Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
Files Specification.xlsx
|
CDFV2 Encrypted
|
initial sample
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\loki[1].exe
|
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
|
downloaded
|
||
C:\Users\user\AppData\Local\Temp\tmp4C3D.tmp
|
XML 1.0 document, ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Roaming\EA860E7A-A87F-4A88-92EF-38F744458171\run.dat
|
Non-ISO extended-ASCII text, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Roaming\tHyARuOEdFlN.exe
|
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\Public\vbc.exe
|
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Program Files (x86)\SMTP Service\smtpsvc.exe
|
PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\115815B4.jpeg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 220x220, segment length 16, baseline, precision 8, 138x95,
frames 3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\18B2D225.png
|
PNG image data, 1686 x 725, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\2302D74A.emf
|
Windows Enhanced Metafile (EMF) image data version 0x10000
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\36DE3ABF.png
|
PNG image data, 712 x 712, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\3B5FB44E.png
|
PNG image data, 712 x 712, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\66C69E2.png
|
PNG image data, 1268 x 540, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\87748436.jpeg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 220x220, segment length 16, baseline, precision 8, 132x92,
frames 3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\8E7BF4C9.png
|
PNG image data, 145 x 220, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\A23758C.png
|
PNG image data, 1686 x 725, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\AB288440.png
|
PNG image data, 145 x 220, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\C0003741.jpeg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 220x220, segment length 16, baseline, precision 8, 132x92,
frames 3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\C1513BF7.jpeg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 220x220, segment length 16, baseline, precision 8, 138x95,
frames 3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\DCC36C7B.jpeg
|
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 333x151, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\E0881DE8.jpeg
|
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 333x151, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\EF266AC3.png
|
PNG image data, 1268 x 540, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Roaming\EA860E7A-A87F-4A88-92EF-38F744458171\Logs\user\KB_6319896.dat
|
data
|
dropped
|
||
C:\Users\user\AppData\Roaming\EA860E7A-A87F-4A88-92EF-38F744458171\catalog.dat
|
data
|
dropped
|
||
C:\Users\user\Desktop\~$Files Specification.xlsx
|
data
|
dropped
|
There are 15 hidden files, click here to show them.
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
|
'C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE' -Embedding
|
||
C:\Users\Public\vbc.exe
|
'C:\Users\Public\vbc.exe'
|
||
C:\Windows\SysWOW64\schtasks.exe
|
'C:\Windows\System32\schtasks.exe' /Create /TN 'Updates\tHyARuOEdFlN' /XML 'C:\Users\user\AppData\Local\Temp\tmp4C3D.tmp'
|
||
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe
|
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
|
||
C:\Program Files (x86)\SMTP Service\smtpsvc.exe
|
'C:\Program Files (x86)\SMTP Service\smtpsvc.exe'
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://covid19vaccinations.hopto.org/loki.exe
|
34.220.10.254
|
||
nassiru1155.ddns.net
|
|||
79.134.225.30
|
|||
http://www.%s.comPA
|
unknown
|
||
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
|
unknown
|
||
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
|
unknown
|
||
https://stackpath.bootstrapcdn.com/bootstrap/4.5.0/css/bootstrap.min.css
|
unknown
|
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
covid19vaccinations.hopto.org
|
34.220.10.254
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
34.220.10.254
|
covid19vaccinations.hopto.org
|
United States
|
||
79.134.225.30
|
unknown
|
Switzerland
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
hd7
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
MTTT
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
ReviewToken
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
EECB0
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
FontCachePath
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
VBAFiles
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
DefaultSheetR2L
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
UseSystemSeparators
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
ThousandsSeparator
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
DecimalSeparator
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
fq7
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
F3B0D
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
F6B51
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Max Display
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 1
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Max Display
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 1
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 2
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 3
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 4
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 5
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 6
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 7
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 8
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 9
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 10
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 11
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 12
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 13
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 14
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 15
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 16
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 17
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 18
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 19
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 20
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 21
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
LastPurgeTime
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
1033
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
1033
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
EXCELFiles
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
ProductFiles
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_3082
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_3082
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_1036
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_1036
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_1033
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_1033
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_3082
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_3082
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_1036
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_1036
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_1033
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_1033
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
ProductFiles
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
ProductFiles
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
ProductFiles
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
ProductFiles
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
F3B0D
|
||
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
|
EquationEditorFilesIntl_1033
|
||
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
|
SavedLegacySettings
|
||
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe
|
SMTP Service
|
There are 52 hidden registries, click here to show them.
