IOCReport

loading gif

Files

File Path
Type
Category
Malicious
document-1251000362.xlsm
Microsoft Excel 2007+
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\3003[1].gif
PE32+ executable (DLL) (native) x86-64, for MS Windows
downloaded
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\3003[1].gif
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
downloaded
malicious
C:\Users\user\Desktop\~$document-1251000362.xlsm
data
dropped
malicious
C:\Users\user\ksjvoefv.skd
PE32+ executable (DLL) (native) x86-64, for MS Windows
dropped
malicious
C:\Users\user\ksjvoefv.skd3
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
malicious
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Microsoft Cabinet archive data, 58596 bytes, 1 file
dropped
clean
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E0F5C59F9FA661F6F4C50B87FEF3A15A
data
dropped
clean
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
data
dropped
clean
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E0F5C59F9FA661F6F4C50B87FEF3A15A
data
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\4AE58898.png
PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\77F73266.png
PNG image data, 485 x 185, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\98EC7FB9.png
PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\DFB60433.png
PNG image data, 205 x 58, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Temp\C4DE0000
data
dropped
clean
C:\Users\user\AppData\Local\Temp\CabDF39.tmp
Microsoft Cabinet archive data, 58596 bytes, 1 file
dropped
clean
C:\Users\user\AppData\Local\Temp\TarDF3A.tmp
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Tue Oct 17 10:04:00 2017, mtime=Wed Apr 7 01:35:39 2021, atime=Wed Apr 7 01:35:39 2021, length=16384, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\document-1251000362.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Aug 26 14:08:16 2020, mtime=Wed Apr 7 01:35:39 2021, atime=Wed Apr 7 01:35:40 2021, length=108032, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\Desktop\A5DE0000
data
dropped
clean
There are 11 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\rundll32.exe
rundll32 ..\ksjvoefv.skd,DllRegisterServer
malicious
C:\Windows\System32\rundll32.exe
rundll32 ..\ksjvoefv.skd1,DllRegisterServer
malicious
C:\Windows\System32\rundll32.exe
rundll32 ..\ksjvoefv.skd2,DllRegisterServer
malicious
C:\Windows\System32\rundll32.exe
rundll32 ..\ksjvoefv.skd3,DllRegisterServer
malicious
C:\Windows\System32\rundll32.exe
rundll32 ..\ksjvoefv.skd4,DllRegisterServer
malicious

URLs

Name
IP
Malicious
https://twitter.com/awscloud
unknown
clean
https://a0.awsstatic.com/libra-css/images/logo
unknown
clean
https://aws.amazon.com/terms/?nc1=f_pr
unknown
clean
https://dc.ads.linkedin.com/collect/?pid=3038&fmt=gif
unknown
clean
https://s0.awsstatic.com/en_US/nav/v3/panel-content/mobile/index.html
unknown
clean
https://a0.awsstatic.com/plc/js/1.0.108/plc
unknown
clean
https://aws.amazon.com/cn/
unknown
clean
http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl0
unknown
clean
http://www.diginotar.nl/cps/pkioverheid0
unknown
clean
https://a0.awsstatic.com/libra-css/images
unknown
clean
https://a0.awsstatic.com/psf/null
unknown
clean
https://aws.amazon.com/ar/
unknown
clean
https://www.honeycode.aws/?&trk=el_a134p000003yC6YAAU&trkCampaign=pac-edm-2020-honeycode-hom
unknown
clean
https://pages.awscloud.com/zillow-case-study?hp=tile&story=zllw
unknown
clean
https://pages.awscloud.com/communication-preferences?trk=homepage
unknown
clean
http://ocsp.rootg2.amazontrust.com08
unknown
clean
https://aws.amazon.com/cn/?nc1=h_ls
unknown
clean
https://portal.aws.amazon.com/gp/aws/developer/registration/index.html?nc1=f_ct&src=default
unknown
clean
http://usaaforced.fun/
unknown
clean
https://aws.amazon.com/ru/
unknown
clean
https://aws.amazon.com/tw/?nc1=h_ls
unknown
clean
https://fls-na.amazon.com/1/action-impressions/1/OE/aws-mktg/action/awsm_:comp_DeprecatedBrowser
unknown
clean
https://i18n-string.us-west-2.prod.pricing.aws.a2z.com
unknown
clean
https://aws.amazon.com/ko/
unknown
clean
https://aws.amazon.com/ru/?nc1=h_ls
unknown
clean
http://usaaforced.fun/Q
unknown
clean
https://a0.awsstatic.com/libra-css/images/site/fav/favicon.ico
unknown
clean
https://aws.amazon.com/es/
unknown
clean
http://crl.sca1b.amazontrust.com/sca1b.crl0
unknown
clean
https://a0.awsstatic.com/target/1.0.113/aws-target-mediator.js
unknown
clean
https://docs.aws.amazon.com/index.html?nc2=h_ql_doc
unknown
clean
http://tvorartificialnature.xyz/
unknown
clean
https://aws.amazon.com/ar/?nc1=h_ls
unknown
clean
https://aws.amazon.com/k
unknown
clean
https://aws.amazon.com/th/
unknown
clean
http://www.windows.com/pctv.
