Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
presupuesto.xlsx
|
CDFV2 Encrypted
|
initial sample
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\svchost[1].exe
|
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
|
downloaded
|
||
C:\Users\user\Desktop\~$presupuesto.xlsx
|
data
|
dropped
|
||
C:\Users\Public\vbc.exe
|
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
|
modified
|
||
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
|
Microsoft Cabinet archive data, 58596 bytes, 1 file
|
dropped
|
||
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E0F5C59F9FA661F6F4C50B87FEF3A15A
|
data
|
dropped
|
||
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
|
data
|
dropped
|
||
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E0F5C59F9FA661F6F4C50B87FEF3A15A
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\234E901.emf
|
Windows Enhanced Metafile (EMF) image data version 0x10000
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\48B2E23A.jpeg
|
gd-jpeg v1.0 (using IJG JPEG v80), quality = 90", baseline, precision 8, 700x990, frames 3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\55794626.jpeg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 220x220, segment length 16, baseline, precision 8, 550x310,
frames 3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\82D1B3EF.jpeg
|
gd-jpeg v1.0 (using IJG JPEG v80), quality = 90", baseline, precision 8, 700x990, frames 3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\87FB93B7.png
|
PNG image data, 399 x 605, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\8CCFB279.jpeg
|
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 333x151, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\91806A4C.jpeg
|
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 333x151, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\EE298F3.jpeg
|
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 191x263, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\EF4BADDD.jpeg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 220x220, segment length 16, baseline, precision 8, 550x310,
frames 3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\F29F3B0E.jpeg
|
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 191x263, frames
3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\FA2D9658.png
|
PNG image data, 399 x 605, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\CabE532.tmp
|
Microsoft Cabinet archive data, 58596 bytes, 1 file
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\TarE533.tmp
|
data
|
dropped
|
There are 11 hidden files, click here to show them.
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
|
'C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE' -Embedding
|
||
C:\Users\Public\vbc.exe
|
'C:\Users\Public\vbc.exe'
|
||
C:\Users\Public\vbc.exe
|
C:\Users\Public\vbc.exe
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://surestdysbonescagecv.dns.army/documenpt/svchost.exe
|
103.153.76.181
|
||
http://d2rIi4JlBhFsgbEW3nM.com
|
unknown
|
||
http://smtp.oucabem.com.br
|
unknown
|
||
http://127.0.0.1:HTTP/1.1
|
unknown
|
||
http://DynDns.comDynDNS
|
unknown
|
||
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
|
unknown
|
||
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha
|
unknown
|
||
http://epVtFD.com
|
unknown
|
||
https://api.ipify.org%GETMozilla/5.0
|
unknown
|
||
http://mail.ita.locaweb.com.br
|
unknown
|
||
http://www.%s.comPA
|
unknown
|
||
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
|
unknown
|
||
https://api.ipify.org%
|
unknown
|
||
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip
|
unknown
|
||
https://stackpath.bootstrapcdn.com/bootstrap/4.5.0/css/bootstrap.min.css
|
unknown
|
There are 5 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
surestdysbonescagecv.dns.army
|
103.153.76.181
|
||
smtp.oucabem.com.br
|
unknown
|
||
fqe.short.gy
|
52.59.165.42
|
||
mail.ita.locaweb.com.br
|
191.252.112.194
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
103.153.76.181
|
surestdysbonescagecv.dns.army
|
unknown
|
||
52.59.165.42
|
fqe.short.gy
|
United States
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
a{7
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
MTTT
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
ReviewToken
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
ECBA8
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
FontCachePath
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
VBAFiles
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
DefaultSheetR2L
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
UseSystemSeparators
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
ThousandsSeparator
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
DecimalSeparator
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
)f7
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
F1842
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
F314D
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Max Display
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 1
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Max Display
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 1
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 2
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 3
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 4
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 5
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 6
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 7
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 8
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 9
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 10
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 11
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 12
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 13
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 14
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 15
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 16
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 17
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 18
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 19
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 20
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
Item 21
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
LastPurgeTime
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
1033
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
1033
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
EXCELFiles
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
ProductFiles
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_3082
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_3082
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_1036
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_1036
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_1033
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_1033
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_3082
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_3082
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_1036
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_1036
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_1033
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
SpellingAndGrammarFiles_1033
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
ProductFiles
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
ProductFiles
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
ProductFiles
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
ProductFiles
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
F1842
|
||
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
ProductFiles
|
||
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
|
EquationEditorFilesIntl_1033
|
||
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
|
SavedLegacySettings
|
||
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
|
Blob
|
||
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
|
Blob
|
||
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
|
Blob
|
||
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
|
Blob
|
||
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
|
Blob
|
||
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
|
Blob
|
There are 58 hidden registries, click here to show them.
