IOCReport

loading gif

Files

File Path
Type
Category
Malicious
Complaint_Letter_1186814227-02192021.xls
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1251, Last Saved By: Friner, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 01:00:00 2006, Last Saved Time/Date: Fri Feb 19 09:43:01 2021, Security: 0
initial sample
malicious
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Microsoft Cabinet archive data, 59134 bytes, 1 file
dropped
clean
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E0F5C59F9FA661F6F4C50B87FEF3A15A
data
dropped
clean
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
data
dropped
clean
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E0F5C59F9FA661F6F4C50B87FEF3A15A
data
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\44250678185879600000[1].htm
HTML document, ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\B1CE0000
data
dropped
clean
C:\Users\user\AppData\Local\Temp\CabD164.tmp
Microsoft Cabinet archive data, 59134 bytes, 1 file
dropped
clean
C:\Users\user\AppData\Local\Temp\TarD165.tmp
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Complaint_Letter_1186814227-02192021.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Aug 26 14:08:12 2020, mtime=Tue Feb 23 23:16:35 2021, atime=Tue Feb 23 23:16:35 2021, length=57856, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Tue Oct 17 10:04:00 2017, mtime=Tue Feb 23 23:16:35 2021, atime=Tue Feb 23 23:16:35 2021, length=8192, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\05Q27A4H.txt
ASCII text
downloaded
clean
C:\Users\user\Desktop\72CE0000
Applesoft BASIC program data, first line number 16
dropped
clean
There are 4 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\rundll32.exe
rundll32 ..\KLSD.ggsso,DllRegisterServer
malicious
C:\Windows\System32\rundll32.exe
rundll32 ..\KLSD.ggsso1,DllRegisterServer
malicious
C:\Windows\System32\rundll32.exe
rundll32 ..\KLSD.ggsso2,DllRegisterServer
malicious
C:\Windows\System32\rundll32.exe
rundll32 ..\KLSD.ggsso3,DllRegisterServer
malicious
C:\Windows\System32\rundll32.exe
rundll32 ..\KLSD.ggsso4,DllRegisterServer
malicious

URLs

Name
IP
Malicious
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://www.windows.com/pctv.
unknown
clean
http://jayshreewoods.com/gvazzbwlvyk/44250678185879600000.dat
13.126.100.34
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://sportsmarquee.com/hmffuzbolyio/44250678185879600000.dat
70.32.104.19
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://investor.msn.com/
unknown
clean
http://raivens.com/zdmqwymhhza/44250678185879600000.dat
159.89.174.35
clean
http://erp.demosoftware.biz/focahjqevd/44250678185879600000.dat
58.96.102.67
clean
There are 2 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
parama-college.id
203.142.76.236
clean
erp.demosoftware.biz
58.96.102.67
clean
sportsmarquee.com
70.32.104.19
clean
raivens.com
159.89.174.35
clean
jayshreewoods.com
13.126.100.34
clean

IPs

IP
Domain
Country
Active
Malicious
13.126.100.34
unknown
United States
unknown
clean
159.89.174.35
unknown
United States
unknown
clean
58.96.102.67
unknown
Australia
unknown
clean
203.142.76.236
unknown
Indonesia
unknown
clean
70.32.104.19
unknown
United States
unknown
clean