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
2501000
|
unkown
|
page read and write
|
||
3549000
|
unkown
|
page read and write
|
||
402000
|
unkown
|
page execute and read and write
|
||
500000
|
unkown
|
page read and write
|
||
25E7000
|
unkown
|
page read and write
|
||
35AC000
|
unkown
|
page read and write
|
||
293000
|
unkown
|
page read and write
|
||
5CD1000
|
unkown
|
page read and write
|
||
500F000
|
unkown
|
page read and write
|
||
184000
|
unkown
|
page read and write
|
||
304000
|
heap default
|
page read and write
|
||
25C9000
|
unkown
|
page read and write
|
||
4FAD000
|
unkown
|
page read and write
|
||
5623000
|
unkown
|
page read and write
|
||
79B000
|
unkown
|
page execute and read and write
|
||
611000
|
unkown
|
page read and write
|
||
4B00000
|
unkown
|
page readonly
|
||
610000
|
unkown
|
page read and write
|
||
870000
|
unkown
|
page read and write
|
||
110000
|
unkown image
|
page readonly
|
||
5880000
|
unkown
|
page write copy
|
||
1D20000
|
unkown
|
page read and write
|
||
D10000
|
unkown
|
page read and write
|
||
840000
|
unkown
|
page read and write
|
||
7D2000
|
unkown
|
page read and write
|
||
4CE0000
|
unkown
|
page readonly
|
||
2605000
|
unkown
|
page read and write
|
||
5600000
|
unkown
|
page read and write
|
||
2285000
|
heap private
|
page read and write
|
||
526000
|
unkown
|
page read and write
|
||
3C5000
|
unkown
|
page read and write
|
||
4A5E000
|
unkown
|
page read and write
|
||
980000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
4ECE000
|
unkown
|
page read and write
|
||
E6E000
|
unkown
|
page read and write
|
||
458000
|
unkown
|
page read and write
|
||
547A000
|
unkown
|
page read and write
|
||
F00000
|
unkown
|
page read and write
|
||
960000
|
unkown
|
page readonly
|
||
33D000
|
heap default
|
page read and write
|
||
7EFDF000
|
unkown
|
page read and write
|
||
8E0000
|
unkown
|
page read and write
|
||
540000
|
unkown
|
page execute and read and write
|
||
61D0000
|
unkown
|
page readonly
|
||
D10000
|
unkown
|
page read and write
|
||
535000
|
unkown
|
page read and write
|
||
5612000
|
unkown
|
page read and write
|
||
2A7000
|
heap default
|
page read and write
|
||
5C0000
|
heap private
|
page execute and read and write
|
||
F6C000
|
unkown
|
page read and write
|
||
29DD000
|
unkown
|
page read and write
|
||
D10000
|
unkown
|
page read and write
|
||
B96E000
|
unkown
|
page read and write
|
||
3E4000
|
heap default
|
page read and write
|
||
7EF40000
|
unkown
|
page execute and read and write
|
||
2C5000
|
unkown
|
page read and write
|
||
C58E000
|
stack
|
page read and write
|
||
BB3000
|
unkown
|
page read and write
|
||
1142000
|
unkown image
|
page readonly
|
||
D0E000
|
stack
|
page read and write
|
||
520000
|
unkown
|
page read and write
|
||
EB0000
|
unkown
|
page read and write
|
||
357000
|
unkown
|
page execute and read and write
|
||
620000
|
unkown
|
page read and write
|
||
527000
|
unkown
|
page read and write
|
||
D10000
|
unkown
|
page read and write
|
||
81E000
|
unkown
|
page read and write
|
||
485F000
|
stack
|
page read and write
|
||
5E84000
|
unkown
|
page readonly
|
||
630E000
|
unkown
|
page read and write
|
||
590000
|
unkown
|
page readonly
|
||
520000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
45A0000
|
unkown
|
page readonly
|
||
845000
|
unkown
|
page read and write
|
||
5F36000
|
unkown
|
page readonly
|
||
540000
|
unkown
|
page read and write
|
||
260000
|
unkown
|
page readonly
|
||
EB0000
|
unkown
|
page read and write
|
||
5605000
|
unkown
|
page read and write
|
||
5F5D000
|
unkown
|
page read and write
|
||
8D0000