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
2361000
|
unkown
|
page read and write
|
||
230A000
|
unkown
|
page read and write
|
||
240E000
|
unkown
|
page read and write
|
||
402000
|
unkown
|
page execute and read and write
|
||
32C9000
|
unkown
|
page read and write
|
||
5795000
|
unkown
|
page readonly
|
||
2326000
|
unkown
|
page read and write
|
||
57CE000
|
unkown
|
page read and write | page guard
|
||
4CA0000
|
heap private
|
page read and write
|
||
459000
|
unkown
|
page read and write
|
||
4970000
|
unkown
|
page write copy
|
||
280000
|
unkown
|
page read and write
|
||
616E000
|
unkown
|
page read and write
|
||
5B0000
|
unkown
|
page read and write
|
||
710000
|
unkown
|
page read and write
|
||
4CD0000
|
unkown
|
page read and write
|
||
45FE000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
9E0000
|
unkown
|
page read and write
|
||
1FB0000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
710000
|
unkown
|
page read and write
|
||
5F0000
|
unkown
|
page readonly
|
||
450000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
4510000
|
unkown
|
page readonly
|
||
AF0000
|
unkown image
|
page readonly
|
||
6FE000
|
unkown
|
page read and write
|
||
59E2000
|
unkown
|
page readonly
|
||
4A72000
|
heap private
|
page read and write
|
||
67FE000
|
unkown
|
page read and write
|
||
500000
|
unkown
|
page read and write
|
||
6B0000
|
unkown
|
page read and write
|
||
4A0000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
591E000
|
unkown
|
page read and write
|
||
AE0000
|
unkown
|
page read and write
|
||
5A20000
|
unkown
|
page readonly
|
||
5B0000
|
unkown
|
page read and write
|
||
56B2000
|
unkown
|
page readonly
|
||
5852000
|
unkown
|
page readonly
|
||
280000
|
unkown
|
page read and write
|
||
280000
|
unkown
|
page read and write
|
||
280000
|
unkown
|
page read and write
|
||
665D000
|
stack
|
page read and write
|
||
760000
|
unkown
|
page read and write
|
||
6D0000
|
heap private
|
page read and write
|
||
4AD4000
|
heap private
|
page read and write
|
||
223E000
|
unkown
|
page read and write
|
||
75C000
|
unkown
|
page read and write
|
||
AC0000
|
unkown
|
page read and write
|
||
614F000
|
unkown
|
page read and write
|
||
4BA7000
|
unkown
|
page read and write
|
||
285000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
20000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
453000
|
unkown
|
page read and write
|
||
187000
|
unkown
|
page execute and read and write
|
||
280000
|
unkown
|
page read and write
|
||
1D0000
|
unkown
|
page execute and read and write
|
||
4A0000
|
unkown
|
page read and write
|
||
280000
|
unkown
|
page read and write
|
||
4B0000
|
heap default
|
page read and write
|
||
452000
|
unkown
|
page read and write
|
||
5859000
|
unkown
|
page readonly
|
||
4D1000
|
heap default
|
page read and write
|
||
44BE000
|
unkown
|
page read and write
|
||
225F000
|
unkown
|
page read and write
|
||
4A0000
|
unkown
|
page read and write
|
||
285000
|
unkown
|
page read and write
|
||
5F0000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
AEE000
|
stack
|
page read and write
|
||
420000
|
heap default
|
page read and write
|
||
19B000
|
unkown
|
page execute and read and write
|
||
450000
|
unkown
|
page read and write
|
||
370000
|
unkown
|
page read and write
|
||
5B0000
|
unkown
|
page read and write
|
||
249E000
|
unkown
|
page read and write
|
||
54F2000
|
unkown
|
page readonly
|
||
4D4000
|
heap default
|
page read and write
|
||
5A81000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
4A0000
|
unkown
|
page read and write
|
||
1F0000
|
unkown
|
page read and write
|
||
110000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
566D000
|
unkown
|
page read and write
|
||
280000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
