IOCReport

loading gif

Files

File Path
Type
Category
Malicious
Original title deed.xlsx
CDFV2 Encrypted
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\nd[1].exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
downloaded
malicious
C:\Users\user\AppData\Roaming\EA860E7A-A87F-4A88-92EF-38F744458171\run.dat
data
dropped
malicious
C:\Users\user\Desktop\~$Original title deed.xlsx
data
dropped
malicious
C:\Users\Public\vbc.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\A830D3DD.emf
Windows Enhanced Metafile (EMF) image data version 0x10000
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\AF79D03A.jpeg
gd-jpeg v1.0 (using IJG JPEG v80), quality = 90", baseline, precision 8, 700x990, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\C7D0AEF3.jpeg
gd-jpeg v1.0 (using IJG JPEG v80), quality = 90", baseline, precision 8, 700x990, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\DEE6A84C.emf
Windows Enhanced Metafile (EMF) image data version 0x10000
dropped
clean
C:\Users\user\AppData\Roaming\EA860E7A-A87F-4A88-92EF-38F744458171\catalog.dat
data
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
'C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE' -Embedding
malicious
C:\Users\Public\vbc.exe
'C:\Users\Public\vbc.exe'
malicious
C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
clean

URLs

Name
IP
Malicious
79.134.225.26
malicious
nassiru1166main.ddns.net
malicious
http://myhostisstillgood11.zapto.org/dashboard/docs/images/nd.exe
172.245.45.28
malicious
http://www.%s.comPA
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://www.day.com/dam/1.0
unknown
clean
https://github.com/unguest
unknown
clean
https://stackpath.bootstrapcdn.com/bootstrap/4.5.0/css/bootstrap.min.css
unknown
clean
https://github.com/unguest9WinForms_RecursiveFormCreate5WinForms_SeeInnerExceptionGProperty
unknown
clean

Domains

Name
IP
Malicious
myhostisstillgood11.zapto.org
172.245.45.28
malicious

IPs

IP
Domain
Country
Malicious
79.134.225.26
unknown
Switzerland
malicious
172.245.45.28
myhostisstillgood11.zapto.org
United States
malicious

Registry

Path
Value
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
4a<
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
MTTT
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ReviewToken
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1096E3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
FontCachePath
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
VBAFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DefaultSheetR2L
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
UseSystemSeparators
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ThousandsSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DecimalSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
;o<
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
10E5FC
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
10F96C
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 21
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
LastPurgeTime
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EXCELFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
10E5FC
clean
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
EquationEditorFilesIntl_1033
clean
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
SavedLegacySettings
clean
There are 51 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
2100000
unkown
page read and write
malicious
402000
unkown
page execute and read and write
malicious
26EB000
unkown
page read and write
malicious
387F000
unkown
page read and write
malicious
36B1000
unkown
page read and write
malicious
901000
unkown
page read and write
clean
2235000
heap private
page execute and read and write
clean
5E12000
unkown
page read and write
clean
4D0000
unkown
page read and write
clean
18A000
unkown
page execute and read and write
clean
579000
heap private
page read and write
clean
562F000
unkown
page read and write
clean
38E4000
unkown
page read and write
clean
7EF43000
unkown
page read and write
clean
3964000
unkown
page read and write
clean
5C0000
unkown
page read and write
clean
AA0000
heap private
page read and write
clean
53BE000
unkown
page read and write
clean
3984000
unkown
page read and write
clean
69CE000
unkown
