IOCReport

loading gif

Files

File Path
Type
Category
Malicious
Documents_460000622_1464906353.xls
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Last Saved By: Windows User, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 01:00:00 2006, Last Saved Time/Date: Wed Apr 7 13:38:33 2021, Security: 0
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\ohior[1].dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
downloaded
malicious
C:\Users\user\ndgfht.frg
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Microsoft Cabinet archive data, 58596 bytes, 1 file
dropped
clean
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
data
dropped
clean
C:\Users\user\AppData\Local\Temp\B3EE0000
data
dropped
clean
C:\Users\user\AppData\Local\Temp\CabD146.tmp
Microsoft Cabinet archive data, 58596 bytes, 1 file
dropped
clean
C:\Users\user\AppData\Local\Temp\TarD147.tmp
data
modified
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Tue Oct 17 10:04:00 2017, mtime=Thu Apr 8 00:46:43 2021, atime=Thu Apr 8 00:46:43 2021, length=8192, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Documents_460000622_1464906353.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Aug 26 14:08:16 2020, mtime=Thu Apr 8 00:46:43 2021, atime=Thu Apr 8 00:46:43 2021, length=115712, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\4MFCXH41.txt
ASCII text
downloaded
clean
C:\Users\user\Desktop\54EE0000
Applesoft BASIC program data, first line number 16
dropped
clean
There are 3 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\rundll32.exe
rundll32 ..\ndgfht.frg,PluginInit
malicious
C:\Windows\SysWOW64\rundll32.exe
rundll32 ..\ndgfht.frg,PluginInit
malicious
C:\Windows\SysWOW64\cmd.exe
C:\Windows\System32\cmd.exe
clean