4A0000
|
unkown
|
page read and write
|
||
4700000
|
unkown
|
page readonly
|
||
18B000
|
unkown
|
page read and write
|
||
22C1000
|
unkown
|
page read and write
|
||
49B8000
|
unkown
|
page read and write
|
||
285000
|
unkown
|
page read and write
|
||
1E0000
|
unkown
|
page execute and read and write
|
||
49E2000
|
unkown
|
page read and write
|
||
AF2000
|
unkown image
|
page execute read
|
||
450000
|
unkown
|
page read and write
|
||
64BC000
|
unkown
|
page read and write
|
||
5F0000
|
unkown
|
page read and write
|
||
4CCE000
|
unkown
|
page read and write
|
||
4A0000
|
unkown
|
page read and write
|
||
AF2000
|
unkown image
|
page execute read
|
||
285000
|
unkown
|
page read and write
|
||
4E0000
|
unkown
|
page read and write
|
||
49E4000
|
unkown
|
page read and write
|
||
B78000
|
unkown image
|
page readonly
|
||
528E000
|
unkown
|
page read and write
|
||
AC0000
|
unkown
|
page read and write
|
||
49E000
|
unkown
|
page read and write
|
||
5B2000
|
unkown
|
page read and write
|
||
46FF000
|
stack
|
page read and write
|
||
235F000
|
unkown
|
page read and write
|
||
285000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
4CA5000
|
heap private
|
page read and write
|
||
285000
|
unkown
|
page read and write
|
||
249C000
|
unkown
|
page read and write
|
||
770000
|
unkown
|
page read and write
|
||
57DD000
|
unkown
|
page readonly
|
||
56B4000
|
unkown
|
page readonly
|
||
450000
|
unkown
|
page read and write
|
||
5410000
|
unkown
|
page read and write
|
||
2400000
|
unkown
|
page read and write
|
||
5815000
|
unkown
|
page readonly
|
||
450000
|
unkown
|
page read and write
|
||
285000
|
unkown
|
page read and write
|
||
57F9000
|
unkown
|
page readonly
|
||
AA0000
|
unkown
|
page read and write
|
||
610000
|
unkown
|
page read and write
|
||
120000
|
unkown
|
page read and write
|
||
3D0000
|
unkown
|
page read and write
|
||
32C1000
|
unkown
|
page read and write
|
||
B78000
|
unkown image
|
page readonly
|
||
4CC000
|
heap default
|
page read and write
|
||
1FAB000
|
unkown
|
page read and write
|
||
404000
|
heap default
|
page read and write
|
||
AF0000
|
unkown image
|
page readonly
|
||
450000
|
unkown
|
page read and write
|
||
3DC0000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
590000
|
heap private
|
page execute and read and write
|
||
5B0000
|
unkown
|
page read and write
|
||
4B5F000
|
stack
|
page read and write
|
||
810000
|
unkown
|
page readonly
|
||
AF2000
|
unkown image
|
page execute read
|
||
130000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
5A00000
|
heap private
|
page read and write
|
||
455000
|
unkown
|
page read and write
|
||
57E000
|
unkown
|
page read and write
|
||
55F2000
|
unkown
|
page readonly
|
||
288000
|
unkown
|
page read and write
|
||
285000
|
unkown
|
page read and write
|
||
5BDE000
|
unkown
|
page read and write
|
||
5D5C000
|
unkown
|
page read and write
|
||
56F4000
|
unkown
|
page readonly
|
||
4A50000
|
heap private
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
6A0000
|
heap private
|
page read and write
|
||
13D000
|
unkown
|
page execute and read and write
|
||
5DFE000
|
unkown
|
page read and write
|
||
49EC000
|
unkown
|
page read and write
|
||
280000
|
unkown
|
page read and write
|
||
760000
|
unkown
|
page read and write
|
||
285000
|
unkown
|
page read and write
|
||
5735000
|
unkown
|
page readonly
|
||
21F0000
|
unkown
|
page read and write
|
||
285000
|
unkown
|
page read and write
|
||
3591000
|
unkown
|
page read and write
|
||
285000
|
unkown
|
page read and write
|
||
110000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
760000
|
unkown
|
page read and write
|
||
5B7C000
|
unkown
|
page read and write
|
||
AB0000
|
unkown
|
page read and write
|
||
580000
|
unkown
|
page read and write