page read and write
clean
38E4000
unkown
page read and write
clean
901000
unkown
page read and write
clean
490000
unkown
page read and write
clean
AC0000
unkown
page read and write
clean
245000
unkown
page read and write
clean
901000
unkown
page read and write
clean
7EF50000
unkown
page execute and read and write
clean
901000
unkown
page read and write
clean
4E0F000
unkown
page read and write
clean
901000
unkown
page read and write
clean
3964000
unkown
page read and write
clean
38E4000
unkown
page read and write
clean
530000
heap private
page read and write
clean
283D000
unkown
page read and write
clean
4A76000
unkown
page read and write
clean
901000
unkown
page read and write
clean
3984000
unkown
page read and write
clean
240000
unkown
page readonly
clean
901000
unkown
page read and write
clean
2130000
unkown
page read and write
clean
38E4000
unkown
page read and write
clean
B10000
unkown
page read and write
clean
B16000
unkown
page read and write
clean
901000
unkown
page read and write
clean
5E11000
unkown
page read and write
clean
3984000
unkown
page read and write
clean
28A000
unkown
page execute and read and write
clean
39C4000
unkown
page read and write
clean
1A2000
unkown
page read and write
clean
204C000
unkown
page readonly
clean
2200000
unkown
page read and write
clean
901000
unkown
page read and write
clean
AB1000
unkown
page read and write
clean
570000
heap private
page read and write
clean
2754000
unkown
page read and write
clean
5E11000
unkown
page read and write
clean
38E4000
unkown
page read and write
clean
38E4000
unkown
page read and write
clean
5B0000
unkown
page read and write
clean
2138000
unkown
page read and write
clean
54FD000
unkown
page read and write
clean
39A4000
unkown
page read and write
clean
510000
unkown
page readonly
clean
4D0000
unkown
page read and write
clean
8B3000
heap default
page read and write
clean
49E0000
heap private
page read and write
clean
39E4000
unkown
page read and write
clean
2230000
heap private
page execute and read and write
clean
48EE000
unkown
page read and write
clean
3923000
unkown
page read and write
clean
240000
unkown
page read and write
clean
4D4000
unkown
page read and write
clean
3A0000
unkown
page readonly
clean
1FA000
unkown
page read and write
clean
3984000
unkown
page read and write
clean
4D7000
unkown
page read and write
clean
901000
unkown
page read and write
clean
23E0000
unkown
page readonly
clean
3964000
unkown
page read and write
clean
4F5000
unkown
page read and write
clean
490000
unkown
page read and write
clean
A0000
unkown
page readonly
clean
901000
unkown
page read and write
clean
58E000
unkown
page read and write
clean
3944000
unkown
page read and write
clean
3A24000
unkown
page read and write
clean
39A4000
unkown
page read and write
clean
2128000
unkown
page read and write
clean
270B000
unkown
page read and write
clean
39C4000
unkown
page read and write
clean
5E11000
unkown
page read and write
clean
4E8000
unkown
page read and write
clean
3964000
unkown
page read and write
clean
4E5000
unkown
page read and write
clean
2949000
unkown
page read and write
clean
3903000
unkown
page read and write
clean
20BC000
unkown
page readonly
clean
42A000
unkown
page execute and read and write
clean
3964000
unkown
page read and write
clean
170000
heap private
page read and write
clean
879000
heap default
page read and write
clean
3944000
unkown
page read and write
clean
578E000
unkown
page read and write
clean
37BF000
unkown
page read and write
clean
21E2000
heap private
page read and write
clean
8FC000
unkown
page read and write
clean
3923000
unkown
page read and write
clean
39A4000
unkown
page read and write
clean
901000
unkown
page read and write
clean
1AB000
unkown
page execute and read and write
clean
290000
unkown
page read and write
clean
7D0000
heap private
page execute and read and write
clean
3923000
unkown
page read and write
clean
AC0000
unkown
page read and write
clean
5E11000
unkown
page read and write
clean
C38000
unkown image
page readonly
clean
39E4000
unkown
page read and write
clean
5E11000
unkown
page read and write
clean
4E4E000
unkown
page read and write
clean
39C4000
unkown
page read and write
clean
2270000
unkown
page read and write
clean
4D0000
unkown
page read and write
clean
39A4000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