unknown
clean
https://a0.awsstatic.com/pricing-calculator/js/1.0.2
unknown
clean
https://aws.amazon.com/marketplace/?nc2=h_mo
unknown
clean
http://ocsp.sca1b.amazontrust.com06
unknown
clean
https://amazon.com/
unknown
clean
https://a0.awsstatic.com/libra-css/images/logos/aws_logo_smile_179x109.png
unknown
clean
https://console.aws.amazon.com/support/home/?nc2=h_ql_cu
unknown
clean
http://crl.rootca1.amazontrust.com/rootca1.crl0
unknown
clean
https://aws.amazon.com/search/
unknown
clean
https://console.aws.amazon.com/iam/home?nc2=h_m_sc#security_credential
unknown
clean
https://aws.amazon.com/?nc2=h_lg
unknown
clean
http://ocsp.rootca1.amazontrust.com0:
unknown
clean
https://console.aws.amazon.com/support/home/?nc1=f_dr
unknown
clean
https://a0.awsstatic.com/aws-blog/1.0.46/js
unknown
clean
https://aws.amazon.com/fr/
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
https://console.aws.amazon.com/console/home?nc1=f_ct&src=footer-signin-mobile
unknown
clean
https://aws.amazon.com/vi/
unknown
clean
https://www.twitch.tv/aws
unknown
clean
http://usaaforced.fun/k
unknown
clean
https://aws.amazon.com/marketplace/?nc2=h_ql_mp
unknown
clean
https://aws.amazon.com/search
unknown
clean
http://crl.rootg2.amazontrust.com/rootg2.crl0
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
https://a0.awsstatic.com/da/js/1.0.47/aws-da.js
unknown
clean
https://aws.amazon.com/tw/
unknown
clean
https://aws.amazon.com/tr/?nc1=h_ls
unknown
clean
https://console.aws.amazon.com/?nc2=h_m_mc
unknown
clean
https://aws.amazon.com/fr/?nc1=h_ls
unknown
clean
http://o.ss2.us/0
unknown
clean
https://aws.amazon.com/search/?searchQuery=
unknown
clean
https://a0.awsstatic.com/libra-search/1.0.13/js
unknown
clean
http://crt.rootca1.am
unknown
clean
https://aws.amazon.com/privacy/?nc1=f_pr
unknown
clean
https://aws.amazon.com/pt/?nc1=h_ls
unknown
clean
https://aws.amazon.com/jp/?nc1=h_ls
unknown
clean
http://crl.entrust.net/2048ca.crl0
unknown
clean
https://aws.amazon.com/marketplace?aws=hp
unknown
clean
https://aws.amazon.com/
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
https://a0.awsstatic.com/libra-css/images/site/touch-icon-ipad-144-smile.png
unknown
clean
https://a0.awsstatic.com/s_code/js/3.0/awshome_s_code.js
unknown
clean
https://aws.amazon.com/podcasts/aws-podcast/
unknown
clean
http://ocsp.entrust.net03
unknown
clean
https://aws.amazon.com/jp/
unknown
clean
http://crt.rootg2.amazontrust.com/rootg2.cer0=
unknown
clean
https://aws.amazon.com/pt/
unknown
clean
https://aws.amazon.com/?nc1=h_ls
unknown
clean
https://s0.awsstatic.com/en_US/nav/v3/panel-content/desktop/index.html
unknown
clean
http://crt.comod
unknown
clean
https://aws.amazon.com/es/?nc1=h_ls
unknown
clean
https://a0.awsstatic.com/libra-css/images/logoo
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
https://d1.awsstatic.com
unknown
clean
https://aws.amazon.com/de/
unknown
clean
http://investor.msn.com/
unknown
clean
https://phd.aws.amazon.com/?nc2=h_m_sc
unknown
clean
https://a0.awsstatic.com/libra/1.0.376/librastandardlib
unknown
clean
https://aws.amazon.com/id/?nc1=h_ls
unknown
clean
https://a0.awsstatic.com/libra-css/images/logos/aws_logo_smile_1200x630.png
unknown
clean
http://www.%s.comPA
unknown
clean
https://portal.aws.amazon.com/gp/aws/developer/registration/index.html?nc2=h_ct&src=default
unknown
clean
https://a0.awsstatic.com
unknown
clean
http://ocsp.entrust.net0D
unknown
clean
https://pages.awscloud.com/fico-case-study.html?hp=tile&story=fico
unknown
clean
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
agenbolatermurah.com
unknown
malicious
usaaforced.fun
unknown
malicious
tvorartificialnature.xyz
unknown
malicious
metaflip.io
192.185.48.186
clean
tajushariya.com
199.79.62.99
clean
columbia.aula-web.net
50.87.146.86
clean
dr49lng3n1n2s.cloudfront.net
143.204.3.74
clean
partsapp.com.br
192.185.214.87
clean
aws.amazon.com
unknown
clean

IPs

IP
Domain
Country
Malicious
50.87.146.86
columbia.aula-web.net
United States
clean
199.79.62.99
tajushariya.com
United States
clean
192.185.214.87
partsapp.com.br
United States
clean
143.204.3.74
dr49lng3n1n2s.cloudfront.net
United States
clean
192.185.48.186
metaflip.io
United States
clean
192.168.2.255
unknown
unknown
clean

Registry

Path
Value
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
p`7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
MTTT
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ReviewToken
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ED079
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
VBAFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DefaultSheetR2L
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
UseSystemSeparators
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ThousandsSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DecimalSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ED402
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ED568
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ED614
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} {000214E6-0000-0000-C000-000000000046} 0xFFFF
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
?j7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\system32\qagentrt.dll,-10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\System32\fveui.dll,-843
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\System32\fveui.dll,-844
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\System32\wuaueng.dll,-400
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
LastPurgeTime
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
110435
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
111140
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EXCELFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SavedLegacySettings
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
There are 109 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
152000
unkown
page read and write
malicious
152000
unkown
page read and write
malicious
DD000
unkown
page read and write
malicious
DD000
unkown
page read and write
malicious
DD000
unkown
page read and write
malicious
152000
unkown
page read and write
malicious
DD000
unkown
page read and write
malicious
152000
unkown
page read and write
malicious
DD000
unkown
page read and write
malicious
152000
unkown
page read and write
malicious
DD000
unkown
page read and write
malicious
DD000
unkown
page read and write
malicious
152000
unkown
page read and write
malicious
152000
unkown
page read and write
malicious
DD000
unkown
page read and write
malicious
152000
unkown
page read and write
malicious
152000
unkown
page read and write
malicious
DD000
unkown
page read and write
malicious
152000
unkown
page read and write
malicious
DD000
unkown
page read and write
malicious
152000
unkown
page read and write
malicious
DD000
unkown
page read and write
malicious
152000
unkown
page read and write
malicious
DD000
unkown
page read and write
malicious
DD000
unkown
page read and write
malicious
152000
unkown
page read and write
malicious
DD000
unkown
page read and write
malicious
DD000
unkown
page read and write
malicious
DD000
unkown
page read and write
malicious
DD000
unkown
page read and write
malicious
DD000
heap default
page read and write
malicious
DD000
unkown
page read and write