URLs

Name
IP
Malicious
http://fedir.comsign.co.il/crl/ComSignSecuredCA.crl0
unknown
clean
http://www.a-cert.at0E
unknown
clean
http://www.certplus.com/CRL/class3.crl0
unknown
clean
http://www.e-me.lv/repository0
unknown
clean
http://www.acabogacia.org/doc0
unknown
clean
http://crl.chambersign.org/chambersroot.crl0
unknown
clean
http://www.digsigtrust.com/DST_TRUST_CPS_v990701.html0
unknown
clean
http://acraiz.icpbrasil.gov.br/LCRacraiz.crl0
unknown
clean
http://www.certifikat.dk/repository0
unknown
clean
http://www.chambersign.org1
unknown
clean
http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl0
unknown
clean
http://www.diginotar.nl/cps/pkioverheid0
unknown
clean
http://www.pkioverheid.nl/policies/root-policy0
unknown
clean
http://repository.swisssign.com/0
unknown
clean
http://crl.ssc.lt/root-c/cacrl.crl0
unknown
clean
https://www.certification.tn/cgi-bin/pub/crl/cacrl.crl0
unknown
clean
http://www.trustcenter.de/crl/v2/tc_class_3_ca_II.crl
unknown
clean
http://ca.disig.sk/ca/crl/ca_disig.crl0
unknown
clean
http://www.certplus.com/CRL/class3P.crl0
unknown
clean
http://repository.infonotary.com/cps/qcps.html0$
unknown
clean
http://www.post.trust.ie/reposit/cps.html0
unknown
clean
http://www.certplus.com/CRL/class2.crl0
unknown
clean
http://www.disig.sk/ca/crl/ca_disig.crl0
unknown
clean
http://ocsp.infonotary.com/responder.cgi0V
unknown
clean
http://www.sk.ee/cps/0
unknown
clean
http://www.certicamara.com0
unknown
clean
http://www.globaltrust.info0=
unknown
clean
https://www.certification.tn/cgi-bin/pub/crl/cacrl.crl0E
unknown
clean
http://www.ssc.lt/cps03
unknown
clean
http://www.windows.com/pctv.
unknown
clean
http://acraiz.icpbrasil.gov.br/DPCacraiz.pdf0=
unknown
clean
http://ocsp.pki.gva.es0
unknown
clean
http://crl.oces.certifikat.dk/oces.crl0
unknown
clean
http://crl.ssc.lt/root-b/cacrl.crl0
unknown
clean
http://www.certicamara.com/dpc/0Z
unknown
clean
http://crl.pki.wellsfargo.com/wsprca.crl0
unknown
clean
http://www.dnie.es/dpc0
unknown
clean
http://www.rootca.or.kr/rca/cps.html0
unknown
clean
http://www.trustcenter.de/guidelines0
unknown
clean
http://pki-root.ecertpki.cl/CertEnroll/E-CERT%20ROOT%20CA.crl0
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.globaltrust.info0
unknown
clean
http://certificates.starfieldtech.com/repository/1604
unknown
clean
http://www.certplus.com/CRL/class3TS.crl0
unknown
clean
http://www.entrust.net/CRL/Client1.crl0
unknown
clean
http://www.entrust.net/CRL/net1.crl0
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
https://www.catcert.net/verarrel
unknown
clean
http://www.disig.sk/ca0f
unknown
clean
http://www.e-szigno.hu/RootCA.crl
unknown
clean
http://www.signatur.rtr.at/current.crl0
unknown
clean
http://www.sk.ee/juur/crl/0
unknown
clean
http://crl.chambersign.org/chambersignroot.crl0
unknown
clean
http://crl.xrampsecurity.com/XGCA.crl0
unknown
clean
http://www.quovadis.bm0
unknown
clean
http://crl.ssc.lt/root-a/cacrl.crl0
unknown
clean
http://www.trustdst.com/certificates/policy/ACES-index.html0
unknown
clean
http://www.firmaprofesional.com0
unknown
clean
https://www.netlock.net/docs
unknown
clean
http://www.trustcenter.de/crl/v2/tc_class_2_ca_II.crl
unknown
clean
https://52.12.4.186/h
unknown
clean
http://crl.entrust.net/2048ca.crl0
unknown
clean
http://www.pki.admin.ch/policy/CPS_2_16_756_1_17_3_21_1.pdf0
unknown
clean
http://cps.chambersign.org/cps/publicnotaryroot.html0
unknown
clean
http://www.e-trust.be/CPS/QNcerts
unknown
clean
http://www.certicamara.com/certicamaraca.crl0
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://crl.netsolssl.com/NetworkSolutionsCertificateAuthority.crl0
unknown
clean
http://fedir.comsign.co.il/crl/ComSignCA.crl0
unknown
clean
http://www.certificadodigital.com.br/repositorio/serasaca/crl/SerasaCAI.crl0
unknown
clean
https://52.12.4.186/news/update6
unknown
clean
http://ocsp.entrust.net03
unknown
clean
http://cps.chambersign.org/cps/chambersroot.html0
unknown
clean
http://www.acabogacia.org0
unknown
clean
https://ca.sia.it/seccli/repository/CPS0
unknown
clean
http://crl.securetrust.com/SGCA.crl0
unknown
clean
http://fedir.comsign.co.il/cacert/ComSignAdvancedSecurityCA.crt0
unknown
clean
http://crl.securetrust.com/STCA.crl0
unknown
clean
http://www.certificadodigital.com.br/repositorio/serasaca/crl/SerasaCAIII.crl0
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://www.certicamara.com/certicamaraca.crl0;
unknown
clean
http://www.e-szigno.hu/RootCA.crt0
unknown
clean
http://www.quovadisglobal.com/cps0
unknown
clean
http://investor.msn.com/
unknown
clean
https://52.12.4.186/news/updateA
unknown
clean
http://www.valicert.com/1
unknown
clean
https://52.12.4.186/news/update
unknown
clean
http://www.e-szigno.hu/SZSZ/0
unknown
clean
http://www.%s.comPA
unknown
clean
http://www.certificadodigital.com.br/repositorio/serasaca/crl/SerasaCAII.crl0
unknown
clean
https://52.12.4.186/news/updateF
unknown
clean
https://ocsp.quovadisoffshore.com0
unknown
clean
http://ocsp.entrust.net0D
unknown
clean
http://cps.chambersign.org/cps/chambersignroot.html0
unknown
clean
http://ca.sia.it/secsrv/repository/CRL.der0J
unknown
clean
http://investor.msn.com
unknown
clean
http://crl.entrust.net/server1.crl0
unknown
clean
http://www.ancert.com/cps0
unknown
clean
http://ca.sia.it/seccli/repository/CRL.der0J
unknown
clean
http://www.registradores.org/scr/normativa/cp_f2.htm0
unknown
clean
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
whiskyexpanse.com
104.21.3.47
clean