4E6000
unkown
page read and write
clean
21BE000
unkown
page read and write
clean
182000
unkown
page read and write
clean
240000
unkown
page read and write
clean
38E4000
unkown
page read and write
clean
538000
unkown
page read and write
clean
2130000
unkown
page read and write
clean
38E4000
unkown
page read and write
clean
4D0000
unkown
page read and write
clean
20B7000
unkown
page readonly
clean
5FE000
unkown
page read and write
clean
3944000
unkown
page read and write
clean
39A4000
unkown
page read and write
clean
B22000
unkown image
page execute read
clean
4B0000
unkown
page read and write
clean
3964000
unkown
page read and write
clean
3984000
unkown
page read and write
clean
39E4000
unkown
page read and write
clean
21C0000
heap private
page read and write
clean
4D0000
unkown
page read and write
clean
54DF000
unkown
page read and write
clean
2921000
unkown
page read and write
clean
2210000
heap private
page execute and read and write
clean
901000
unkown
page read and write
clean
3944000
unkown
page read and write
clean
589D000
unkown
page read and write
clean
282000
unkown
page execute and read and write
clean
4D0000
unkown
page read and write
clean
160000
unkown
page read and write
clean
3A6A000
unkown
page read and write
clean
5E11000
unkown
page read and write
clean
901000
unkown
page read and write
clean
4E0000
unkown
page read and write
clean
4F0000
unkown
page read and write
clean
5E0000
unkown
page read and write
clean
39C4000
unkown
page read and write
clean
4D0000
unkown
page read and write
clean
377F000
unkown
page read and write
clean
39A4000
unkown
page read and write
clean
3984000
unkown
page read and write
clean
140000
unkown
page read and write
clean
5A0000
unkown
page readonly
clean
19A000
unkown
page execute and read and write
clean
90C000
unkown
page read and write
clean
3944000
unkown
page read and write
clean
200000
unkown
page read and write
clean
5B8000
unkown
page read and write
clean
4A30000
heap private
page execute and read and write
clean
490000
unkown
page read and write
clean
500000
unkown
page read and write
clean
385F000
unkown
page read and write
clean
901000
unkown
page read and write
clean
20DB000
unkown
page readonly
clean
4F0000
unkown
page read and write
clean
4AF0000
unkown
page read and write
clean
39A4000
unkown
page read and write
clean
21C4000
heap private
page read and write
clean
21E0000
unkown
page read and write
clean
38E4000
unkown
page read and write
clean
2270000
unkown
page read and write
clean
270000
unkown
page read and write
clean
AC0000
unkown
page read and write
clean
AC0000
unkown
page read and write
clean
5E11000
unkown
page read and write
clean
375F000
unkown
page read and write
clean
2130000
unkown
page read and write
clean
4F0000
unkown
page readonly
clean
39C4000
unkown
page read and write
clean
901000
unkown
page read and write
clean
900000
unkown
page read and write
clean
58A0000
unkown
page write copy
clean
2140000
unkown
page read and write
clean
4E0000
unkown
page read and write
clean
901000
unkown
page read and write
clean
580000
unkown
page read and write
clean
2136000
unkown
page read and write
clean
63A000
heap default
page read and write
clean
3903000
unkown
page read and write
clean
590000
unkown
page read and write
clean
490000
unkown
page readonly
clean
900000
unkown
page read and write
clean
4BF0000
unkown
page read and write
clean
911000
unkown
page read and write
clean
4A0D000
unkown
page read and write
clean
4D0000
unkown
page read and write
clean
1A7000
unkown
page read and write
clean
901000
unkown
page read and write
clean
39C4000
unkown
page read and write
clean
2279000
unkown
page read and write
clean
C50000
unkown
page readonly
clean
422000
unkown
page execute and read and write
clean
3924000
unkown
page read and write
clean
901000
unkown
page read and write
clean
3944000
unkown
page read and write
clean
3944000
unkown
page read and write
clean
4F0000
unkown
page read and write
clean
2723000
unkown
page read and write
clean
4E0000
unkown
page read and write
clean
39C4000
unkown
page read and write
clean
901000
unkown
page read and write
clean
AB0000
unkown
page read and write
clean
292000
unkown
page execute and read and write
clean
820000
unkown
page read and write
clean
346000