Registry

Path
Value
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
e~6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
MTTT
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ReviewToken
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EBE40
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
VBAFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DefaultSheetR2L
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
UseSystemSeparators
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ThousandsSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DecimalSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EC081
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EC14C
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EC246
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EC2D2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} {000214E6-0000-0000-C000-000000000046} 0xFFFF
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ng6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\system32\qagentrt.dll,-10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\System32\fveui.dll,-843
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\System32\fveui.dll,-844
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\System32\wuaueng.dll,-400
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
LastPurgeTime
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
100030
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
100232
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EXCELFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SavedLegacySettings
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
There are 108 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
2965000
unkown
page readonly
clean
2AD2000
unkown
page readonly
clean
20000
unkown
page readonly
clean
2852000
unkown
page readonly
clean
E0000
unkown
page read and write
clean
21D0000
unkown
page readonly
clean
31E000
heap default
page read and write
clean
2975000
unkown
page readonly
clean
2BB000
heap default
page read and write
clean
2BB0000
unkown
page read and write
clean
29A2000
unkown
page readonly
clean
2804000
unkown
page readonly
clean
1BC0000
unkown
page readonly
clean
2050000
heap private
page read and write
clean
1FA0000
unkown
page write copy
clean
22A0000
unkown
page readonly
clean
1D0000
heap private
page read and write
clean
1D4000
heap private
page read and write
clean
2C6000
unkown
page read and write
clean
2962000
unkown
page readonly
clean
2825000
unkown
page readonly
clean
2A26000
unkown
page readonly
clean
2C52000
unkown
page readonly
clean
2389000
heap private
page read and write
clean
2648000
unkown
page readonly
clean
2E90000
heap private
page read and write
clean
2768000
unkown
page readonly
clean
2839000
unkown
page readonly
clean
2100000
unkown
page readonly
clean
100000
unkown
page write copy
clean
2552000
unkown
page readonly
clean
2055000
heap private
page read and write
clean
2909000
unkown
page readonly
clean
D0000
unkown
page read and write
clean
3C0000
unkown
page readonly
clean
2B02000
unkown
page readonly
clean
2802000
unkown
page readonly
clean
28D5000
unkown
page readonly
clean
1AE000
heap default
page read and write
clean
28C6000
unkown
page readonly
clean
2A99000
unkown
page readonly
clean
2AF5000
unkown
page readonly
clean
2CB0000
heap private
page read and write
clean
2A62000
unkown
page readonly
clean
60000
unkown
page read and write
clean
2A62000
unkown
page readonly
clean
60000
unkown
page readonly
clean
2AE5000
unkown
page readonly
clean
2229000
heap private
page read and write
clean
3A0000
unkown
page read and write
clean
41E000
heap default
page read and write
clean
29F2000
unkown
page readonly
clean
60000
unkown
page readonly
clean
2280000
unkown
page readonly
clean
2F10000
unkown
page readonly
clean
277000
heap default
page read and write
clean
2200000
heap private
page read and write
clean
2A86000
unkown
page readonly
clean
2A15000
unkown
page readonly
clean
2C0000
heap default
page read and write
clean
28E2000
unkown
page readonly
clean
2945000
unkown
page readonly
clean
E0000
unkown
page read and write
clean
2A42000
unkown
page readonly
clean
15C000
unkown
page read and write
clean
5BE000
unkown
page read and write
clean
27E2000
unkown
page readonly
clean
2B09000
unkown
page readonly
clean
EB000
unkown
page read and write
clean
370000
unkown
page read and write
clean
28F6000
unkown
page readonly
clean
290000
unkown
page read and write
clean
660000
unkown
page readonly
clean
1B90000
unkown
page readonly
clean
2742000
unkown
page readonly
clean
60000
unkown
page readonly
clean
210000
unkown
page write copy
clean
2A49000
unkown
page readonly
clean
2952000
unkown
page readonly
clean
1DA7000
unkown
page readonly
clean
2A80000
unkown
page readonly
clean
2D20000
heap private
page read and write
clean
2DE000
heap default
page read and write
clean