malicious
152000
unkown
page read and write
malicious
152000
unkown
page read and write
malicious
DD000
unkown
page read and write
malicious
152000
unkown
page read and write
malicious
DD000
unkown
page read and write
malicious
DD000
unkown
page read and write
malicious
152000
unkown
page read and write
malicious
152000
unkown
page read and write
malicious
152000
unkown
page read and write
malicious
152000
unkown
page read and write
malicious
152000
unkown
page read and write
malicious
DD000
unkown
page read and write
malicious
152000
unkown
page read and write
malicious
F9000
unkown
page read and write
clean
F9000
unkown
page read and write
clean
31DC000
unkown
page read and write
clean
439000
unkown
page read and write
clean
2BD0000
unkown
page readonly
clean
31E1000
unkown
page read and write
clean
3202000
unkown
page read and write
clean
28E9000
unkown
page readonly
clean
386000
heap default
page read and write
clean
2200000
unkown
page readonly
clean
439000
unkown
page read and write
clean
31E1000
unkown
page read and write
clean
16A000
unkown
page read and write
clean
142000
unkown
page read and write
clean
426000
unkown
page read and write
clean
443000
unkown
page read and write
clean
44E000
unkown
page read and write
clean
D8000
unkown
page read and write
clean
28A4000
unkown
page readonly
clean
3AF000
unkown
page read and write
clean
2C77000
unkown
page read and write
clean
150000
unkown
page read and write
clean
28B9000
unkown
page readonly
clean
376000
heap default
page read and write
clean
2985000
unkown
page readonly
clean
D8000
unkown
page read and write
clean
2A72000
unkown
page readonly
clean
426000
unkown
page read and write
clean
31E1000
unkown
page read and write
clean
2A25000
unkown
page readonly
clean
450000
unkown
page readonly
clean
2B0000
unkown
page execute and read and write
clean
3230000
unkown
page read and write
clean
426000
unkown
page read and write
clean
2099000
heap private
page read and write
clean
426000
unkown
page read and write
clean
2902000
unkown
page readonly
clean
14A000
unkown
page read and write
clean
31E1000
unkown
page read and write
clean
31F6000
unkown
page read and write
clean
16A000
unkown
page read and write
clean
142000
unkown
page read and write
clean
443000
unkown
page read and write
clean
2280000
heap private
page read and write
clean
142000
unkown
page read and write
clean
27E000
heap default
page read and write
clean
31E1000
unkown
page read and write
clean
426000
unkown
page read and write
clean
2EC0000
unkown
page read and write
clean
3230000
unkown
page read and write
clean
446000
unkown
page read and write
clean
31D2000
unkown
page read and write
clean
16A000
unkown
page read and write
clean
2C77000
unkown
page read and write
clean
14A000
unkown
page read and write
clean
2989000
unkown
page readonly
clean
426000
unkown
page read and write
clean
443000
unkown
page read and write
clean
2889000
unkown
page readonly
clean
16A000
unkown
page read and write
clean
2866000
unkown
page readonly
clean
31E1000
unkown
page read and write
clean
F9000
unkown
page read and write
clean
44E000
unkown
page read and write
clean
426000
unkown
page read and write
clean
150000
unkown
page read and write
clean
2C77000
unkown
page read and write
clean
428000
unkown
page read and write
clean
F9000
unkown
page read and write
clean
15C000
unkown
page read and write
clean
380000
unkown
page readonly
clean
7FEF40E1000
unkown image
page execute read
clean
31DC000
unkown
page read and write
clean
F9000
unkown
page read and write
clean
439000
unkown
page read and write
clean
142000
unkown
page read and write
clean
31C9000
unkown
page read and write
clean
2C77000
unkown
page read and write
clean
F9000
unkown
page read and write
clean
142000
unkown
page read and write
clean
7FEF46BA000
unkown image
page readonly
clean
31EF000
unkown
page read and write
clean
2C77000
unkown
page read and write
clean
CE000
unkown
page read and write
clean
14A000
unkown
page read and write
clean
3B7000
heap default
page read and write
clean
2C77000
unkown
page read and write
clean
2C51000
unkown
page read and write
clean
214000
heap private
page read and write
clean
428000
unkown
page read and write
clean
426000
unkown
page read and write
clean
31DC000
unkown
page read and write
clean
3230000
unkown
page read and write
clean
2C77000
unkown
page read and write
clean
440000
unkown
page readonly
clean
20000
unkown
page readonly
clean
3C0000
unkown
page read and write
clean
142000
unkown
page read and write
clean
F8000
unkown
page read and write
clean
443000
unkown
page read and write
clean
150000
unkown
page read and write
clean
28E2000
unkown
page readonly
clean
426000
unkown
page read and write
clean
E0000
unkown
page read and write
clean
AE000
heap default
page read and write
clean
2320000
unkown
page readonly
clean
3230000
unkown
page read and write
clean
F9000
unkown
page read and write
clean
443000
unkown
page read and write
clean
428000
unkown
page read and write
clean
31DC000
unkown
page read and write
clean
428000
unkown
page read and write
clean
3AF000
unkown
page read and write
clean
3B2000
unkown
page read and write
clean
44E000
unkown
page read and write
clean
31EF000
unkown
page read and write
clean
31D2000
unkown
page read and write
clean
CE000
unkown
page read and write
clean
21E0000
heap private
page read and write
clean
1B00000
unkown
page readonly
clean
2C51000
unkown
page read and write
clean
5F0000
unkown
page readonly
clean
426000
unkown
page read and write
clean
27E4000
unkown
page readonly
clean
3B7000
unkown
page read and write
clean
31E1000
unkown
page read and write
clean
28D5000
unkown
page readonly
clean
3AE000
unkown
page read and write
clean
2782000
unkown
page readonly
clean
7FEF40E3000
unkown image
page write copy
clean
DD000
unkown
page read and write
clean
44E000
unkown
page read and write
clean
150000
unkown
page read and write
clean
28D2000
unkown
page readonly
clean
28D5000
unkown
page readonly
clean
426000
unkown
page read and write
clean
D0000
unkown
page read and write
clean
3D0000
heap private
page read and write
clean
443000
unkown
page read and write
clean
31C9000
unkown
page read and write
clean
439000
unkown
page read and write
clean
376000
unkown
page read and write
clean
443000
unkown
page read and write
clean
2C77000
unkown
page read and write
clean
20000
unkown
page readonly
clean
439000
unkown
page read and write
clean
CE000
unkown
page read and write
clean
3AF000
unkown
page read and write
clean
148000
unkown
page read and write
clean
150000
unkown
page read and write
clean
3B7000
unkown
page read and write
clean
D2000
unkown
page read and write
clean
2C77000
unkown
page read and write
clean
148000
unkown
page read and write
clean
31D2000
unkown
page read and write
clean
426000
unkown
page read and write
clean
170000
unkown
page read and write
clean
444000
unkown
page read and write
clean
148000
unkown
page read and write
clean
31FE000
unkown
page read and write
clean
426000
unkown
page read and write
clean
28A5000
unkown
page readonly
clean
44E000
unkown
page read and write
clean
443000
unkown
page read and write
clean
2804000
unkown
page readonly
clean
443000
unkown
page read and write
clean
F9000
unkown
page read and write
clean
44E000
unkown
page read and write
clean
3B2000
unkown