unkown
page read and write
clean
4D0000
unkown
page read and write
clean
206B000
unkown
page readonly
clean
4A37000
heap private
page execute and read and write
clean
6B6E000
unkown
page read and write
clean
3903000
unkown
page read and write
clean
39A4000
unkown
page read and write
clean
490000
unkown
page read and write
clean
241000
unkown
page read and write
clean
3923000
unkown
page read and write
clean
383F000
unkown
page read and write
clean
4D0000
unkown
page read and write
clean
4D6000
unkown
page read and write
clean
4D0000
unkown
page read and write
clean
38E3000
unkown
page read and write
clean
5E11000
unkown
page read and write
clean
5E11000
unkown
page read and write
clean
493000
unkown
page read and write
clean
5E11000
unkown
page read and write
clean
5E11000
unkown
page read and write
clean
3984000
unkown
page read and write
clean
4D0000
unkown
page read and write
clean
3944000
unkown
page read and write
clean
901000
unkown
page read and write
clean
4C0000
unkown
page execute and read and write
clean
8B6000
unkown
page read and write
clean
38E4000
unkown
page read and write
clean
780000
unkown
page read and write
clean
39A4000
unkown
page read and write
clean
5B0000
unkown
page readonly
clean
3984000
unkown
page read and write
clean
3964000
unkown
page read and write
clean
2691000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
240000
unkown
page read and write
clean
5E11000
unkown
page read and write
clean
41A000
unkown
page execute and read and write
clean
8F2000
unkown
page read and write
clean
490000
unkown
page read and write
clean
90C000
unkown
page read and write
clean
4D0000
unkown
page read and write
clean
3903000
unkown
page read and write
clean
4D0000
unkown
page read and write
clean
5E12000
unkown
page read and write
clean
4D6000
unkown
page read and write
clean
790000
unkown
page read and write
clean
39E4000
unkown
page read and write
clean
901000
unkown
page read and write
clean
5BFE000
unkown
page read and write
clean
9B0000
unkown
page readonly
clean
162000
unkown
page execute and read and write
clean
39C4000
unkown
page read and write
clean
3923000
unkown
page read and write
clean
930000
unkown
page readonly
clean
2170000
unkown
page read and write
clean
810000
unkown
page readonly
clean
180000
unkown
page read and write
clean
417000
unkown
page execute and read and write
clean
3964000
unkown
page read and write
clean
21F0000
unkown
page read and write
clean
38E4000
unkown
page read and write
clean
8B8000
unkown
page read and write
clean
2252000
heap private
page execute and read and write
clean
2A7000
heap default
page read and write
clean
5E12000
unkown
page read and write
clean
3944000
unkown
page read and write
clean
913000
unkown
page read and write
clean
3903000
unkown
page read and write
clean
472E000
unkown
page read and write
clean
500000
unkown
page read and write
clean
5E11000
unkown
page read and write
clean
3984000
unkown
page read and write
clean
130000
unkown
page read and write
clean
5E11000
unkown
page read and write
clean
2E8000
heap default
page read and write
clean
3944000
unkown
page read and write
clean
3964000
unkown
page read and write
clean
AB0000
unkown
page readonly
clean
1C0000
unkown
page readonly
clean
901000
unkown
page read and write
clean
910000
unkown
page read and write
clean
52BF000
unkown
page read and write
clean
3944000
unkown
page read and write
clean
20000
unkown
page read and write
clean
48BF000
unkown
page read and write
clean
120000
unkown
page read and write
clean
371F000
unkown
page read and write
clean
2160000
unkown
page read and write
clean
5E11000
unkown
page read and write
clean
190000
unkown
page read and write
clean
110000
unkown
page readonly
clean
600000
unkown
page read and write
clean
4D0000
unkown
page read and write
clean
3903000
unkown
page read and write
clean
7C0000
unkown
page execute and read and write
clean
901000
unkown
page read and write
clean
5E12000
unkown
page read and write
clean
3944000
unkown
page read and write
clean
3963000
unkown
page read and write
clean
854000
heap default
page read and write
clean
8FF000
unkown
page read and write
clean
480000
heap private
page read and write
clean
B10000
unkown
page read and write
clean
20000
unkown
page read and write
clean
3903000
unkown