27E2000
unkown
page readonly
clean
2732000
unkown
page readonly
clean
27E4000
unkown
page readonly
clean
28A6000
unkown
page readonly
clean
214000
heap private
page read and write
clean
2D25000
heap private
page read and write
clean
2D10000
unkown
page readonly
clean
D0000
unkown
page read and write
clean
18B000
unkown
page read and write
clean
170000
heap default
page read and write
clean
2340000
heap private
page read and write
clean
27C5000
unkown
page readonly
clean
2B90000
unkown
page readonly
clean
380000
unkown
page write copy
clean
1B30000
unkown
page readonly
clean
164000
heap private
page read and write
clean
2400000
unkown
page readonly
clean
2B50000
unkown
page readonly
clean
2130000
heap private
page read and write
clean
29A2000
unkown
page readonly
clean
4E0000
unkown
page readonly
clean
2642000
unkown
page readonly
clean
2AA0000
unkown
page readonly
clean
210000
heap private
page read and write
clean
2A69000
unkown
page readonly
clean
283D000
unkown
page readonly
clean
29A9000
unkown
page readonly
clean
1D17000
unkown
page readonly
clean
28B9000
unkown
page readonly
clean
2FE000
heap default
page read and write
clean
2B70000
unkown
page readonly
clean
2C7000
heap default
page read and write
clean
60000
unkown
page readonly
clean
1D77000
unkown
page readonly
clean
28B5000
unkown
page readonly
clean
27A2000
unkown
page readonly
clean
2992000
unkown
page readonly
clean
2A6000
unkown
page read and write
clean
2964000
unkown
page readonly
clean
2734000
unkown
page readonly
clean
620000
unkown
page readonly
clean
28D2000
unkown
page readonly
clean
29D2000
unkown
page readonly
clean
292D000
unkown
page readonly
clean
2CF0000
unkown
page read and write
clean
2802000
unkown
page readonly
clean
2795000
unkown
page readonly
clean
F0000
unkown
page readonly
clean
2929000
unkown
page readonly
clean
2882000
unkown
page readonly
clean
2842000
unkown
page readonly
clean
2752000
unkown
page readonly
clean
2349000
heap private
page read and write
clean
2205000
heap private
page read and write
clean
2B70000
unkown
page readonly
clean
28E5000
unkown
page readonly
clean
2754000
unkown
page readonly
clean
1DE7000
unkown
page readonly
clean
2889000
unkown
page readonly
clean
2804000
unkown
page readonly
clean
60000
unkown
page readonly
clean
2922000
unkown
page readonly
clean
28F5000
unkown
page readonly
clean
2A45000
unkown
page readonly
clean
2806000
unkown
page readonly
clean
2782000
unkown
page readonly
clean
470000
unkown
page readonly
clean
2E0000
heap default
page read and write
clean
20000
unkown
page readonly
clean
160000
unkown
page read and write
clean
2380000
heap private
page read and write
clean
2AC2000
unkown
page readonly
clean
2CD0000
unkown
page readonly
clean
2A75000
unkown
page readonly
clean
2A89000
unkown
page readonly
clean
2875000
unkown
page readonly
clean
2CEB000
heap private
page read and write
clean
28A2000
unkown
page readonly
clean
2862000
unkown
page readonly
clean
2B12000
unkown
page readonly
clean
2926000
unkown
page readonly
clean
2885000
unkown
page readonly
clean
2AA9000
unkown
page readonly
clean
2982000
unkown
page readonly
clean
1C0000
heap private
page read and write
clean
2A92000
unkown
page readonly
clean
29D5000
unkown
page readonly
clean
2AC0000
unkown
page readonly
clean
1C4000
heap private
page read and write
clean
2A22000
unkown
page readonly
clean
260000
unkown
page read and write
clean
20B000
unkown
page read and write
clean
2812000
unkown
page readonly
clean
28A5000
unkown
page readonly
clean
270000
heap default
page read and write
clean
18D000
unkown
page read and write
clean
20000
unkown
page readonly
clean
29E5000
unkown
page readonly
clean
2DA0000
unkown
page readonly
clean
2AD9000
unkown
page readonly
clean
2949000
unkown
page readonly
clean
20000
unkown
page readonly
clean
3E0000
heap default
page read and write
clean
2882000
unkown
page readonly
clean
26F000
unkown
page read and write
clean
4E0000
unkown
page readonly
clean
2385000
heap private
page read and write
clean
23E0000
unkown
page readonly
clean
2E7000
heap default
page read and write
clean
2915000
unkown
page readonly
clean
27F5000
unkown
page readonly
clean
2942000
unkown
page readonly
clean
2AE0000
unkown
page readonly
clean
160000
heap private
page read and write
clean
2B6000
heap default
page read and write
clean
2714000
unkown
page readonly
clean
2859000
unkown
page readonly
clean
A9F000
unkown
page read and write
clean
2D5B000
heap private
page read and write
clean
2AD000
heap default
page read and write
clean
416000
unkown
page read and write
clean
2995000
unkown
page readonly
clean
2DA0000
unkown
page readonly
clean
23C0000
unkown
page readonly
clean
2D30000
unkown
page readonly
clean
2822000
unkown
page readonly
clean
196000
unkown
page read and write
clean
29C2000
unkown
page readonly
clean
2A32000
unkown
page readonly
clean
2558000
unkown
page readonly
clean
29F6000
unkown