|
unkown
|
page readonly
|
||
1D7E000
|
unkown
|
page read and write
|
||
845000
|
unkown
|
page read and write
|
||
5F06000
|
unkown
|
page readonly
|
||
19A000
|
unkown
|
page execute and read and write
|
||
520000
|
unkown
|
page read and write
|
||
381D000
|
unkown
|
page read and write
|
||
8C0000
|
unkown
|
page read and write
|
||
EAF000
|
unkown
|
page read and write
|
||
A0C000
|
unkown
|
page read and write
|
||
5239000
|
unkown
|
page read and write
|
||
8A6000
|
heap private
|
page read and write
|
||
5AA000
|
unkown
|
page execute and read and write
|
||
61F000
|
unkown
|
page read and write
|
||
5FB2000
|
unkown
|
page readonly
|
||
500000
|
unkown
|
page read and write
|
||
258000
|
stack
|
page read and write
|
||
82E000
|
unkown
|
page read and write
|
||
1DA0000
|
unkown
|
page read and write
|
||
390000
|
unkown
|
page read and write
|
||
4C40000
|
unkown
|
page readonly
|
||
5F12000
|
unkown
|
page readonly
|
||
3C0000
|
unkown
|
page read and write
|
||
5C0000
|
unkown
|
page readonly
|
||
3686000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
1D30000
|
unkown
|
page read and write
|
||
5616000
|
unkown
|
page read and write
|
||
2D0000
|
heap default
|
page read and write
|
||
180000
|
unkown
|
page read and write
|
||
7EFDF000
|
unkown
|
page read and write
|
||
1AB000
|
unkown
|
page execute and read and write
|
||
56E0000
|
unkown
|
page read and write
|
||
527D000
|
unkown
|
page read and write
|
||
F04000
|
unkown
|
page read and write
|
||
5EB2000
|
unkown
|
page readonly
|
||
EC4000
|
heap private
|
page read and write
|
||
3A0000
|
unkown
|
page readonly
|
||
5607000
|
unkown
|
page read and write
|
||
525D000
|
unkown
|
page read and write
|
||
610000
|
unkown
|
page read and write
|
||
5A2000
|
unkown
|
page read and write
|
||
211F000
|
unkown
|
page read and write
|
||
466000
|
unkown
|
page read and write
|
||
5612000
|
unkown
|
page read and write
|
||
684000
|
heap private
|
page read and write
|
||
525000
|
unkown
|
page read and write
|
||
D7E000
|
unkown
|
page read and write
|
||
20000
|
heap private
|
page read and write
|
||
520000
|
unkown
|
page read and write
|
||
17A000
|
unkown
|
page read and write
|
||
D30000
|
unkown
|
page readonly
|
||
5EE2000
|
unkown
|
page readonly
|
||
410000
|
unkown
|
page readonly
|
||
3C7000
|
heap default
|
page read and write
|
||
F00000
|
unkown
|
page read and write
|
||
528000
|
unkown
|
page read and write
|
||
5900000
|
unkown
|
page readonly
|
||
133000
|
unkown
|
page execute and read and write
|
||
C0D000
|
unkown
|
page read and write
|
||
23DE000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
546E000
|
heap private
|
page read and write
|
||
850000
|
unkown
|
page read and write
|
||
520000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
5236000
|
unkown
|
page read and write
|
||
25B5000
|
unkown
|
page read and write
|
||
1D30000
|
unkown
|
page read and write
|
||
C190000
|
unkown
|
page read and write
|
||
F10000
|
unkown
|
page read and write
|
||
5A7C000
|
unkown
|
page read and write
|
||
510000
|
unkown
|
page read and write
|
||
51B0000
|
unkown
|
page read and write
|
||
610000
|
unkown
|
page read and write
|
||
5B9000
|
heap private
|
page read and write
|
||
110000
|
unkown image
|
page readonly
|
||
1145000
|
unkown image
|
page readonly
|
||
5FA5000
|
unkown
|
page readonly
|
||
940000
|
heap private
|
page read and write
|
||
BAE000
|
unkown
|
page read and write | page guard
|
||
D10000
|
unkown
|
page read and write
|
||
874000
|
unkown
|
page read and write
|
||
5590000
|
unkown
|
page read and write
|
||
2607000
|
unkown
|