page read and write
clean
44E000
unkown
page read and write
clean
428000
unkown
page read and write
clean
560000
unkown
page readonly
clean
31F6000
unkown
page read and write
clean
2C47000
unkown
page read and write
clean
426000
unkown
page read and write
clean
CF000
unkown
page read and write
clean
31E1000
unkown
page read and write
clean
148000
unkown
page read and write
clean
428000
unkown
page read and write
clean
31FB000
unkown
page read and write
clean
31C9000
unkown
page read and write
clean
14A000
unkown
page read and write
clean
2986000
unkown
page readonly
clean
31DC000
unkown
page read and write
clean
14A000
unkown
page read and write
clean
D8000
unkown
page read and write
clean
2C50000
unkown
page read and write
clean
2C77000
unkown
page read and write
clean
1FE3000
heap private
page read and write
clean
F9000
unkown
page read and write
clean
160000
unkown
page read and write
clean
2C10000
unkown
page readonly
clean
26CF000
unkown
page read and write
clean
443000
unkown
page read and write
clean
16A000
unkown
page read and write
clean
2812000
unkown
page readonly
clean
31D2000
unkown
page read and write
clean
14A000
unkown
page read and write
clean
2882000
unkown
page readonly
clean
D8000
unkown
page read and write
clean
31D2000
unkown
page read and write
clean
2C00000
unkown
page read and write
clean
1EA0000
heap private
page read and write
clean
426000
unkown
page read and write
clean
428000
unkown
page read and write
clean
31E1000
unkown
page read and write
clean
150000
unkown
page read and write
clean
16A000
unkown
page read and write
clean
3230000
unkown
page read and write
clean
22CD000
unkown
page read and write
clean
31F6000
unkown
page read and write
clean
298D000
unkown
page readonly
clean
150000
unkown
page read and write
clean
DD000
unkown
page read and write
clean
2C77000
unkown
page read and write
clean
31E2000
unkown
page read and write
clean
31E2000
unkown
page read and write
clean
150000
unkown
page read and write
clean
16A000
unkown
page read and write
clean
520000
unkown
page readonly
clean
3201000
unkown
page read and write
clean
31E1000
unkown
page read and write
clean
31DC000
unkown
page read and write
clean
31DC000
unkown
page read and write
clean
7FEF46C5000
unkown image
page readonly
clean
44E000
unkown
page read and write
clean
152000
unkown
page read and write
clean
1A6000
unkown
page read and write
clean
14A000
unkown
page read and write
clean
CB000
heap default
page read and write
clean
31C9000
unkown
page read and write
clean
3230000
unkown
page read and write
clean
60000
unkown
page readonly
clean
44E000
unkown
page read and write
clean
31C9000
unkown
page read and write
clean
150000
unkown
page read and write
clean
439000
unkown
page read and write
clean
31C9000
unkown
page read and write
clean
E0000
unkown
page read and write
clean
31FE000
unkown
page read and write
clean
27A2000
unkown
page readonly
clean
148000
unkown
page read and write
clean
44E000
unkown
page read and write
clean
439000
unkown
page read and write
clean
150000
unkown
page read and write
clean
31D2000
unkown
page read and write
clean
5C0000
unkown
page readonly
clean
31C9000
unkown
page read and write
clean
31F6000
unkown
page read and write
clean
31C9000
unkown
page read and write
clean
31D2000
unkown
page read and write
clean
3230000
unkown
page read and write
clean
44E000
unkown
page read and write
clean
428000
unkown
page read and write
clean
11B000
unkown
page read and write
clean
2C50000
unkown
page read and write
clean
3B7000
unkown
page read and write
clean
2C77000
unkown
page read and write
clean
142000
unkown
page read and write
clean
2C4C000
unkown
page read and write
clean
31E2000
unkown
page read and write
clean
31D2000
unkown
page read and write
clean
443000
unkown
page read and write
clean
44E000
unkown
page read and write
clean
3230000
unkown
page read and write
clean
D8000
unkown
page read and write
clean
28E6000
unkown
page readonly
clean
150000
unkown
page read and write
clean
D8000
unkown
page read and write
clean
2780000
heap private
page read and write
clean
443000
unkown
page read and write
clean
2A1B000
unkown
page read and write
clean
2A0000
unkown
page read and write
clean
14A000
unkown
page read and write
clean
16A000
unkown
page read and write
clean
428000
unkown
page read and write
clean
CE000
unkown
page read and write
clean
150000
unkown
page read and write
clean
428000
unkown
page read and write
clean
294000
heap private
page read and write
clean
14A000
unkown
page read and write
clean
428000
unkown
page read and write
clean
3230000
unkown
page read and write
clean
142000
unkown
page read and write
clean
31EF000
unkown
page read and write
clean
142000
unkown
page read and write
clean
2B50000
unkown
page readonly
clean
D8000
unkown
page read and write
clean
F9000
unkown
page read and write
clean
3230000
unkown
page read and write
clean
60000
unkown
page readonly
clean
2B42000
unkown
page read and write
clean
31EF000
unkown
page read and write
clean
28B2000
unkown
page readonly
clean
43A000
unkown
page read and write
clean
142000
unkown
page read and write
clean
2608000
unkown
page readonly
clean
31E1000
unkown
page read and write
clean
31C9000
unkown
page read and write
clean
31DC000
unkown
page read and write
clean
1A6000
unkown
page read and write
clean
2682000
unkown
page readonly
clean
27B2000
unkown
page readonly
clean
F9000
unkown
page read and write
clean
2B32000
unkown
page read and write
clean
D8000
unkown
page read and write
clean
426000
unkown
page read and write
clean
D0000
unkown
page read and write
clean
2E70000
unkown
page readonly
clean
3230000
unkown
page read and write
clean
20B0000
heap private
page read and write
clean
170000
unkown
page read and write
clean
D8000
unkown
page read and write
clean
443000
unkown
page read and write
clean
426000
unkown
page read and write
clean
428000
unkown
page read and write
clean
3B2000
unkown
page read and write
clean
1FD0000
heap private
page read and write
clean
16A000
unkown
page read and write
clean
31DC000
unkown
page read and write
clean
28E9000
unkown
page readonly
clean
21E0000
unkown
page readonly
clean
2784000
unkown
page readonly
clean
3230000
unkown
page read and write
clean
436000
unkown
page read and write
clean
150000
unkown
page read and write
clean
31E1000
unkown
page read and write
clean
31D2000
unkown
page read and write
clean
2A20000
heap private
page read and write
clean
240000
heap default
page read and write
clean
3230000
unkown
page read and write
clean
2582000
unkown
page readonly
clean
2280000
unkown
page readonly
clean
2932000
unkown
page readonly
clean
3B7000
unkown
page read and write
clean
14A000
unkown
page read and write
clean
443000
heap default
page read and write
clean
443000
unkown
page read and write
clean
31DC000
unkown
page read and write
clean
16F000
unkown
page read and write
clean
31EF000
unkown
page read and write
clean
426000
unkown
page read and write
clean
CE000
unkown
page read and write
clean
D8000
unkown
page read and write
clean
32DC000
unkown
page read and write
clean
3230000
unkown
page read and write
clean
2260000
unkown
page readonly
clean
142000
unkown
page read and write
clean
280000
unkown
page readonly
clean
F9000
unkown
page read and write
clean
20DB000
heap private
page read and write