page readonly
clean
2CD0000
unkown
page readonly
clean
2972000
unkown
page readonly
clean
2C92000
unkown
page readonly
clean
2906000
unkown
page readonly
clean
2A7000
heap default
page read and write
clean
2902000
unkown
page readonly
clean
2824000
unkown
page readonly
clean
2964000
unkown
page readonly
clean
3E7000
heap default
page read and write
clean
2BB0000
unkown
page readonly
clean
29A5000
unkown
page readonly
clean
177000
heap default
page read and write
clean
27A8000
unkown
page readonly
clean
2EF0000
unkown
page readonly
clean
5F0000
unkown
page readonly
clean
2420000
unkown
page readonly
clean
E0000
unkown
page read and write
clean
29B6000
unkown
page readonly
clean
2865000
unkown
page readonly
clean
1C00000
unkown
page readonly
clean
28D6000
unkown
page readonly
clean
160000
unkown
page read and write
clean
2896000
unkown
page readonly
clean
2712000
unkown
page readonly
clean
2AC5000
unkown
page readonly
clean
2A4D000
unkown
page readonly
clean
28B2000
unkown
page readonly
clean
2D20000
heap private
page read and write
clean
3D6000
unkown
page read and write
clean
2040000
unkown
page write copy
clean
2225000
heap private
page read and write
clean
29A4000
unkown
page readonly
clean
2895000
unkown
page readonly
clean
2762000
unkown
page readonly
clean
2929000
unkown
page readonly
clean
290D000
unkown
page readonly
clean
1C00000
unkown
page readonly
clean
540000
unkown
page readonly
clean
2220000
heap private
page read and write
clean
2CF0000
unkown
page readonly
clean
2924000
unkown
page readonly
clean
4A0000
unkown
page readonly
clean
2B25000
unkown
page readonly
clean
2E70000
heap private
page read and write
clean
2982000
unkown
page readonly
clean
660000
unkown
page readonly
clean
2979000
unkown
page readonly
clean
20000
unkown
page readonly
clean
D0000
unkown
page read and write
clean
2652000
unkown
page readonly
clean
2A0000
heap default
page read and write
clean
594000
heap private
page read and write
clean
2AC9000
unkown
page readonly
clean
21B0000
unkown
page readonly
clean
2962000
unkown
page readonly
clean
28B2000
unkown
page readonly
clean
2345000
heap private
page read and write
clean
2A16000
unkown
page readonly
clean
1F70000
unkown
page readonly
clean
1DE7000
unkown
page readonly
clean
2984000
unkown
page readonly
clean
3E0000
unkown
page read and write
clean
28C5000
unkown
page readonly
clean
2B90000
unkown
page readonly
clean
28C000
unkown
page read and write
clean
2C90000
unkown
page readonly
clean
3000000
unkown
page read and write
clean
27A6000
unkown
page readonly
clean
640000
unkown
page readonly
clean
29A5000
unkown
page readonly
clean
2E95000
heap private
page read and write
clean
28A2000
unkown
page readonly
clean
2D25000
heap private
page read and write
clean
2A85000
unkown
page readonly
clean
2059000
heap private
page read and write
clean
21A0000
unkown
page readonly
clean
2AB5000
unkown
page readonly
clean
270000
unkown
page read and write
clean
2844000
unkown
page readonly
clean
464000
heap private
page read and write
clean
2A56000
unkown
page readonly
clean
2A02000
unkown
page readonly
clean
2628000
unkown
page readonly
clean
2EAB000
heap private
page read and write
clean
460000
heap private
page read and write
clean
9CF000
unkown
page read and write
clean
2872000
unkown
page readonly
clean
21F0000
unkown
page read and write
clean
2050000
heap private
page read and write
clean
1FC0000
heap private
page read and write
clean
2852000
unkown
page readonly
clean
D0000
unkown
page read and write
clean
2170000
heap private
page read and write
clean
2E75000
heap private
page read and write
clean
2836000
unkown
page readonly
clean
2A05000
unkown
page readonly
clean
2A8D000
unkown
page readonly
clean
22A0000
unkown
page readonly
clean
2CB5000
heap private
page read and write
clean
2722000
unkown
page readonly
clean
2942000
unkown
page readonly
clean
2CB0000
unkown
page readonly
clean
2A46000
unkown
page readonly
clean
2A35000
unkown
page readonly
clean
2D5B000
heap private
page read and write
clean
27B2000
unkown
page readonly
clean
2944000
unkown
page readonly
clean
2B32000
unkown
page readonly
clean
22C0000
unkown
page readonly
clean
2ECB000
heap private
page read and write
clean
2822000
unkown
page readonly
clean
2209000
heap private
page read and write
clean
2922000
unkown
page readonly
clean
1FE0000
unkown
page readonly
clean
2AA2000
unkown
page readonly
clean
29E6000
unkown
page readonly
clean
29C5000
unkown
page readonly
clean
2120000
heap private
page read and write
clean
2959000
unkown
page readonly
clean
2989000
unkown
page readonly
clean
590000
heap private
page read and write
clean
2824000
unkown
page readonly
clean
20D0000
unkown
page read and write
clean
2622000
unkown
page readonly
clean
3A6000
unkown
page read and write
clean
27D6000
unkown
page readonly
clean
2876000
unkown
page readonly
clean
There are 331 hidden memdumps, click here to show them.