page read and write
|
||
460000
|
unkown
|
page read and write
|
||
382000
|
unkown
|
page read and write
|
||
20000
|
unkown
|
page read and write
|
||
F00000
|
unkown
|
page read and write
|
||
530000
|
unkown
|
page read and write
|
||
2552000
|
unkown
|
page read and write
|
||
5450000
|
heap private
|
page read and write
|
||
8D0000
|
unkown
|
page read and write
|
||
1A2000
|
unkown
|
page read and write
|
||
4B0000
|
unkown
|
page read and write
|
||
540000
|
unkown
|
page read and write
|
||
3D80000
|
unkown
|
page read and write
|
||
840000
|
unkown
|
page read and write
|
||
950000
|
unkown
|
page readonly
|
||
5454000
|
heap private
|
page read and write
|
||
100000
|
unkown
|
page read and write
|
||
FD0000
|
unkown image
|
page readonly
|
||
318000
|
unkown
|
page read and write
|
||
C3EE000
|
unkown
|
page read and write
|
||
5624000
|
unkown
|
page read and write
|
||
5B0000
|
heap private
|
page read and write
|
||
D30000
|
unkown
|
page read and write
|
||
548C000
|
unkown
|
page read and write
|
||
526000
|
unkown
|
page read and write
|
||
5B6D000
|
unkown
|
page read and write
|
||
11A000
|
unkown image
|
page readonly
|
||
6A2000
|
heap private
|
page read and write
|
||
56CE000
|
unkown
|
page read and write
|
||
F70000
|
unkown
|
page read and write
|
||
2A07000
|
unkown
|
page read and write
|
||
460000
|
unkown
|
page read and write
|
||
5AEC000
|
unkown
|
page read and write
|
||
560D000
|
unkown
|
page read and write
|
||
4AF0000
|
heap private
|
page read and write
|
||
990000
|
unkown
|
page read and write
|
||
830000
|
unkown
|
page read and write
|
||
5A7000
|
unkown
|
page execute and read and write
|
||
112000
|
unkown image
|
page execute read
|
||
52B0000
|
unkown
|
page read and write
|
||
460000
|
unkown
|
page read and write
|
||
287000
|
stack
|
page read and write
|
||
5E44000
|
unkown
|
page readonly
|
||
440000
|
unkown
|
page write copy
|
||
3696000
|
unkown
|
page read and write
|
||
D10000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
4B0000
|
unkown
|
page read and write
|
||
422000
|
unkown
|
page execute and read and write
|
||
B2E000
|
unkown
|
page read and write
|
||
1182000
|
unkown image
|
page readonly
|
||
D20000
|
unkown
|
page read and write
|
||
5775000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
500000
|
unkown
|
page read and write
|
||
8C5000
|
unkown
|
page read and write
|
||
587D000
|
unkown
|
page read and write
|
||
460000
|
unkown
|
page read and write
|
||
740000
|
unkown
|
page readonly
|
||
D10000
|
unkown
|
page read and write
|
||
119B000
|
unkown image
|
page readonly
|
||
BB0D000
|
stack
|
page read and write
|
||
18D000
|
unkown
|
page execute and read and write
|
||
60E000
|
unkown
|
page read and write
|
||
3603000
|
unkown
|
page read and write
|
||
170000
|
unkown
|
page read and write
|
||
D34000
|
unkown
|
page read and write
|
||
D10000
|
unkown
|
page read and write
|
||
570000
|
unkown
|
page read and write
|
||
5E62000
|
unkown
|
page readonly
|
||
460000
|
unkown
|
page read and write
|
||
25B8000
|
unkown
|
page read and write
|
||
5EF5000
|
unkown
|
page readonly
|
||
E60000
|
unkown
|
page read and write
|
||
3509000
|
unkown
|
page read and write
|
||
5277000
|
unkown
|
page read and write
|
||
516E000
|
unkown
|
page read and write
|
||
860000
|
unkown
|
page read and write
|
||
5C82000
|
unkown
|
page readonly
|
||
4AC0000
|
unkown
|
page readonly
|
||
456000
|
unkown
|
page read and write
|
||
37CB000
|
unkown
|
page read and write
|
||
FB0000
|
unkown
|
page read and write
|
||
55FE000
|
unkown
|
page read and write
|
||
5F55000
|
unkown
|
page readonly