|
||
540E000
|
unkown
|
page read and write
|
||
3E7000
|
heap default
|
page read and write
|
||
5AD000
|
heap default
|
page read and write
|
||
455000
|
unkown
|
page read and write
|
||
675E000
|
stack
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
6C0000
|
heap private
|
page read and write
|
||
4F0000
|
unkown
|
page read and write
|
||
57D6000
|
unkown
|
page readonly
|
||
455000
|
unkown
|
page read and write
|
||
288000
|
unkown
|
page read and write
|
||
B78000
|
unkown image
|
page readonly
|
||
5B0000
|
unkown
|
page read and write
|
||
ABA000
|
unkown
|
page read and write
|
||
23B5000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
6E0000
|
unkown
|
page readonly
|
||
450000
|
unkown
|
page read and write
|
||
700000
|
unkown
|
page read and write
|
||
5829000
|
unkown
|
page readonly
|
||
AD0000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
455000
|
unkown
|
page read and write
|
||
AD0000
|
unkown
|
page read and write
|
||
203E000
|
unkown
|
page read and write
|
||
280000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
285000
|
unkown
|
page read and write
|
||
42C0000
|
unkown
|
page readonly
|
||
57A6000
|
unkown
|
page readonly
|
||
AA4000
|
unkown
|
page read and write
|
||
4B60000
|
unkown
|
page read and write
|
||
6F6B000
|
unkown
|
page read and write
|
||
455000
|
unkown
|
page read and write
|
||
280000
|
unkown
|
page read and write
|
||
455000
|
unkown
|
page read and write
|
||
5F0000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
182000
|
unkown
|
page read and write
|
||
542D000
|
unkown
|
page read and write
|
||
658E000
|
unkown
|
page read and write
|
||
280000
|
unkown
|
page read and write
|
||
4B5E000
|
unkown
|
page read and write
|
||
5FBE000
|
unkown
|
page read and write
|
||
4AD0000
|
heap private
|
page read and write
|
||
454000
|
unkown
|
page read and write
|
||
124000
|
unkown
|
page read and write
|
||
4F0000
|
unkown
|
page read and write
|
||
5C0000
|
unkown
|
page execute and read and write
|
||
4E0000
|
unkown
|
page read and write
|
||
280000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
5B80000
|
unkown
|
page readonly
|
||
1E0000
|
heap default
|
page read and write
|
||
5776000
|
unkown
|
page readonly
|
||
3C0000
|
unkown
|
page readonly
|
||
510000
|
unkown
|
page read and write
|
||
280000
|
unkown
|
page read and write
|
||
2040000
|
unkown
|
page readonly
|
||
455000
|
unkown
|
page read and write
|
||
770000
|
unkown
|
page read and write
|
||
123000
|
unkown
|
page execute and read and write
|
||
5D0000
|
unkown
|
page read and write
|
||
2280000
|
heap private
|
page read and write
|
||
280000
|
unkown
|
page read and write
|
||
6B4F000
|
stack
|
page read and write
|
||
245E000
|
unkown
|
page read and write
|
||
3D0000
|
unkown
|
page read and write
|
||
49B4000
|
unkown
|
page read and write
|
||
5845000
|
unkown
|
page readonly
|
||
63B000
|
heap private
|
page read and write
|
||
62EE000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
4A55000
|
heap private
|
page read and write
|
||
AC5000
|
unkown
|
page read and write
|
||
770000
|
unkown
|
page execute and read and write
|
||
4A0000
|
unkown
|
page read and write
|
||
5D0000
|
unkown
|
page read and write
|
||
4A0000
|
unkown
|
page read and write
|
||
4A0000
|
unkown
|
page read and write
|
||
4E7000
|
unkown
|
page read and write
|
||
4928000
|
unkown
|
page read and write
|
||
47E0000
|
unkown
|
page readonly
|
||
280000
|
unkown
|
page read and write
|
||
4CE7000
|
unkown
|
page read and write
|
||
770000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
57F2000
|
unkown
|
page readonly
|
||
43AE000
|
unkown
|
page read and write
|
||
280000
|
unkown
|
page read and write
|
||
280000
|
unkown
|
page read and write
|
||
4A3000
|
unkown
|