clean
44E000
unkown
page read and write
clean
20A0000
heap private
page read and write
clean
439000
unkown
page read and write
clean
260000
unkown
page read and write
clean
428000
unkown
page read and write
clean
152000
unkown
page read and write
clean
31D2000
unkown
page read and write
clean
443000
unkown
page read and write
clean
426000
unkown
page read and write
clean
D0000
unkown
page read and write
clean
F9000
unkown
page read and write
clean
3AF000
unkown
page read and write
clean
60000
unkown
page readonly
clean
310000
heap private
page read and write
clean
D8000
unkown
page read and write
clean
3B7000
unkown
page read and write
clean
439000
unkown
page read and write
clean
3AF000
unkown
page read and write
clean
426000
unkown
page read and write
clean
238B000
heap private
page read and write
clean
14A000
unkown
page read and write
clean
16A000
unkown
page read and write
clean
148000
unkown
page read and write
clean
28A5000
unkown
page readonly
clean
31DC000
unkown
page read and write
clean
15F000
unkown
page read and write
clean
426000
unkown
page read and write
clean
16A000
unkown
page read and write
clean
634000
heap private
page read and write
clean
31EF000
unkown
page read and write
clean
2BFF000
unkown
page read and write
clean
2A2C000
unkown
page read and write
clean
3230000
unkown
page read and write
clean
31E1000
unkown
page read and write
clean
44E000
unkown
page read and write
clean
148000
unkown
page read and write
clean
3B7000
unkown
page read and write
clean
7FEF4690000
unkown image
page readonly
clean
2B4000
unkown
page execute and read and write
clean
CE000
unkown
page read and write
clean
2C77000
unkown
page read and write
clean
31E1000
unkown
page read and write
clean
44E000
unkown
page read and write
clean
439000
unkown
page read and write
clean
142000
unkown
page read and write
clean
2285000
heap private
page read and write
clean
2762000
unkown
page readonly
clean
439000
unkown
page read and write
clean
25C000
unkown
page read and write
clean
443000
unkown
page read and write
clean
3190000
unkown
page read and write
clean
3B7000
unkown
page read and write
clean
426000
unkown
page read and write
clean
439000
unkown
page read and write
clean
31E1000
unkown
page read and write
clean
3230000
unkown
page read and write
clean
2C77000
unkown
page read and write
clean
428000
unkown
page read and write
clean
31E1000
unkown
page read and write
clean
27BF000
heap private
page read and write
clean
3230000
unkown
page read and write
clean
2B92000
unkown
page readonly
clean
D8000
unkown
page read and write
clean
31E1000
unkown
page read and write
clean
16F000
unkown
page read and write
clean
426000
unkown
page read and write
clean
2055000
heap private
page read and write
clean
2289000
heap private
page read and write
clean
31EF000
unkown
page read and write
clean
1D10000
unkown
page readonly
clean
33CC000
unkown
page read and write
clean
443000
unkown
page read and write
clean
3230000
unkown
page read and write
clean
428000
unkown
page read and write
clean
3B3000
unkown
page read and write
clean
428000
unkown
page read and write
clean
2800000
unkown
page write copy
clean
439000
unkown
page read and write
clean
3B7000
unkown
page read and write
clean
F9000
unkown
page read and write
clean
D6000
unkown
page read and write
clean
D8000
unkown
page read and write
clean
3230000
unkown
page read and write
clean
142000
unkown
page read and write
clean
44E000
unkown
page read and write
clean
1F50000
heap private
page read and write
clean
314000
heap private
page read and write
clean
168000
unkown
page read and write
clean
150000
unkown
page read and write
clean
350000
heap default
page read and write
clean
142000
unkown
page read and write
clean
3B4000
unkown
page execute and read and write
clean
14A000
unkown
page read and write
clean
44E000
unkown
page read and write
clean
426000
unkown
page read and write
clean
439000
heap default
page read and write
clean
44E000
unkown
page read and write
clean
31E2000
unkown
page read and write
clean
3AF000
unkown
page read and write
clean
439000
unkown
page read and write
clean
3230000
unkown
page read and write
clean
BCF000
unkown
page read and write
clean
148000
unkown
page read and write
clean
F9000
unkown
page read and write
clean
3AF000
unkown
page read and write
clean
3B1000
unkown
page read and write
clean
31DC000
unkown
page read and write
clean
CE000
unkown
page read and write
clean
16A000
unkown
page read and write
clean
31DC000
unkown
page read and write
clean
2975000
unkown
page readonly
clean
480000
unkown
page write copy
clean
3B7000
unkown
page read and write
clean
CE000
unkown
page read and write
clean
5E4000
heap private
page read and write
clean
3AF000
unkown
page read and write
clean
2B90000
unkown
page read and write
clean
3AF000
unkown
page read and write
clean
2AD0000
unkown
page readonly
clean
7FEF40E9000
unkown image
page write copy
clean
44E000
unkown
page read and write
clean
3B2000
unkown
page read and write
clean
CE000
unkown
page read and write
clean
426000
unkown
page read and write
clean
142000
unkown
page read and write
clean
3B7000
unkown
page read and write
clean
2C77000
unkown
page read and write
clean
31D2000
unkown
page read and write
clean
148000
unkown
page read and write
clean
21E9000
heap private
page read and write
clean
428000
unkown
page read and write
clean
439000
unkown
page read and write
clean
148000
unkown
page read and write
clean
3B0000
unkown
page execute and read and write
clean
2C77000
unkown
page read and write
clean
14A000
unkown
page read and write
clean
443000
unkown
page read and write
clean
2C47000
unkown
page read and write
clean
443000
unkown
page read and write
clean
439000
unkown
page read and write
clean
14A000
unkown
page read and write
clean
2939000
unkown
page readonly
clean
3230000
unkown
page read and write
clean
D8000
unkown
page read and write
clean
31DC000
unkown
page read and write
clean
3B7000
unkown
page read and write
clean
15B000
unkown
page read and write
clean
1CA7000
unkown
page readonly
clean
150000
unkown
page read and write
clean
2C77000
unkown
page read and write
clean
428000
unkown
page read and write
clean
22D0000
unkown
page readonly
clean
2300000
unkown
page readonly
clean
3B2000
unkown
page read and write
clean
20F0000
unkown
page readonly
clean
3B7000
unkown
page read and write
clean
2825000
unkown
page readonly
clean
142000
unkown
page read and write
clean
3A0000
unkown
page read and write
clean
31D2000
unkown
page read and write
clean
3AF000
unkown
page read and write
clean
31C9000
unkown
page read and write
clean
31C9000
unkown
page read and write
clean
443000
unkown
page read and write
clean
3230000
unkown
page read and write
clean
2C47000
unkown
page read and write
clean
31D2000
unkown
page read and write
clean
38E000
heap default
page read and write
clean
31DC000
unkown
page read and write
clean
443000
unkown
page read and write
clean
148000
unkown
page read and write
clean
16A000
unkown
page read and write
clean
1B60000
unkown
page readonly
clean
2169000
heap private
page read and write
clean
3B7000
unkown
page read and write
clean
148000
unkown
page read and write
clean
443000
unkown
page read and write
clean
7FEF40E0000
unkown image
page readonly
clean
142000
unkown
page read and write
clean