page read and write
clean
39C4000
unkown
page read and write
clean
901000
unkown
page read and write
clean
3A84000
unkown
page read and write
clean
3903000
unkown
page read and write
clean
4D5000
unkown
page read and write
clean
901000
unkown
page read and write
clean
296E000
unkown
page read and write
clean
39E4000
unkown
page read and write
clean
39A4000
unkown
page read and write
clean
1A6000
unkown
page read and write | page guard
clean
39C4000
unkown
page read and write
clean
642F000
unkown
page read and write
clean
490000
unkown
page read and write
clean
5E11000
unkown
page read and write
clean
39E4000
unkown
page read and write
clean
3984000
unkown
page read and write
clean
450000
unkown
page read and write
clean
7EF4C000
unkown
page read and write
clean
7A0000
unkown
page read and write
clean
490000
unkown
page read and write
clean
901000
unkown
page read and write
clean
4D0000
unkown
page read and write
clean
2047000
unkown
page readonly
clean
2150000
unkown
page execute and read and write
clean
490000
unkown
page execute and read and write
clean
4E0000
unkown
page read and write
clean
AC0000
unkown
page read and write
clean
901000
unkown
page read and write
clean
5E11000
unkown
page read and write
clean
5E11000
unkown
page read and write
clean
36DE000
unkown
page read and write
clean
37DF000
unkown
page read and write
clean
484E000
unkown
page read and write
clean
291D000
unkown
page read and write
clean
4A1C000
unkown
page read and write
clean
620000
heap default
page read and write
clean
39A4000
unkown
page read and write
clean
520000
unkown
page read and write
clean
520000
unkown
page read and write
clean
3923000
unkown
page read and write
clean
4D6000
unkown
page read and write
clean
19C000
unkown
page execute and read and write
clean
3924000
unkown
page read and write
clean
837000
heap default
page read and write
clean
AC0000
unkown
page read and write
clean
3903000
unkown
page read and write
clean
2270000
unkown
page read and write
clean
498000
unkown
page read and write
clean
5E11000
unkown
page read and write
clean
2040000
unkown
page readonly
clean
901000
unkown
page read and write
clean
4D6000
unkown
page read and write
clean
490000
unkown
page read and write
clean
2120000
unkown
page read and write
clean
437000
unkown
page execute and read and write
clean
487C000
unkown
page read and write
clean
400000
unkown
page execute and read and write
clean
4D0000
unkown
page read and write
clean
39C4000
unkown
page read and write
clean
4D6000
unkown
page read and write
clean
5E12000
unkown
page read and write
clean
4B0000
unkown
page write copy
clean
63C000
heap default
page read and write
clean
490000
unkown
page read and write
clean
3903000
unkown
page read and write
clean
3923000
unkown
page read and write
clean
5E11000
unkown
page read and write
clean
910000
unkown
page read and write
clean
901000
unkown
page read and write
clean
4D0000
unkown
page read and write
clean
2270000
unkown
page read and write
clean
38E4000
unkown
page read and write
clean
3923000
unkown
page read and write
clean
5C50000
heap private
page read and write
clean
3984000
unkown
page read and write
clean
610000
unkown
page read and write
clean
4D5000
unkown
page read and write
clean
4690000
unkown
page read and write
clean
240000
unkown
page read and write
clean
901000
unkown
page read and write
clean
4F0000
unkown
page read and write
clean
5B0000
unkown
page read and write
clean
1A7000
unkown
page execute and read and write
clean
2135000
unkown
page read and write
clean
4A70000
unkown
page read and write
clean
4D0000
unkown
page read and write
clean
530000
unkown
page read and write
clean
39C4000
unkown
page read and write
clean
39A4000
unkown
page read and write
clean
2137000
unkown
page read and write
clean
38E4000
unkown
page read and write
clean
AB0000
unkown
page read and write
clean
B0C000
unkown
page read and write
clean
3903000
unkown
page read and write
clean
2050000
unkown
page readonly
clean
2120000
unkown
page execute and read and write
clean
4D6000
unkown
page read and write
clean
3984000
unkown
page read and write
clean
39C4000
unkown
page read and write
clean
3944000
unkown
page read and write
clean
230000
unkown
page read and write
clean
632000
heap default
page read and write
clean
373F000
unkown