|
||
67E000
|
unkown
|
page read and write
|
||
610000
|
unkown
|
page read and write
|
||
2267000
|
heap private
|
page read and write
|
||
D30000
|
unkown
|
page read and write
|
||
530000
|
unkown
|
page read and write
|
||
D20000
|
unkown
|
page read and write
|
||
680000
|
heap private
|
page read and write
|
||
5EC5000
|
unkown
|
page readonly
|
||
5F69000
|
unkown
|
page readonly
|
||
4C0000
|
heap private
|
page execute and read and write
|
||
5F42000
|
unkown
|
page readonly
|
||
1A7000
|
unkown
|
page execute and read and write
|
||
840000
|
unkown
|
page read and write
|
||
FD2000
|
unkown image
|
page execute read
|
||
35B000
|
unkown
|
page execute and read and write
|
||
820000
|
unkown
|
page execute and read and write
|
||
C06E000
|
unkown
|
page read and write
|
||
4B5000
|
unkown
|
page read and write
|
||
13D000
|
unkown
|
page execute and read and write
|
||
3D0000
|
unkown
|
page readonly
|
||
4B0000
|
unkown
|
page read and write
|
||
1145000
|
unkown image
|
page readonly
|
||
860000
|
unkown
|
page read and write
|
||
3121000
|
unkown
|
page read and write
|
||
BB0000
|
unkown
|
page read and write
|
||
8ED000
|
unkown
|
page read and write
|
||
5FB9000
|
unkown
|
page readonly
|
||
840000
|
unkown
|
page read and write
|
||
5FE2000
|
unkown
|
page readonly
|
||
630000
|
unkown
|
page read and write
|
||
840000
|
unkown
|
page read and write
|
||
EC0000
|
heap private
|
page read and write
|
||
5ED6000
|
unkown
|
page readonly
|
||
610000
|
unkown
|
page read and write
|
||
13D000
|
unkown
|
page execute and read and write
|
||
1182000
|
unkown image
|
page readonly
|
||
383D000
|
unkown
|
page read and write
|
||
610000
|
unkown
|
page read and write
|
||
3F0000
|
unkown
|
page read and write
|
||
BC20000
|
unkown
|
page readonly
|
||
4F00000
|
heap private
|
page read and write
|
||
2260000
|
heap private
|
page read and write
|
||
35A1000
|
unkown
|
page read and write
|
||
520000
|
unkown
|
page read and write
|
||
550000
|
heap default
|
page read and write
|
||
8C0000
|
unkown
|
page read and write
|
||
382000
|
unkown
|
page read and write
|
||
8D0000
|
unkown
|
page read and write
|
||
7C9000
|
heap default
|
page read and write
|
||
5D82000
|
unkown
|
page readonly
|
||
970000
|
unkown
|
page read and write
|
||
500000
|
unkown
|
page read and write
|
||
615000
|
unkown
|
page read and write
|
||
36A6000
|
unkown
|
page read and write
|
||
4B0000
|
unkown
|
page read and write
|
||
546C000
|
heap private
|
page read and write
|
||
1E4E000
|
unkown
|
page read and write
|
||
196000
|
unkown
|
page execute and read and write
|
||
520000
|
unkown
|
page read and write
|
||
500E000
|
unkown
|
page read and write | page guard
|
||
528C000
|
unkown
|
page read and write
|
||
610000
|
unkown
|
page read and write
|
||
1CE0000
|
unkown
|
page readonly
|
||
656E000
|
unkown
|
page read and write
|
||
2E0000
|
heap default
|
page read and write
|
||
620000
|
unkown
|
page read and write
|
||
5B0000
|
heap private
|
page read and write
|
||
4B0000
|
unkown
|
page read and write
|
||
A60000
|
heap private
|
page execute and read and write
|
||
112000
|
unkown image
|
page execute read
|
||
100000
|
heap private
|
page read and write
|
||
1D10000
|
unkown
|
page read and write
|
||
90000
|
unkown
|
page readonly
|
||
AC000
|
unkown
|
page read and write
|
||
D00000
|
unkown
|
page readonly
|
||
24FF000
|
unkown
|
page read and write
|
||
560D000
|
unkown
|
page read and write
|
||
610000
|
unkown
|
page read and write
|
||
3501000
|
unkown
|
page read and write
|
||
562F000
|
unkown
|
page read and write
|
||
F20000
|
unkown