IPs

IP
Domain
Country
Malicious
52.12.4.186
unknown
United States
malicious
104.21.3.47
whiskyexpanse.com
United States
clean

Registry

Path
Value
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
hs8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
MTTT
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ReviewToken
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EDB52
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
FontCachePath
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
VBAFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DefaultSheetR2L
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
UseSystemSeparators
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ThousandsSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DecimalSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EE1C7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EE2D0
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EE36C
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EE428
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EE4B4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} {000214E6-0000-0000-C000-000000000046} 0xFFFF
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
a8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\system32\qagentrt.dll,-10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\System32\fveui.dll,-843
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\System32\fveui.dll,-844
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\System32\wuaueng.dll,-400
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
LastPurgeTime
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
FBE12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
FBF4A
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EXCELFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SavedLegacySettings
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Windows\SysWOW64\rundll32.exe
SavedLegacySettings
clean
There are 109 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
2440000
unkown
page read and write
clean
335000
unkown
page read and write
clean
104000
heap private
page read and write
clean
1C30000
unkown
page readonly
clean
374000
heap default
page read and write
clean
BE7000
unkown
page readonly
clean
6E85A000
unkown image
page read and write
clean
20000
unkown
page readonly
clean
920000
heap private
page read and write
clean
7F0000
heap private
page read and write
clean
1BC000
unkown
page read and write
clean
1C5000
unkown
page read and write
clean
23EE000
unkown
page read and write
clean
2EC000
unkown
page read and write
clean
1A8000
unkown
page read and write
clean
7B0000
heap private
page read and write
clean
E30000
heap private
page read and write
clean
1B9000
unkown
page read and write
clean
2440000
unkown
page read and write
clean
32D000
heap default
page read and write
clean
6E869000
unkown image
page readonly
clean
258F000
unkown
page read and write
clean
740000
unkown
page execute and read and write
clean
700000
heap private
page read and write
clean
6E856000
unkown image
page execute and read and write
clean
1B2000
unkown
page read and write
clean
2EB000
heap default
page read and write
clean
34E000
heap default
page read and write
clean
2DA000
unkown
page read and write
clean
9F7000
heap private
page read and write
clean
2440000
unkown
page read and write
clean
29FE000
unkown
page read and write
clean
930000
unkown
page readonly
clean
2537000
unkown
page read and write
clean
6E791000
unkown image
page execute read
clean
8B0000
heap private
page read and write
clean
3B0000
unkown
page readonly
clean
6E770000
unkown image
page readonly
clean
2630000
unkown
page read and write
clean
6E869000
unkown image
page readonly
clean
6E84A000
unkown image
page write copy
clean
251A000
unkown
page read and write
clean
1B2000
unkown
page read and write
clean
26C0000
unkown
page readonly
clean
1BF000
unkown
page read and write
clean
90C000
unkown
page read and write
clean
1E17000
unkown
page readonly
clean
120000
unkown
page readonly
clean
6D0000
unkown
page read and write
clean
B17000
unkown
page readonly
clean
1C1000
unkown
page read and write
clean
2430000
unkown
page read and write
clean
6E770000
unkown image
page readonly
clean
1AF000
unkown
page read and write