page read and write
clean
C38000
unkown image
page readonly
clean
650000
heap private
page execute and read and write
clean
B20000
unkown image
page readonly
clean
39C4000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
3903000
unkown
page read and write
clean
39A4000
unkown
page read and write
clean
5E11000
unkown
page read and write
clean
240000
unkown
page read and write
clean
3984000
unkown
page read and write
clean
46B0000
unkown
page read and write
clean
3964000
unkown
page read and write
clean
7EF50000
unkown
page execute and read and write
clean
901000
unkown
page read and write
clean
6A0000
unkown
page readonly
clean
420000
unkown
page read and write
clean
291F000
unkown
page read and write
clean
2120000
unkown
page read and write
clean
8F3000
unkown
page read and write
clean
483D000
unkown
page read and write
clean
911000
unkown
page read and write
clean
520000
unkown
page read and write
clean
901000
unkown
page read and write
clean
39C4000
unkown
page read and write
clean
3964000
unkown
page read and write
clean
2C4000
heap default
page read and write
clean
4D0000
unkown
page read and write
clean
49F0000
unkown
page read and write
clean
192000
unkown
page execute and read and write
clean
4D0000
unkown
page read and write
clean
4BBE000
unkown
page read and write
clean
39C4000
unkown
page read and write
clean
23DF000
unkown
page read and write
clean
46B0000
unkown
page read and write
clean
4D0000
unkown
page read and write
clean
540000
heap private
page read and write
clean
20F0000
unkown
page read and write
clean
43B000
unkown
page execute and read and write
clean
810000
unkown
page read and write
clean
2A0000
heap default
page read and write
clean
358000
unkown
page read and write
clean
5E12000
unkown
page read and write
clean
220000
unkown
page readonly
clean
534000
heap private
page read and write
clean
5E10000
unkown
page read and write
clean
2130000
unkown
page read and write
clean
4E8E000
unkown
page read and write
clean
23C0000
unkown
page readonly
clean
39A4000
unkown
page read and write
clean
2090000
unkown
page readonly
clean
39A4000
unkown
page read and write
clean
29C000
unkown
page execute and read and write
clean
4E0000
unkown
page read and write
clean
3964000
unkown
page read and write
clean
3984000
unkown
page read and write
clean
46FE000
unkown
page read and write
clean
5E11000
unkown
page read and write
clean
39C4000
unkown
page read and write
clean
790000
unkown
page read and write
clean
3984000
unkown
page read and write
clean
6F60000
unkown
page read and write
clean
53C0000
heap private
page read and write
clean
4A0000
unkown
page execute and read and write
clean
901000
unkown
page read and write
clean
2120000
unkown
page read and write
clean
A90000
unkown
page execute and read and write
clean
470000
unkown
page readonly
clean
901000
unkown
page read and write
clean
3984000
unkown
page read and write
clean
491000
unkown
page read and write
clean
38E4000
unkown
page read and write
clean
23BF000
unkown
page read and write
clean
4D0000
unkown
page read and write
clean
490000
unkown
page read and write
clean
8F3000
unkown
page read and write
clean
2270000
unkown
page read and write
clean
20B0000
unkown
page readonly
clean
4D0000
unkown
page read and write
clean
3903000
unkown
page read and write
clean
3964000
unkown
page read and write
clean
643000
heap default
page read and write
clean
4D0000
unkown
page read and write
clean
2150000
unkown
page read and write
clean
901000
unkown
page read and write
clean
5E11000
unkown
page read and write
clean
901000
unkown
page read and write
clean
8F7000
unkown
page read and write
clean
2170000
unkown
page read and write
clean
3964000
unkown
page read and write
clean
AB0000
unkown
page read and write
clean
3944000
unkown
page read and write
clean
39A4000
unkown
page read and write
clean
3964000
unkown
page read and write
clean
3964000
unkown
page read and write
clean
460000
unkown
page readonly
clean
50CD000
unkown
page read and write
clean
3984000
unkown
page read and write
clean
3984000
unkown
page read and write
clean
3A04000
unkown
page read and write
clean
210000
unkown
page readonly
clean
5B2D000
unkown
page read and write
clean
3A64000
unkown
page read and write
clean
590000
unkown
page execute and read and write
clean