|
page execute and read and write
|
||
54D5000
|
unkown
|
page read and write
|
||
4B0000
|
unkown
|
page read and write
|
||
5F66000
|
unkown
|
page readonly
|
||
847000
|
unkown
|
page read and write
|
||
3666000
|
unkown
|
page read and write
|
||
42CE000
|
stack
|
page read and write
|
||
520000
|
unkown
|
page read and write
|
||
A40000
|
unkown
|
page read and write
|
||
4CDE000
|
stack
|
page read and write
|
||
632D000
|
unkown
|
page read and write
|
||
54AD000
|
unkown
|
page read and write
|
||
120000
|
unkown
|
page read and write
|
||
5246000
|
unkown
|
page read and write
|
||
390000
|
unkown
|
page read and write
|
||
14D000
|
unkown
|
page execute and read and write
|
||
5490000
|
unkown
|
page read and write
|
||
211E000
|
unkown
|
page read and write | page guard
|
||
531C000
|
unkown
|
page read and write
|
||
4FC0000
|
unkown
|
page read and write
|
||
840000
|
unkown
|
page read and write
|
||
628F000
|
unkown
|
page read and write
|
||
4B30000
|
heap private
|
page execute and read and write
|
||
3758000
|
unkown
|
page read and write
|
||
720000
|
heap default
|
page read and write
|
||
72D000
|
heap default
|
page read and write
|
||
4A60000
|
unkown
|
page read and write
|
||
2100000
|
unkown
|
page readonly
|
||
51E0000
|
heap private
|
page read and write
|
||
69EE000
|
unkown
|
page read and write
|
||
EB0000
|
unkown
|
page read and write
|
||
3E0000
|
unkown
|
page readonly
|
||
29F5000
|
unkown
|
page read and write
|
||
C92E000
|
unkown
|
page read and write | page guard
|
||
5613000
|
unkown
|
page read and write
|
||
7EF58000
|
unkown
|
page execute and read and write
|
||
C190000
|
unkown
|
page read and write
|
||
840000
|
unkown
|
page read and write
|
||
2C4000
|
heap default
|
page read and write
|
||
5F89000
|
unkown
|
page readonly
|
||
5E42000
|
unkown
|
page readonly
|
||
B8DE000
|
unkown
|
page read and write
|
||
1EC0000
|
heap private
|
page read and write
|
||
FD2000
|
unkown image
|
page execute read
|
||
400000
|
heap default
|
page read and write
|
||
840000
|
unkown
|
page read and write
|
||
C190000
|
unkown
|
page read and write
|
||
5F82000
|
unkown
|
page readonly
|
||
500000
|
unkown
|
page read and write
|
||
920000
|
unkown
|
page readonly
|
||
787000
|
heap default
|
page read and write
|
||
24FE000
|
unkown
|
page read and write | page guard
|
||
400000
|
unkown
|
page execute and read and write
|
||
8C8000
|
unkown
|
page read and write
|
||
4AD000
|
unkown
|
page read and write
|
||
610D000
|
unkown
|
page read and write
|
||
D20000
|
unkown
|
page read and write
|
||
3B0000
|
unkown
|
page read and write
|
||
518000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
541C000
|
unkown
|
page read and write
|
||
797000
|
unkown
|
page execute and read and write
|
||
7EF40000
|
unkown
|
page execute and read and write
|
||
740000
|
heap default
|
page read and write
|
||
2A0000
|
heap default
|
page read and write
|
||
8C0000
|
unkown
|
page read and write
|
||
1DC0000
|
heap private
|
page execute and read and write
|
||
35D3000
|
unkown
|
page read and write
|
||
610000
|
unkown
|
page read and write
|
||
5612000
|
unkown
|
page read and write
|
||
6E7000
|
heap default
|
page read and write
|
||
4680000
|
unkown
|
page readonly
|
||
871000
|
unkown
|
page read and write
|
||
D80000
|
unkown
|
page readonly
|
||
C2AF000
|
stack
|
page read and write
|
||
530000
|
unkown
|
page read and write
|
||
5591000
|
unkown
|
page read and write
|
||
B91C000
|
unkown
|
page read and write
|
||
2F0000
|
unkown
|
page read and write
|
||
20000
|
unkown
|
page read and write
|
||
562A000
|
unkown
|