426000
unkown
page read and write
clean
3B7000
unkown
page read and write
clean
426000
unkown
page read and write
clean
3230000
unkown
page read and write
clean
28F6000
unkown
page readonly
clean
2350000
heap private
page read and write
clean
15C000
heap default
page read and write
clean
2C3A000
unkown
page read and write
clean
337000
heap default
page read and write
clean
428000
unkown
page read and write
clean
31E1000
unkown
page read and write
clean
27C4000
unkown
page readonly
clean
D8000
heap default
page read and write
clean
27C5000
unkown
page readonly
clean
21E5000
heap private
page read and write
clean
3201000
unkown
page read and write
clean
5D0000
unkown
page readonly
clean
2855000
unkown
page readonly
clean
F8000
unkown
page read and write
clean
428000
unkown
page read and write
clean
436000
unkown
page read and write
clean
439000
unkown
page read and write
clean
142000
heap default
page read and write
clean
2B30000
unkown
page readonly
clean
31E1000
unkown
page read and write
clean
700000
unkown
page readonly
clean
31EF000
unkown
page read and write
clean
3B2000
unkown
page read and write
clean
630000
heap private
page read and write
clean
152000
heap default
page read and write
clean
428000
unkown
page read and write
clean
14A000
unkown
page read and write
clean
443000
unkown
page read and write
clean
2962000
unkown
page readonly
clean
31DC000
unkown
page read and write
clean
F9000
unkown
page read and write
clean
3AF000
unkown
page read and write
clean
44E000
unkown
page read and write
clean
426000
unkown
page read and write
clean
F9000
unkown
page read and write
clean
20CF000
heap private
page read and write
clean
3AF000
unkown
page read and write
clean
31DC000
unkown
page read and write
clean
152000
unkown
page read and write
clean
3B7000
unkown
page read and write
clean
D8000
unkown
page read and write
clean
31C9000
unkown
page read and write
clean
31DC000
unkown
page read and write
clean
31E1000
unkown
page read and write
clean
2836000
unkown
page readonly
clean
426000
unkown
page read and write
clean
31F6000
unkown
page read and write
clean
31F6000
unkown
page read and write
clean
150000
unkown
page read and write
clean
14A000
unkown
page read and write
clean
150000
unkown
page read and write
clean
2845000
unkown
page readonly
clean
3AF000
unkown
page read and write
clean
439000
unkown
page read and write
clean
3202000
unkown
page read and write
clean
148000
heap default
page read and write
clean
1DB7000
unkown
page readonly
clean
390000
unkown
page read and write
clean
2882000
unkown
page readonly
clean
2C4C000
unkown
page read and write
clean
27F0000
heap private
page read and write
clean
D8000
unkown
page read and write
clean
2764000
unkown
page readonly
clean
14A000
unkown
page read and write
clean
29A2000
unkown
page readonly
clean
3B7000
unkown
page read and write
clean
330000
heap default
page read and write
clean
D8000
unkown
page read and write
clean
14A000
unkown
page read and write
clean
2DE000
heap default
page read and write
clean
16E000
unkown
page read and write
clean
148000
unkown
page read and write
clean
44E000
unkown
page read and write
clean
3AF000
unkown
page read and write
clean
31C9000
unkown
page read and write
clean
167000
heap default
page read and write
clean
2945000
unkown
page readonly
clean
31EF000
unkown
page read and write
clean
31C9000
unkown
page read and write
clean
F9000
unkown
page read and write
clean
2C77000
unkown
page read and write
clean
2C77000
unkown
page read and write
clean
148000
unkown
page read and write
clean
446000
unkown
page read and write
clean
3B7000
unkown
page read and write
clean
3AF000
unkown
page read and write
clean
31D2000
unkown
page read and write
clean
2AB0000
unkown
page readonly
clean
28B6000
unkown
page readonly
clean
428000
unkown
page read and write
clean
2C77000
unkown
page read and write
clean
44E000
unkown
page read and write
clean
2925000
unkown
page readonly
clean
31E1000
unkown
page read and write
clean
26A8000
unkown
page readonly
clean
26A2000
unkown
page readonly
clean
44E000
unkown
page read and write
clean
290000
unkown
page read and write
clean
340000
unkown
page read and write
clean
150000
unkown
page read and write
clean
31D2000
unkown
page read and write
clean
439000
unkown
page read and write
clean
3AF000
unkown
page read and write
clean
20D0000
unkown
page readonly
clean
16A000
unkown
page read and write
clean
142000
unkown
page read and write
clean
2C47000
unkown
page read and write
clean
31D2000
unkown
page read and write
clean
22EF000
unkown
page read and write
clean
2856000
unkown
page readonly
clean
2892000
unkown
page readonly
clean
436000
unkown
page read and write
clean
F9000
heap default
page read and write
clean
31DC000
unkown
page read and write
clean
3B7000
unkown
page read and write
clean
7FEF40E8000
unkown image
page readonly
clean
426000
unkown
page read and write
clean
44E000
heap default
page read and write
clean
2050000
heap private
page read and write
clean
142000
unkown
page read and write
clean
3C0000
unkown
page read and write
clean
2875000
unkown
page readonly
clean
2DF5000
heap private
page read and write
clean
436000
unkown
page read and write
clean
3B2000
unkown
page read and write
clean
142000
unkown
page read and write
clean
44E000
unkown
page read and write
clean
439000
unkown
page read and write
clean
296000
unkown
page read and write
clean
1BD0000
unkown
page readonly
clean
2A0000
heap default
page read and write
clean
2886000
unkown
page readonly
clean
31D2000
unkown
page read and write
clean
14A000
unkown
page read and write
clean
2C77000
unkown
page read and write
clean
3B7000
unkown
page read and write
clean
31D2000
unkown
page read and write
clean
16C000
unkown
page read and write
clean
31F6000
unkown
page read and write
clean
31C9000
unkown
page read and write
clean
426000
unkown
page read and write
clean
2956000
unkown
page readonly
clean
31C9000
unkown
page read and write
clean
3B2000
unkown
page read and write
clean
2C60000
unkown
page readonly
clean
31EF000
unkown
page read and write
clean
31C9000
unkown
page read and write
clean
2D4B000
heap private
page read and write
clean
150000
unkown
page read and write
clean
70000
unkown
page read and write
clean
2C77000
unkown
page read and write
clean
31DC000
unkown
page read and write
clean
3AF000
unkown
page read and write
clean
14A000
unkown
page read and write
clean
CE000
unkown
page read and write
clean
148000
unkown
page read and write
clean
770000
unkown
page readonly
clean
31D2000
unkown
page read and write
clean
276B000
unkown
page read and write
clean
3202000
unkown
page read and write
clean
3B7000
unkown
page read and write
clean
3230000
unkown
page read and write
clean
3B7000
unkown
page read and write
clean
3201000
unkown
page read and write
clean
2C47000
unkown
page read and write
clean
120000
unkown
page readonly
clean
D8000
unkown
page read and write
clean
2C40000
unkown
page read and write
clean
2C77000
unkown
page read and write
clean
B0F000
unkown
page read and write
clean
439000
unkown
page read and write
clean
31EF000
unkown
page read and write
clean
5E0000
heap private
page read and write
clean
2C39000
unkown
page read and write
clean
428000
unkown
page read and write
clean
142000
unkown
page read and write
clean
2C77000
unkown
