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Tue Oct 17 10:04:00 2017, mtime=Tue Feb 23 03:13:50 2021, atime=Tue Feb 23 03:13:50 2021, length=8192, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\document-1915351743.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Aug 26 14:08:14 2020, mtime=Tue Feb 23 03:13:50 2021, atime=Tue Feb 23 03:13:50 2021, length=90112, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\Desktop\ADFE0000
Applesoft BASIC program data, first line number 16
dropped
clean
There are 2 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\rundll32.exe
rundll32 ..\idefje.ekfd,DllRegisterServer
malicious

URLs

Name
IP
Malicious
http://oskolko.uno/
206.189.10.247
malicious
https://twitter.com/awscloud
unknown
clean
https://a0.awsstatic.com/libra-css/images/logo
unknown
clean
https://a0.awsstatic.com/libra/1.0.373/libra-head.js
unknown
clean
https://amazon.com/Y
unknown
clean
https://aws.amazon.com/terms/?nc1=f_pr
unknown
clean
https://dc.ads.linkedin.com/collect/?pid=3038&fmt=gif
unknown
clean
https://s0.awsstatic.com/en_US/nav/v3/panel-content/mobile/index.html
unknown
clean
https://aws.amazon.com/cn/
unknown
clean
http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl0
unknown
clean
http://www.diginotar.nl/cps/pkioverheid0
unknown
clean
https://a0.awsstatic.com/libra-css/images
unknown
clean
https://a0.awsstatic.com/target/1.0.112/aws-target-mediator.js
unknown
clean
https://a0.awsstatic.com/psf/null
unknown
clean
https://aws.amazon.com/ar/
unknown
clean
https://www.honeycode.aws/?&trk=el_a134p000003yC6YAAU&trkCampaign=pac-edm-2020-honeycode-hom
unknown
clean
https://pages.awscloud.com/zillow-case-study?hp=tile&story=zllw
unknown
clean
https://pages.awscloud.com/communication-preferences?trk=homepage
unknown
clean
http://ocsp.rootg2.amazontrust.com08
unknown
clean
https://aws.amazon.com/cn/?nc1=h_ls
unknown
clean
https://portal.aws.amazon.com/gp/aws/developer/registration/index.html?nc1=f_ct&src=default
unknown
clean
https://aws.amazon.com/ru/
unknown
clean
https://aws.amazon.com/tw/?nc1=h_ls
unknown
clean
https://fls-na.amazon.com/1/action-impressions/1/OE/aws-mktg/action/awsm_:comp_DeprecatedBrowser
unknown
clean
https://i18n-string.us-west-2.prod.pricing.aws.a2z.com
unknown
clean
https://aws.amazon.com/ko/
unknown
clean
https://aws.amazon.com/ru/?nc1=h_ls
unknown
clean
https://a0.awsstatic.com/libra-css/images/site/fav/favicon.ico
unknown
clean
https://aws.amazon.com/es/
unknown
clean
http://crl.sca1b.amazontrust.com/sca1b.crl0
unknown
clean
https://docs.aws.amazon.com/index.html?nc2=h_ql_doc
unknown
clean
https://aws.amazon.com/ar/?nc1=h_ls
unknown
clean
https://a0.awsstatic.com/libra-css/css/1.0.373/style-awsm.css
unknown
clean
https://aws.amazon.com/th/
unknown
clean
http://www.windows.com/pctv.
unknown
clean
https://a0.awsstatic.com/pricing-calculator/js/1.0.2
unknown
clean
https://aws.amazon.com/marketplace/?nc2=h_mo
unknown
clean
http://ocsp.sca1b.amazontrust.com06
unknown
clean
http://oskolko.uno/om/
unknown
clean
https://a0.awsstatic.com/libra-css/images/logos/aws_logo_smile_179x109.png
unknown
clean
https://console.aws.amazon.com/support/home/?nc2=h_ql_cu
unknown
clean
http://crl.rootca1.amazontrust.com/rootca1.crl0
unknown
clean
https://aws.amazon.com/search/