page read and write
|
||
1D90000
|
unkown
|
page read and write
|
||
25A1000
|
unkown
|
page read and write
|
||
36E6000
|
unkown
|
page read and write
|
||
42D0000
|
unkown
|
page readonly
|
||
5214000
|
unkown
|
page read and write
|
||
560D000
|
unkown
|
page read and write
|
||
704000
|
heap default
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
840000
|
unkown
|
page read and write
|
||
4A0F000
|
stack
|
page read and write
|
||
7D0000
|
unkown
|
page read and write
|
||
5C88000
|
unkown
|
page readonly
|
||
2310000
|
unkown
|
page readonly
|
||
2210000
|
heap private
|
page execute and read and write
|
||
5605000
|
unkown
|
page read and write
|
||
AD0000
|
unkown
|
page readonly
|
||
5040000
|
unkown
|
page readonly
|
||
889000
|
heap private
|
page read and write
|
||
BAF000
|
unkown
|
page read and write
|
||
910000
|
heap private
|
page read and write
|
||
4C00000
|
heap private
|
page execute and read and write
|
||
840000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
C18E000
|
stack
|
page read and write
|
||
FD0000
|
unkown image
|
page readonly
|
||
930000
|
unkown
|
page read and write
|
||
38A0000
|
unkown
|
page read and write
|
||
B30000
|
heap private
|
page execute and read and write
|
||
86D000
|
unkown
|
page read and write
|
||
BC1E000
|
stack
|
page read and write
|
||
5476000
|
unkown
|
page read and write
|
||
5FE9000
|
unkown
|
page readonly
|
||
85D8000
|
unkown
|
page read and write
|
||
110000
|
unkown image
|
page readonly
|
||
EAE000
|
unkown
|
page read and write | page guard
|
||
610000
|
unkown
|
page read and write
|
||
360000
|
unkown
|
page read and write
|
||
2121000
|
unkown
|
page read and write
|
||
4AF5000
|
heap private
|
page read and write
|
||
65AF000
|
stack
|
page read and write
|
||
5F6D000
|
unkown
|
page readonly
|
||
610000
|
unkown
|
page read and write
|
||
51AE000
|
stack
|
page read and write
|
||
380000
|
heap private
|
page execute and read and write
|
||
1142000
|
unkown image
|
page readonly
|
||
1FEE000
|
unkown
|
page read and write
|
||
465000
|
unkown
|
page read and write
|
||
37AB000
|
unkown
|
page read and write
|
||
D10000
|
unkown
|
page read and write
|
||
C6DE000
|
stack
|
page read and write
|
||
460000
|
unkown
|
page read and write
|
||
61F0000
|
unkown
|
page readonly
|
||
2A77000
|
unkown
|
page read and write
|
||
880000
|
heap private
|
page read and write
|
||
792000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
4870000
|
unkown
|
page read and write
|
||
4BA0000
|
heap private
|
page read and write
|
||
D20000
|
unkown
|
page read and write
|
||
3656000
|
unkown
|
page read and write
|
||
460000
|
unkown
|
page read and write
|
||
120000
|
unkown
|
page read and write
|
||
3C0000
|
unkown
|
page read and write
|
||
960000
|
unkown
|
page read and write
|
||
562E000
|
unkown
|
page read and write
|
||
FD0000
|
unkown image
|
page readonly
|
||
6E0000
|
heap default
|
page read and write
|
||
3529000
|
unkown
|
page read and write
|
||
1F7D000
|
unkown
|
page read and write
|
||
2EC000
|
heap default
|
page read and write
|
||
642E000
|
unkown
|
page read and write
|
||
612000
|
unkown
|
page read and write
|
||
AA0000
|
unkown
|
page read and write
|
||
183000
|
unkown
|
page execute and read and write
|
||
7D6000
|
heap default
|
page read and write
|
||
6172000
|
unkown
|
page readonly
|
||
520000
|
unkown
|
page read and write
|
||
510D000
|
unkown
|
page read and write
|
||
610000
|
unkown
|
page read and write
|
||
5FD5000
|
unkown
|
page readonly
|
||
119B000
|
unkown image
|
page readonly
|
||
35A1000
|
unkown
|
page read and write
|
||
456D000
|
unkown