page read and write
|
||
500000
|
unkown
|
page read and write
|
||
60C000
|
unkown
|
page read and write
|
||
469F000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
5722000
|
unkown
|
page readonly
|
||
710000
|
unkown
|
page read and write
|
||
4A0000
|
unkown
|
page read and write
|
||
800000
|
heap private
|
page read and write
|
||
3BE000
|
unkown
|
page read and write
|
||
285000
|
unkown
|
page read and write
|
||
5D0000
|
unkown
|
page readonly
|
||
700000
|
unkown
|
page read and write
|
||
580000
|
unkown
|
page read and write
|
||
4A00000
|
heap private
|
page execute and read and write
|
||
4B7000
|
heap default
|
page read and write
|
||
5B0000
|
unkown
|
page read and write
|
||
17D000
|
unkown
|
page execute and read and write
|
||
170000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
4E30000
|
heap private
|
page execute and read and write
|
||
450000
|
unkown
|
page read and write
|
||
6A3F000
|
unkown
|
page read and write
|
||
634000
|
heap private
|
page read and write
|
||
5D0000
|
unkown
|
page read and write
|
||
7D0000
|
unkown
|
page read and write
|
||
3D7000
|
unkown
|
page read and write
|
||
4CE0000
|
unkown
|
page readonly
|
||
2C0000
|
unkown
|
page readonly
|
||
AF0000
|
unkown image
|
page readonly
|
||
53BE000
|
unkown
|
page read and write
|
||
285000
|
unkown
|
page read and write
|
||
14A000
|
unkown
|
page execute and read and write
|
||
285000
|
unkown
|
page read and write
|
||
2130000
|
heap private
|
page execute and read and write
|
||
B78000
|
unkown image
|
page readonly
|
||
450000
|
unkown
|
page read and write
|
||
2302000
|
unkown
|
page read and write
|
||
514E000
|
stack
|
page read and write
|
||
56D4000
|
unkown
|
page readonly
|
||
3E0000
|
heap default
|
page read and write
|
||
67D000
|
unkown
|
page read and write
|
||
4AB000
|
unkown
|
page read and write
|
||
BA0000
|
unkown
|
page readonly
|
||
280000
|
unkown
|
page read and write
|
||
4A0000
|
unkown
|
page read and write
|
||
6C7000
|
heap private
|
page read and write
|
||
280000
|
unkown
|
page read and write
|
||
440000
|
unkown
|
page read and write
|
||
6F50000
|
unkown
|
page read and write
|
||
AD0000
|
unkown
|
page read and write
|
||
4A0000
|
unkown
|
page read and write
|
||
455000
|
unkown
|
page read and write
|
||
5A40000
|
unkown
|
page readonly
|
||
23E8000
|
unkown
|
page read and write
|
||
452000
|
unkown
|
page read and write
|
||
280000
|
unkown
|
page read and write
|
||
4E0000
|
unkown
|
page read and write
|
||
450E000
|
unkown
|
page read and write
|
||
80000
|
unkown
|
page readonly
|
||
450000
|
unkown
|
page read and write
|
||
142000
|
unkown
|
page read and write
|
||
4A0000
|
unkown
|
page read and write
|
||
2B0000
|
unkown
|
page readonly
|
||
AC0000
|
unkown
|
page read and write
|
||
5B0000
|
unkown
|
page read and write
|
||
4E0000
|
unkown
|
page read and write
|
||
5765000
|
unkown
|
page readonly
|
||
5170000
|
unkown
|
page readonly
|
||
280000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
280000
|
unkown
|
page read and write
|
||
5875000
|
unkown
|
page readonly
|
||
26D000
|
unkown
|
page read and write
|
||
48F0000
|
unkown
|
page read and write
|
||
5746000
|
unkown
|
page readonly
|
||
285000
|
unkown
|
page read and write
|
||
710000
|
unkown
|
page read and write
|
||
4AF2000
|
heap private
|
page read and write
|
||
290000
|
unkown
|
page read and write
|
||
5B0000
|
unkown
|
page read and write
|
||
195000
|
unkown
|
page execute and read and write
|
||
450000
|
unkown
|
page read and write
|
||
49E000
|
heap default
|
page read and write
|
||
456000
|
unkown
|
page read and write
|
||
2120000
|
unkown
|
page read and write
|
||
56D2000
|
unkown
|
page readonly
|
||
4A0000
|
unkown
|
page read and write
|
||
5A80000
|
unkown
|