page read and write
clean
2DB0000
unkown
page readonly
clean
31DC000
unkown
page read and write
clean
33D000
unkown
page read and write
clean
31E1000
unkown
page read and write
clean
2C51000
unkown
page read and write
clean
3230000
unkown
page read and write
clean
F9000
unkown
page read and write
clean
14A000
unkown
page read and write
clean
31DC000
unkown
page read and write
clean
2862000
unkown
page readonly
clean
150000
unkown
page read and write
clean
3AF000
unkown
page read and write
clean
250000
unkown
page read and write
clean
44E000
unkown
page read and write
clean
380000
heap default
page read and write
clean
1AC0000
unkown
page readonly
clean
31E1000
unkown
page read and write
clean
2588000
unkown
page readonly
clean
2932000
unkown
page readonly
clean
170000
unkown
page readonly
clean
443000
unkown
page read and write
clean
3230000
unkown
page read and write
clean
29F5000
unkown
page readonly
clean
340000
unkown
page read and write
clean
3B7000
unkown
page read and write
clean
60000
unkown
page read and write
clean
2789000
heap private
page read and write
clean
3B7000
unkown
page read and write
clean
152000
unkown
page read and write
clean
31D2000
unkown
page read and write
clean
2B10000
unkown
page readonly
clean
44E000
unkown
page read and write
clean
439000
unkown
page read and write
clean
16A000
unkown
page read and write
clean
443000
unkown
page read and write
clean
16A000
unkown
page read and write
clean
2902000
unkown
page readonly
clean
37B000
heap default
page read and write
clean
20A5000
heap private
page read and write
clean
443000
unkown
page read and write
clean
29A9000
unkown
page readonly
clean
2B3B000
unkown
page read and write
clean
3B7000
unkown
page read and write
clean
31EF000
unkown
page read and write
clean
3AF000
unkown
page read and write
clean
2C77000
unkown
page read and write
clean
28ED000
unkown
page readonly
clean
150000
unkown
page read and write
clean
2160000
heap private
page read and write
clean
2090000
heap private
page read and write
clean
3201000
unkown
page read and write
clean
2802000
unkown
page readonly
clean
148000
unkown
page read and write
clean
31C9000
unkown
page read and write
clean
31D2000
unkown
page read and write
clean
247000
heap default
page read and write
clean
2C77000
unkown
page read and write
clean
290000
heap private
page read and write
clean
148000
unkown
page read and write
clean
31E1000
unkown
page read and write
clean
2A02000
unkown
page readonly
clean
142000
unkown
page read and write
clean
14A000
heap default
page read and write
clean
31D2000
unkown
page read and write
clean
428000
unkown
page read and write
clean
31F6000
unkown
page read and write
clean
2926000
unkown
page readonly
clean
2AF2000
unkown
page readonly
clean
31D2000
unkown
page read and write
clean
D8000
unkown
page read and write
clean
208B000
heap private
page read and write
clean
CE000
unkown
page read and write
clean
2B70000
unkown
page readonly
clean
2806000
unkown
page readonly
clean
428000
unkown
page read and write
clean
31E1000
unkown
page read and write
clean
15A000
unkown
page read and write
clean
31EF000
unkown
page read and write
clean
30CB000
unkown
page read and write
clean
6F0000
unkown
page readonly
clean
2B4C000
unkown
page read and write
clean
2C77000
unkown
page read and write
clean
44E000
unkown
page read and write
clean
3230000
unkown
page read and write
clean
7FEF4691000
unkown image
page execute read
clean
436000
unkown
page read and write
clean
446000
unkown
page read and write
clean
443000
unkown
page read and write
clean
2962000
unkown
page readonly
clean
3230000
unkown
page read and write
clean
44E000
unkown
page read and write
clean
3B7000
unkown
page read and write
clean
31DC000
unkown
page read and write
clean
3201000
unkown
page read and write
clean
439000
unkown
page read and write
clean
F9000
unkown
page read and write
clean
2DF0000
heap private
page read and write
clean
44E000
unkown
page read and write
clean
2864000
unkown
page readonly
clean
31DC000
unkown
page read and write
clean
3AF000
unkown
page read and write
clean
2C77000
unkown
page read and write
clean
44E000
unkown
page read and write
clean
27E2000
unkown
page readonly
clean
D8000
unkown
page read and write
clean
27E2000
unkown
page readonly
clean
3202000
unkown
page read and write
clean
27F5000
unkown
page readonly
clean
31DC000
unkown
page read and write
clean
150000
unkown
page read and write
clean
31C9000
unkown
page read and write
clean
142000
unkown
page read and write
clean
2A7000
heap default
page read and write
clean
2BE0000
heap private
page read and write
clean
2C77000
unkown
page read and write
clean
36D000
heap default
page read and write
clean
31C9000
unkown
page read and write
clean
3AF000
unkown
page read and write
clean
2C4B000
unkown
page read and write
clean
3B2000
heap default
page read and write
clean
2C47000
unkown
page read and write
clean
3B3000
unkown
page read and write
clean
44E000
unkown
page read and write
clean
3BE000
heap default
page read and write
clean
2955000
unkown
page readonly
clean
426000
unkown
page read and write
clean
340000
unkown
page read and write
clean
F9000
unkown
page read and write
clean
2C77000
unkown
page read and write
clean
1CE7000
unkown
page readonly
clean
31EF000
unkown
page read and write
clean
3230000
unkown
page read and write
clean
3B7000
unkown
page read and write
clean
3AF000
unkown
page read and write
clean
2602000
unkown
page readonly
clean
1C6000
unkown
page read and write
clean
24B000
unkown
page read and write
clean
31D2000
unkown
page read and write
clean
3E0000
unkown
page readonly
clean
3AF000
unkown
page read and write
clean
31D2000
unkown
page read and write
clean
2C77000
unkown
page read and write
clean
31D2000
unkown
page read and write
clean
2909000
unkown
page readonly
clean
3AF000
unkown
page read and write
clean
2905000
unkown
page readonly
clean
3AF000
unkown
page read and write
clean
2C77000
unkown
page read and write
clean
3AF000
unkown
page read and write
clean
31D2000
unkown
page read and write
clean
2910000
heap private
page read and write
clean
428000
unkown
page read and write
clean
28C2000
unkown
page readonly
clean
7FEF46C0000
unkown image
page write copy
clean
31E1000
unkown
page read and write
clean
3B7000
unkown
page read and write
clean
77000
heap default
page read and write
clean
148000
unkown
page read and write
clean
3B7000
unkown
page read and write
clean
31C9000
unkown
page read and write
clean
27C2000
unkown
page readonly
clean
31E1000
unkown
page read and write
clean
439000
unkown
page read and write
clean
426000
unkown
page read and write
clean
428000
unkown
page read and write
clean
443000
unkown
page read and write
clean
148000
unkown
page read and write
clean
29D2000
unkown
page readonly
clean
428000
unkown
page read and write
clean
426000
unkown
page read and write
clean
44E000
unkown
page read and write
clean
31DC000
unkown
page read and write
clean
59E000
unkown
page read and write
clean
190000
unkown
page read and write
clean
443000
unkown
page read and write
clean
31C9000
unkown
page read and write
clean
357000
heap default
page read and write
clean
44E000
unkown
page read and write
clean
31DC000
unkown
page read and write
clean
CE000
unkown
page read and write
clean
3AF000
unkown
page read and write