|
page read and write
|
||
18D000
|
unkown
|
page execute and read and write
|
||
4ABF000
|
unkown
|
page read and write
|
||
C82D000
|
stack
|
page read and write
|
||
1132000
|
unkown image
|
page readonly
|
||
3C0000
|
unkown
|
page read and write
|
||
850000
|
unkown
|
page read and write
|
||
D20000
|
unkown
|
page read and write
|
||
F1D000
|
unkown
|
page read and write
|
||
36B6000
|
unkown
|
page read and write
|
||
3738000
|
unkown
|
page read and write
|
||
59D0000
|
heap private
|
page read and write
|
||
840000
|
unkown
|
page read and write
|
||
49BF000
|
unkown
|
page read and write
|
||
940000
|
unkown
|
page readonly
|
||
850000
|
unkown
|
page read and write
|
||
456000
|
unkown
|
page read and write
|
||
98C000
|
unkown
|
page read and write
|
||
35A9000
|
unkown
|
page read and write
|
||
530000
|
unkown
|
page read and write
|
||
1D80000
|
unkown
|
page read and write
|
||
3646000
|
unkown
|
page read and write
|
||
3C0000
|
unkown
|
page read and write
|
||
3686000
|
unkown
|
page read and write
|
||
61B0000
|
unkown
|
page readonly
|
||
2E0000
|
unkown
|
page execute and read and write
|
||
5473000
|
unkown
|
page read and write
|
||
36C6000
|
unkown
|
page read and write
|
||
2EA000
|
heap default
|
page read and write
|
||
D0000
|
heap default
|
page read and write
|
||
5E64000
|
unkown
|
page readonly
|
||
560000
|
unkown
|
page execute and read and write
|
||
35F3000
|
unkown
|
page read and write
|
||
C92F000
|
unkown
|
page read and write
|
||
467E000
|
unkown
|
page read and write
|
||
29D000
|
unkown
|
page execute and read and write
|
||
AA000
|
unkown
|
page read and write
|
||
35E3000
|
unkown
|
page read and write
|
||
520000
|
unkown
|
page read and write
|
||
620000
|
unkown
|
page read and write
|
||
5F25000
|
unkown
|
page readonly
|
||
1D00000
|
unkown
|
page execute and read and write
|
||
58E0000
|
unkown
|
page readonly
|
||
7EFDF000
|
unkown
|
page read and write
|
||
390000
|
unkown
|
page read and write
|
||
133000
|
unkown
|
page execute and read and write
|
||
51E8000
|
unkown
|
page read and write
|
||
4A0E000
|
stack
|
page read and write
|
||
11A000
|
unkown image
|
page readonly
|
||
D10000
|
unkown
|
page read and write
|
||
40D000
|
heap default
|
page read and write
|
||
EE2000
|
heap private
|
page read and write
|
||
460000
|
unkown
|
page read and write
|
||
5271000
|
unkown
|
page read and write
|
||
110000
|
unkown
|
page read and write
|
||
3C0000
|
unkown
|
page readonly
|
||
134000
|
unkown
|
page read and write
|
||
5E82000
|
unkown
|
page readonly
|
||
520000
|
unkown
|
page read and write
|
||
672E000
|
unkown
|
page read and write
|
||
35D000
|
unkown
|
page read and write
|
||
BC0000
|
unkown
|
page read and write
|
||
D30000
|
unkown
|
page read and write
|
||
840000
|
unkown
|
page read and write
|
||
6005000
|
unkown
|
page readonly
|
||
450000
|
unkown
|
page read and write
|
||
795000
|
unkown
|
page execute and read and write
|
||
1132000
|
unkown image
|
page readonly
|
||
520000
|
unkown
|
page read and write
|
||
8AE000
|
unkown
|
page read and write
|
||
5320000
|
unkown
|
page readonly
|
||
134000
|
unkown
|
page read and write
|
||
25BB000
|
unkown
|
page read and write
|
||
3C0000
|
heap default
|
page read and write
|
||
140000
|
unkown
|
page read and write
|
||
460000
|
unkown
|
page read and write
|
||
532000
|
unkown
|
page read and write
|
||
5CCD000
|
stack
|
page read and write
|
||
510000
|
unkown
|
page read and write
|
||
36BC000
|
unkown
|
page read and write
|
||
F10000
|
unkown
|
page read and write
|
There are 565 hidden memdumps, click here to show them.