page read and write
|
||
280000
|
unkown
|
page read and write
|
||
280000
|
unkown
|
page read and write
|
||
280000
|
unkown
|
page read and write
|
||
638000
|
heap private
|
page read and write
|
||
200000
|
heap default
|
page read and write
|
||
48D2000
|
heap private
|
page read and write
|
||
56F2000
|
unkown
|
page readonly
|
||
5C0000
|
unkown
|
page read and write
|
||
5B0000
|
unkown
|
page read and write
|
||
280000
|
unkown
|
page read and write
|
||
285000
|
unkown
|
page read and write
|
||
57D9000
|
unkown
|
page readonly
|
||
285000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
5B0000
|
unkown
|
page read and write
|
||
760000
|
unkown
|
page read and write
|
||
4E70000
|
unkown
|
page readonly
|
||
24A6000
|
unkown
|
page read and write
|
||
4E0000
|
unkown
|
page read and write
|
||
990000
|
unkown
|
page readonly
|
||
5A60000
|
unkown
|
page readonly
|
||
20000
|
unkown
|
page read and write
|
||
455000
|
unkown
|
page read and write
|
||
48B4000
|
heap private
|
page read and write
|
||
AC0000
|
unkown
|
page read and write
|
||
F0000
|
unkown
|
page read and write
|
||
7E0000
|
unkown
|
page read and write
|
||
600000
|
heap private
|
page execute and read and write
|
||
225E000
|
unkown
|
page read and write | page guard
|
||
790000
|
heap private
|
page execute and read and write
|
||
AD5000
|
unkown
|
page read and write
|
||
42C000
|
heap default
|
page read and write
|
||
4FD000
|
heap default
|
page read and write
|
||
5C0000
|
unkown
|
page read and write
|
||
5F0000
|
unkown
|
page read and write
|
||
290000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
21ED000
|
unkown
|
page read and write
|
||
AC0000
|
unkown
|
page read and write
|
||
5782000
|
unkown
|
page readonly
|
||
AF0000
|
unkown image
|
page readonly
|
||
400000
|
unkown
|
page execute and read and write
|
||
4B7D000
|
unkown
|
page read and write
|
||
28B000
|
unkown
|
page read and write
|
||
4F0000
|
heap default
|
page read and write
|
||
57CF000
|
unkown
|
page read and write
|
||
4A0000
|
unkown
|
page read and write
|
||
4CE000
|
heap default
|
page read and write
|
||
760000
|
unkown
|
page read and write
|
||
5E0000
|
unkown
|
page read and write
|
||
4E8000
|
unkown
|
page read and write
|
||
455000
|
unkown
|
page read and write
|
||
455000
|
unkown
|
page read and write
|
||
5B0000
|
unkown
|
page read and write
|
||
455000
|
unkown
|
page read and write
|
||
197000
|
unkown
|
page execute and read and write
|
||
809000
|
heap private
|
page read and write
|
||
AF0000
|
unkown image
|
page readonly
|
||
80000
|
unkown
|
page readonly
|
||
AF2000
|
unkown image
|
page execute read
|
||
7EFDF000
|
unkown
|
page read and write
|
||
5670000
|
unkown
|
page read and write
|
||
5150000
|
unkown
|
page readonly
|
||
12D000
|
unkown
|
page execute and read and write
|
||
6FAA000
|
unkown
|
page read and write
|
||
5F1000
|
unkown
|
page read and write
|
||
5822000
|
unkown
|
page readonly
|
||
AA0000
|
unkown
|
page readonly
|
||
5C00000
|
unkown
|
page read and write
|
||
48B0000
|
heap private
|
page read and write
|
||
3F0000
|
unkown
|
page readonly
|
||
450000
|
unkown
|
page read and write
|
||
6F65000
|
unkown
|
page read and write
|
||
5F0000
|
unkown
|
page read and write
|
||
54F8000
|
unkown
|
page readonly
|
||
6C6E000
|
stack
|
page read and write
|
||
285000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
532E000
|
unkown
|
page read and write
|
||
760000
|
unkown
|
page read and write
|
||
12D000
|
unkown
|
page execute and read and write
|
||
57C5000
|
unkown
|
page readonly
|
||
22D0000
|
unkown
|
page read and write
|
||
1D0000
|
unkown
|
page read and write
|
||
5B0000
|
unkown
|
page read and write
|
||
280000
|
unkown
|
page read and write
|
||
1FA0000
|
unkown
|
page read and write