clean
3B7000
unkown
page read and write
clean
31D2000
unkown
page read and write
clean
3B7000
unkown
page read and write
clean
2D15000
heap private
page read and write
clean
31E1000
unkown
page read and write
clean
148000
unkown
page read and write
clean
14A000
unkown
page read and write
clean
1EF7000
unkown
page readonly
clean
14A000
unkown
page read and write
clean
443000
unkown
page read and write
clean
3B2000
unkown
page read and write
clean
148000
unkown
page read and write
clean
3230000
unkown
page read and write
clean
443000
unkown
page read and write
clean
428000
unkown
page read and write
clean
150000
unkown
page read and write
clean
2969000
unkown
page readonly
clean
60000
unkown
page readonly
clean
148000
unkown
page read and write
clean
3230000
unkown
page read and write
clean
3B7000
unkown
page read and write
clean
2C77000
unkown
page read and write
clean
28A2000
unkown
page readonly
clean
210000
heap private
page read and write
clean
2C01000
unkown
page read and write
clean
28E5000
unkown
page readonly
clean
16D000
unkown
page read and write
clean
2869000
unkown
page readonly
clean
2AF0000
unkown
page readonly
clean
2842000
unkown
page readonly
clean
44E000
unkown
page read and write
clean
2915000
unkown
page readonly
clean
2C30000
unkown
page read and write
clean
3B2000
unkown
page read and write
clean
26A0000
unkown
page write copy
clean
443000
unkown
page read and write
clean
16A000
unkown
page read and write
clean
31E2000
unkown
page read and write
clean
2C47000
unkown
page read and write
clean
3AF000
unkown
page read and write
clean
3B2000
unkown
page read and write
clean
31F6000
unkown
page read and write
clean
443000
unkown
page read and write
clean
150000
unkown
page read and write
clean
31D2000
unkown
page read and write
clean
29D9000
unkown
page readonly
clean
31DC000
unkown
page read and write
clean
142000
unkown
page read and write
clean
2C51000
unkown
page read and write
clean
2C51000
unkown
page read and write
clean
F9000
unkown
page read and write
clean
3230000
unkown
page read and write
clean
3B7000
unkown
page read and write
clean
1F20000
unkown
page write copy
clean
428000
unkown
page read and write
clean
428000
unkown
page read and write
clean
7FEF40E0000
unkown image
page readonly
clean
2355000
heap private
page read and write
clean
426000
unkown
page read and write
clean
2C77000
unkown
page read and write
clean
2C77000
unkown
page read and write
clean
31DC000
unkown
page read and write
clean
2E2B000
heap private
page read and write
clean
3AB000
heap default
page read and write
clean
3B7000
unkown
page read and write
clean
2A09000
unkown
page readonly
clean
16A000
unkown
page read and write
clean
2C77000
unkown
page read and write
clean
2165000
heap private
page read and write
clean
44E000
unkown
page read and write
clean
29C5000
unkown
page readonly
clean
16A000
unkown
page read and write
clean
3B7000
unkown
page read and write
clean
150000
heap default
page read and write
clean
1D47000
unkown
page readonly
clean
360000
unkown
page read and write
clean
150000
unkown
page read and write
clean
106000
unkown
page read and write
clean
44E000
unkown
page read and write
clean
148000
unkown
page read and write
clean
286D000
unkown
page readonly
clean
436000
unkown
page read and write
clean
27D6000
unkown
page readonly
clean
3AF000
unkown
page read and write
clean
2832000
unkown
page readonly
clean
3B2000
unkown
page read and write
clean
428000
unkown
page read and write
clean
20000
unkown
page readonly
clean
2BF0000
unkown
page readonly
clean
2862000
unkown
page readonly
clean
31DC000
unkown
page read and write
clean
150000
unkown
page read and write
clean
16F000
unkown
page read and write
clean
280000
heap private
page read and write
clean
148000
unkown
page read and write
clean
44E000
unkown
page read and write
clean
142000
unkown
page read and write
clean
142000
unkown
page read and write
clean
148000
unkown
page read and write
clean
31D2000
unkown
page read and write
clean
44E000
unkown
page read and write
clean
31EF000
unkown
page read and write
clean
7D0000
unkown
page readonly
clean
14A000
unkown
page read and write
clean
3B7000
unkown
page read and write
clean
3202000
unkown
page read and write
clean
3230000
unkown
page read and write
clean
16C000
unkown
page read and write
clean
70000
heap default
page read and write
clean
3AF000
unkown
page read and write
clean
2D30000
heap private
page read and write
clean
2702000
unkown
page readonly
clean
443000
unkown
page read and write
clean
7FEF4690000
unkown image
page readonly
clean
439000
unkown
page read and write
clean
31E1000
unkown
page read and write
clean
3AF000
unkown
page read and write
clean
439000
unkown
page read and write
clean
16A000
unkown
page read and write
clean
3AF000
unkown
page read and write
clean
23D0000
unkown
page readonly
clean
1FB0000
unkown
page readonly
clean
443000
unkown
page read and write
clean
31D2000
unkown
page read and write
clean
2130000
unkown
page readonly
clean
1F40000
unkown
page write copy
clean
443000
unkown
page read and write
clean
20000
unkown
page readonly
clean
2C77000
unkown
page read and write
clean
31C9000
unkown
page read and write
clean
2884000
unkown
page readonly
clean
2744000
unkown
page readonly
clean
426000
heap default
page read and write
clean
3D4000
heap private
page read and write
clean
439000
unkown
page read and write
clean
7FEF40E2000
unkown image
page readonly
clean
31D2000
unkown
page read and write
clean
318E000
unkown
page read and write
clean
60000
unkown
page read and write
clean
43B000
unkown
page read and write
clean
387000
heap default
page read and write
clean
2D90000
unkown
page readonly
clean
16A000
unkown
page read and write
clean
439000
unkown
page read and write
clean
426000
unkown
page read and write
clean
15F000
unkown
page read and write
clean
14A000
unkown
page read and write
clean
428000
unkown
page read and write
clean
2160000
heap private
page read and write
clean
3B7000
unkown
page read and write
clean
2BF0000
unkown
page readonly
clean
3AF000
unkown
page read and write
clean
3202000
unkown
page read and write
clean
2C77000
unkown
page read and write
clean
2D10000
heap private
page read and write
clean
428000
unkown
page read and write
clean
D8000
unkown
page read and write
clean
3230000
unkown
page read and write
clean
3A0000
unkown
page readonly
clean
3AF000
heap default
page read and write
clean
3AF000
unkown
page read and write
clean
439000
unkown
page read and write
clean
3B2000
unkown
page read and write
clean
148000
unkown
page read and write
clean
260000
unkown
page read and write
clean
428000
unkown
page read and write
clean
428000
unkown
page read and write
clean
D8000
unkown
page read and write
clean
31E1000
unkown
page read and write
clean
439000
unkown
page read and write
clean
14A000
unkown
page read and write
clean
31E2000
unkown
page read and write
clean
3230000
unkown
page read and write
clean
2742000
unkown
page readonly
clean
439000
unkown
page read and write
clean
428000
heap default
page read and write
clean
443000
unkown
page read and write
clean
3201000
unkown
page read and write
clean
20000
unkown
page readonly
clean
443000
unkown
page read and write
clean
3230000
unkown
page read and write
clean
There are 1109 hidden memdumps, click here to show them.