clean
2440000
unkown
page read and write
clean
2440000
unkown
page read and write
clean
DD000
unkown
page read and write
clean
1460000
heap private
page read and write
clean
6E84A000
unkown image
page write copy
clean
812000
heap private
page read and write
clean
B0000
heap default
page read and write
clean
253F000
unkown
page read and write
clean
21B000
unkown
page read and write
clean
230000
unkown
page execute and read and write
clean
530000
unkown
page readonly
clean
2430000
unkown
page read and write
clean
2250000
unkown
page read and write
clean
1AC000
unkown
page read and write
clean
5D0000
unkown
page readonly
clean
2430000
unkown
page read and write
clean
254B000
unkown
page read and write
clean
8C0000
unkown
page readonly
clean
260B000
unkown
page read and write
clean
6E849000
unkown image
page read and write
clean
2380000
heap private
page read and write
clean
2416000
heap private
page read and write
clean
130000
unkown
page readonly
clean
1B0000
unkown
page read and write
clean
226E000
unkown
page read and write
clean
6E771000
unkown image
page execute read
clean
17D000
heap default
page read and write
clean
2530000
unkown
page read and write
clean
160000
unkown
page execute and read and write
clean
277000
heap default
page read and write
clean
110000
unkown
page read and write
clean
2B2E000
stack
page read and write
clean
2440000
unkown
page read and write
clean
2B90000
heap private
page read and write
clean
6E855000
unkown image
page read and write
clean
450000
unkown
page readonly
clean
22E000
stack
page read and write
clean
120000
unkown
page read and write
clean
7F4000
heap private
page read and write
clean
27D000
heap default
page read and write
clean
2510000
unkown
page read and write
clean
21F0000
heap private
page read and write
clean
38D000
heap default
page read and write
clean
2EB000
unkown
page read and write
clean
480000
unkown
page readonly
clean
228D000
unkown
page read and write
clean
2293000
unkown
page read and write
clean
A3F000
unkown
page read and write
clean
6E78C000
unkown image
page read and write
clean
E0000
unkown
page read and write
clean
130000
unkown
page readonly
clean
29EE000
unkown
page read and write
clean
140000
heap default
page read and write
clean
690000
unkown
page readonly
clean
140000
unkown
page readonly
clean
2350000
unkown
page read and write
clean
280000
heap private
page read and write
clean
1AF000
unkown
page read and write
clean
A00000
unkown
page readonly
clean
2430000
unkown
page read and write
clean
23F8000
heap private
page read and write
clean
23AE000
stack
page read and write
clean
2531000
unkown
page read and write
clean
2400000
heap private
page read and write
clean
B20000
unkown
page readonly
clean
2DEE000
stack
page read and write
clean
2430000
unkown
page read and write
clean
446000
unkown
page read and write
clean
2530000
unkown
page read and write
clean
100000
unkown
page readonly
clean
2440000
unkown
page read and write
clean
927000
heap private
page read and write
clean
1A6000
unkown
page read and write
clean
2440000
unkown
page read and write
clean
2530000
unkown
page read and write
clean
20000
unkown
page readonly
clean
60000
unkown
page readonly
clean
2C0E000
unkown
page read and write
clean
7F0000
heap private
page read and write
clean
249F000
stack
page read and write
clean
32F000
unkown
page read and write
clean
226D000
unkown
page read and write
clean
6E855000
unkown image
page read and write
clean
2AAE000
unkown
page read and write
clean
17B000
unkown
page read and write
clean
1B3000
unkown
page read and write
clean
2F00000
heap private
page read and write
clean
1C1000
unkown
page read and write
clean
240000
unkown
page readonly
clean
335000
unkown
page read and write
clean
33C0000
unkown
page readonly
clean
100000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
6E78E000
unkown image
page readonly
clean
8CE000
unkown
page read and write
clean
D0000
unkown
page read and write
clean
1B2000
unkown
page read and write
clean
100000
heap private
page read and write
clean
1AE000
unkown
page read and write
clean
310000
heap default
page read and write
clean
6E770000
unkown image
page readonly
clean
410000
unkown
page read and write
clean
2AED000
stack
page read and write
clean
2F10000
unkown
page readonly
clean
240000
heap default