unknown
clean
https://console.aws.amazon.com/iam/home?nc2=h_m_sc#security_credential
unknown
clean
https://aws.amazon.com/?nc2=h_lg
unknown
clean
http://ocsp.rootca1.amazontrust.com0:
unknown
clean
https://console.aws.amazon.com/support/home/?nc1=f_dr
unknown
clean
https://aws.amazon.com/fr/
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
https://console.aws.amazon.com/console/home?nc1=f_ct&src=footer-signin-mobile
unknown
clean
https://aws.amazon.com/vi/
unknown
clean
https://www.twitch.tv/aws
unknown
clean
https://a0.awsstatic.com/aws-blog/1.0.34/js
unknown
clean
https://aws.amazon.com/marketplace/?nc2=h_ql_mp
unknown
clean
https://aws.amazon.com/search
unknown
clean
http://crl.rootg2.amazontrust.com/rootg2.crl0
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
https://a0.awsstatic.com/da/js/1.0.47/aws-da.js
unknown
clean
https://aws.amazon.com/tw/
unknown
clean
https://aws.amazon.com/tr/?nc1=h_ls
unknown
clean
https://console.aws.amazon.com/?nc2=h_m_mc
unknown
clean
https://aws.amazon.com/fr/?nc1=h_ls
unknown
clean
http://o.ss2.us/0
unknown
clean
https://aws.amazon.com/search/?searchQuery=
unknown
clean
https://a0.awsstatic.com/libra-search/1.0.13/js
unknown
clean
https://aws.amazon.com/privacy/?nc1=f_pr
unknown
clean
https://a0.awsstatic.com/libra/1.0.373/libra-cardsui
unknown
clean
https://aws.amazon.com/pt/?nc1=h_ls
unknown
clean
https://aws.amazon.com/jp/?nc1=h_ls
unknown
clean
http://crl.entrust.net/2048ca.crl0
unknown
clean
https://aws.amazon.com/marketplace?aws=hp
unknown
clean
https://aws.amazon.com/
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
https://a0.awsstatic.com/libra-css/images/site/touch-icon-ipad-144-smile.png
unknown
clean
https://a0.awsstatic.com/s_code/js/3.0/awshome_s_code.js
unknown
clean
http://ocsp.sectigo.com0
unknown
clean
https://aws.amazon.com/podcasts/aws-podcast/
unknown
clean
http://ocsp.entrust.net03
unknown
clean
https://aws.amazon.com/jp/
unknown
clean
http://crt.rootg2.amazontrust.com/rootg2.cer0=
unknown
clean
https://aws.amazon.com/pt/
unknown
clean
https://a0.awsstatic.com/plc/js/1.0.107/plc
unknown
clean
https://aws.amazon.com/?nc1=h_ls
unknown
clean
https://s0.awsstatic.com/en_US/nav/v3/panel-content/desktop/index.html
unknown
clean
https://aws.amazon.com/es/?nc1=h_ls
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
https://d1.awsstatic.com
unknown
clean
https://aws.amazon.com/de/
unknown
clean
http://investor.msn.com/
unknown
clean
https://phd.aws.amazon.com/?nc2=h_m_sc
unknown
clean
https://aws.amazon.com/id/?nc1=h_ls
unknown
clean
https://miraclecollagen.co.za/ds/1802.Dc
unknown
clean
https://a0.awsstatic.com/libra-css/images/logos/aws_logo_smile_1200x630.png
unknown
clean
https://sectigo.com/CPS0D
unknown
clean
http://www.%s.comPA
unknown
clean
https://portal.aws.amazon.com/gp/aws/developer/registration/index.html?nc2=h_ct&src=default
unknown
clean
https://a0.awsstatic.com
unknown
clean
http://ocsp.entrust.net0D
unknown
clean
https://pages.awscloud.com/fico-case-study.html?hp=tile&story=fico
unknown
clean
http://s.ss2.us/r.crl0
unknown
clean
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
oskolko.uno
206.189.10.247
malicious
dr49lng3n1n2s.cloudfront.net
143.204.4.74
clean
miraclecollagen.co.za
197.242.147.47
clean
aws.amazon.com
unknown
clean