|
||
451000
|
unkown
|
page read and write
|
||
455000
|
unkown
|
page read and write
|
||
140000
|
unkown
|
page read and write
|
||
5E5E000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
7F0000
|
unkown
|
page read and write
|
||
455000
|
unkown
|
page read and write
|
||
3361000
|
unkown
|
page read and write
|
||
760000
|
unkown
|
page read and write
|
||
AF0000
|
unkown image
|
page readonly
|
||
860000
|
unkown
|
page readonly
|
||
7EFDF000
|
unkown
|
page read and write
|
||
780000
|
unkown
|
page read and write
|
||
5B0000
|
unkown
|
page read and write
|
||
3E0000
|
unkown
|
page execute and read and write
|
||
450000
|
unkown
|
page read and write
|
||
19B000
|
unkown
|
page execute and read and write
|
||
4FC0000
|
unkown
|
page read and write
|
||
124000
|
unkown
|
page read and write
|
||
680000
|
heap private
|
page read and write
|
||
280000
|
unkown
|
page read and write
|
||
285000
|
unkown
|
page read and write
|
||
192000
|
unkown
|
page read and write
|
||
AB0000
|
unkown
|
page read and write
|
||
760000
|
unkown
|
page read and write
|
||
285000
|
unkown
|
page read and write
|
||
5AE6000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
6F61000
|
unkown
|
page read and write
|
||
245B000
|
unkown
|
page read and write
|
||
197000
|
unkown
|
page execute and read and write
|
||
5752000
|
unkown
|
page readonly
|
||
4A0000
|
unkown
|
page read and write
|
||
AC0000
|
unkown
|
page read and write
|
||
760000
|
unkown
|
page read and write
|
||
AC1000
|
unkown
|
page read and write
|
||
4993000
|
unkown
|
page read and write
|
||
59F000
|
heap default
|
page read and write
|
||
AD0000
|
unkown
|
page read and write
|
||
6F7A000
|
unkown
|
page read and write
|
||
280000
|
unkown
|
page read and write
|
||
AE0000
|
unkown
|
page read and write
|
||
21AE000
|
unkown
|
page read and write
|
||
1FC0000
|
heap private
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
5B80000
|
unkown
|
page read and write
|
||
192000
|
unkown
|
page read and write
|
||
9A0000
|
unkown
|
page read and write
|
||
18A000
|
unkown
|
page execute and read and write
|
||
5B0000
|
unkown
|
page execute and read and write
|
||
285000
|
unkown
|
page read and write
|
||
16B000
|
unkown
|
page read and write
|
||
5A9000
|
heap default
|
page read and write
|
||
685E000
|
stack
|
page read and write
|
||
5B0000
|
unkown
|
page read and write
|
||
285000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
4CD0000
|
heap private
|
page read and write
|
||
146000
|
unkown
|
page execute and read and write
|
||
285000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
5F6E000
|
stack
|
page read and write
|
||
49C3000
|
unkown
|
page read and write
|
||
285000
|
unkown
|
page read and write
|
||
455000
|
unkown
|
page read and write
|
||
6300000
|
heap private
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
488E000
|
unkown
|
page read and write
|
||
123000
|
unkown
|
page execute and read and write
|
||
368000
|
stack
|
page read and write
|
||
AA0000
|
unkown
|
page read and write
|
||
56C000
|
heap default
|
page read and write
|
||
66B0000
|
heap private
|
page read and write
|
||
5B0000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
630000
|
heap private
|
page read and write
|
||
290000
|
unkown
|
page read and write
|
||
4BBD000
|
unkown
|
page read and write
|
||
2D0000
|
unkown
|
page read and write
|
||
280000
|
unkown
|
page read and write
|
||
260000
|
unkown
|
page read and write
|
||
46A0000
|
unkown
|
page readonly
|
||
57B2000
|
unkown
|
page readonly
|
||
783000
|
unkown
|
page read and write
|
||
285000
|
unkown
|
page read and write
|
||
280000
|
unkown
|
page read and write
|
||
455000
|
unkown
|
page read and write
|
There are 529 hidden memdumps, click here to show them.