page read and write
clean
247000
heap default
page read and write
clean
280000
heap default
page read and write
clean
2DA000
unkown
page read and write
clean
3300000
unkown
page write copy
clean
872000
heap private
page read and write
clean
6E815000
unkown image
page readonly
clean
6F0000
unkown
page readonly
clean
32D000
unkown
page read and write
clean
850000
heap private
page read and write
clean
2520000
unkown
page read and write
clean
6E815000
unkown image
page readonly
clean
264000
heap default
page read and write
clean
1B5000
unkown
page read and write
clean
357000
heap default
page read and write
clean
32F000
unkown
page read and write
clean
2D8000
unkown
page read and write
clean
2501000
heap private
page read and write
clean
25FC000
unkown
page read and write
clean
6E78E000
unkown image
page readonly
clean
1A2000
heap default
page read and write
clean
2250000
unkown
page read and write
clean
36C0000
unkown
page read and write
clean
510000
unkown
page readonly
clean
6E785000
unkown image
page readonly
clean
387000
heap default
page read and write
clean
2C39000
unkown
page read and write
clean
2450000
unkown
page read and write
clean
D10000
unkown
page readonly
clean
2B0000
unkown
page read and write
clean
26BD000
stack
page read and write
clean
2581000
unkown
page read and write
clean
350000
heap default
page read and write
clean
2620000
heap private
page read and write
clean
317000
heap default
page read and write
clean
2440000
unkown
page read and write
clean
180000
unkown
page execute and read and write
clean
2430000
unkown
page read and write
clean
854000
heap private
page read and write
clean
1C8000
unkown
page read and write
clean
147000
heap default
page read and write
clean
90000
unkown
page readonly
clean
47A000
unkown
page read and write
clean
6E856000
unkown image
page execute and read and write
clean
2C70000
heap private
page read and write
clean
257A000
unkown
page read and write
clean
227D000
unkown
page read and write
clean
6E791000
unkown image
page execute read
clean
B1E000
unkown
page read and write
clean
23F0000
heap private
page read and write
clean
331000
unkown
page read and write
clean
1B2000
stack
page read and write
clean
1D0000
heap private
page read and write
clean
2540000
unkown
page read and write
clean
2540000
unkown
page read and write
clean
190000
unkown
page execute and read and write
clean
150000
unkown
page execute and read and write
clean
7EFDF000
unkown
page read and write
clean
6E770000
unkown image
page readonly
clean
339000
unkown
page read and write
clean
36C1000
unkown
page read and write
clean
36C1000
unkown
page read and write
clean
2C29000
unkown
page read and write
clean
1BB000
stack
page read and write
clean
186000
heap default
page read and write
clean
9F0000
heap private
page read and write
clean
251D000
unkown
page read and write
clean
6E85A000
unkown image
page read and write
clean
1AC000
unkown
page read and write
clean
250A000
unkown
page read and write
clean
6E771000
unkown image
page execute read
clean
1B1000
unkown
page read and write
clean
24F0000
heap private
page read and write
clean
CA0000
unkown
page readonly
clean
25A4000
unkown
page read and write
clean
6E78C000
unkown image
page read and write
clean
2D2C000
unkown
page read and write
clean
2BE000
heap default
page read and write
clean
19F000
unkown
page read and write
clean
1A5000
unkown
page read and write
clean
2F0E000
unkown
page read and write
clean
6E785000
unkown image
page readonly
clean
1AC000
unkown
page read and write
clean
78D000
stack
page read and write
clean
1C9000
unkown
page read and write
clean
2E6000
unkown
page read and write
clean
250D000
unkown
page read and write
clean
29EE000
unkown
page read and write
clean
1C6000
unkown
page read and write
clean
E40000
unkown
page readonly
clean
1AA000
unkown
page read and write
clean
F0000
unkown
page readonly
clean
1AD000
unkown
page read and write
clean
2520000
unkown
page read and write
clean
90000
unkown
page read and write
clean
6D0000
unkown
page read and write
clean
6E849000
unkown image
page read and write
clean
2F1E000
unkown
page read and write
clean
284000
heap private
page read and write
clean
20000
unkown
page readonly
clean
340000
unkown
page readonly
clean
There are 249 hidden memdumps, click here to show them.