IPs

IP
Domain
Country
Active
Malicious
206.189.10.247
unknown
United States
unknown
malicious
197.242.147.47
unknown
South Africa
unknown
clean
143.204.4.74
unknown
United States
unknown
clean

Registry

Path
Value
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
291
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
MTTT
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ReviewToken
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EF528
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
VBAFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DefaultSheetR2L
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
UseSystemSeparators
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ThousandsSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DecimalSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EF93D
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EFA94
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EFD62
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EFE2D
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} {000214E6-0000-0000-C000-000000000046} 0xFFFF
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
m(1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\system32\qagentrt.dll,-10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\System32\fveui.dll,-843
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\System32\fveui.dll,-844
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\System32\wuaueng.dll,-400
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F7FE9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F81FC
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
LastPurgeTime
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EXCELFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SavedLegacySettings
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Windows\System32\rundll32.exe
Blob
clean
C:\Windows\System32\rundll32.exe
Blob
clean
There are 108 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
37F000
heap default
page read and write
malicious
7FEEA7C5000
unkown image
page read and write
clean
2DA0000
unkown
page readonly
clean
7FEEAC2F000
unkown image
page readonly
clean
3F5000
heap default
page read and write
clean
2B50000
heap private
page read and write
clean
23B000
heap default
page read and write
clean
850000
unkown
page readonly
clean
2D20000
heap private
page read and write
clean
7FEEA7C4000
unkown image
page readonly
clean
120000
unkown
page readonly
clean
130000
heap private
page read and write
clean
1C80000
unkown
page readonly
clean
405000
unkown
page read and write
clean
22D000
heap default
page read and write
clean
219C000
unkown
page read and write
clean
7FEEA7C7000
unkown image
page execute read
clean
446000
unkown
page read and write
clean
326000
unkown
page read and write
clean
1F7000
heap default
page read and write
clean
410000
unkown
page read and write
clean
3EB000
heap default
page read and write
clean
230000
unkown
page readonly
clean
560000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
554000
heap private
page read and write
clean
379000
heap default
page read and write
clean
2A10000
unkown
page read and write
clean
28E0000
heap private
page read and write
clean
26A9000
heap private
page read and write
clean
283F000
unkown
page read and write
clean
2192000
unkown
page read and write
clean
6E0000
unkown
page readonly
clean
11D000
unkown
page read and write
clean
7FEEA7C6000
unkown image
page readonly
clean
D0000
unkown
page read and write
clean
60000
unkown
page readonly
clean
6CF000
unkown
page read and write
clean
550000
heap private
page read and write
clean
34E000
heap default
page read and write
clean
2B63000
heap private
page read and write
clean
2240000
unkown
page readonly
clean
2A4B000
unkown
page read and write
clean
310000
heap default
page read and write
clean
20000
unkown
page readonly
clean
56E000
unkown
page read and write
clean
1F0000
heap default
page read and write
clean
21C5000
heap private
page read and write
clean
21FB000
heap private
page read and write
clean
7FEEA7C0000
unkown image
page readonly
clean
110000
unkown
page read and write
clean
2A79000
unkown
page read and write
clean
E0000
unkown
page read and write
clean
46F000
unkown
page read and write
clean
110000
unkown
page read and write
clean
268C000
unkown
page read and write
clean
BDF000
unkown
page read and write
clean
21C0000
heap private
page read and write
clean
2A0C000
unkown
page read and write
clean
4C0000
heap private
page read and write
clean
7FEEA7C0000
unkown image
page readonly
clean
236000
heap default
page read and write
clean
36B000
heap default
page read and write
clean
2510000
unkown
page write copy
clean
4C4000
heap private
page read and write
clean
1E67000
unkown
page readonly
clean
26DF000
heap private
page read and write
clean
317000
heap default
page read and write
clean
110000
unkown
page read and write
clean
100000
unkown
page readonly
clean
3ED000
heap default
page read and write
clean
7FEEA7C1000
unkown image
page execute read
clean
2CAF000
unkown
page read and write
clean
40F000
heap default
page read and write
clean
22C000
unkown
page read and write
clean
26A0000
heap private
page read and write
clean
There are 66 hidden memdumps, click here to show them.