3904000
unkown
page read and write
clean
37FF000
unkown
page read and write
clean
4D0000
unkown
page read and write
clean
3923000
unkown
page read and write
clean
4F80000
unkown
page readonly
clean
23BE000
unkown
page read and write | page guard
clean
2250000
unkown
page read and write
clean
3984000
unkown
page read and write
clean
4D6000
unkown
page read and write
clean
4E0000
unkown
page execute and read and write
clean
8FC000
unkown
page read and write
clean
60BE000
unkown
page read and write
clean
911000
unkown
page read and write
clean
3BD7000
unkown
page read and write
clean
4D00000
unkown
page read and write
clean
510000
unkown
page read and write
clean
3F0000
unkown
page execute and read and write
clean
7EF49000
unkown
page read and write
clean
2275000
unkown
page read and write
clean
49DE000
unkown
page read and write
clean
90F000
unkown
page read and write
clean
3924000
unkown
page read and write
clean
543D000
unkown
page read and write
clean
5B0000
unkown
page read and write
clean
490000
unkown
page read and write
clean
5E11000
unkown
page read and write
clean
39A4000
unkown
page read and write
clean
4D7000
unkown
page read and write
clean
8EE000
heap default
page read and write
clean
3964000
unkown
page read and write
clean
3691000
unkown
page read and write
clean
4D0000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
7B8000
heap private
page read and write
clean
4D0000
unkown
page read and write
clean
600000
unkown
page read and write
clean
3924000
unkown
page read and write
clean
4A54000
heap private
page execute and read and write
clean
590000
unkown
page read and write
clean
5B0000
unkown
page read and write
clean
520000
unkown
page read and write
clean
4A8D000
unkown
page read and write
clean
4D0000
unkown
page read and write
clean
681E000
unkown
page read and write
clean
36FF000
unkown
page read and write
clean
3924000
unkown
page read and write
clean
690000
unkown
page readonly
clean
4CEF000
unkown
page read and write
clean
5E11000
unkown
page read and write
clean
2130000
unkown
page read and write
clean
22BE000
unkown
page read and write
clean
229E000
unkown
page read and write
clean
186000
unkown
page execute and read and write
clean
AB000
unkown
page read and write
clean
8BB000
unkown
page read and write
clean
7B0000
heap private
page read and write
clean
5A1000
unkown
page read and write
clean
B22000
unkown image
page execute read
clean
552000
heap private
page read and write
clean
3923000
unkown
page read and write
clean
4E0E000
unkown
page read and write | page guard
clean
152000
unkown
page execute and read and write
clean
5B0000
unkown
page read and write
clean
4DC000
unkown
page read and write
clean
3A44000
unkown
page read and write
clean
39C4000
unkown
page read and write
clean
38E4000
unkown
page read and write
clean
3944000
unkown
page read and write
clean
36B6000
unkown
page read and write
clean
3964000
unkown
page read and write
clean
1F0000
heap default
page read and write
clean
7190000
unkown
page read and write
clean
62E000
unkown
page read and write
clean
5E12000
unkown
page read and write
clean
15A000
unkown
page execute and read and write
clean
B20000
unkown image
page readonly
clean
4D0000
unkown
page read and write
clean
3903000
unkown
page read and write
clean
7B6000
heap private
page read and write
clean
4FBE000
unkown
page read and write
clean
52BE000
unkown
page read and write | page guard
clean
26B1000
unkown
page read and write
clean
3923000
unkown
page read and write
clean
2789000
unkown
page read and write
clean
3944000
unkown
page read and write
clean
2270000
unkown
page read and write
clean
4D5000
unkown
page read and write
clean
381F000
unkown
page read and write
clean
2130000
unkown
page read and write
clean
3923000
unkown
page read and write
clean
3984000
unkown
page read and write
clean
901000
unkown
page read and write
clean
B20000
unkown image
page readonly
clean
662E000
unkown
page read and write
clean
5E12000
unkown
page read and write
clean
38E4000
unkown
page read and write
clean
39E4000
unkown
page read and write
clean
630000
unkown
page read and write
clean
4D0000
unkown
page read and write
clean
39A4000
unkown
page read and write
clean
31D000
heap default
page read and write
clean
4E0000
unkown
page read and write
clean
8FE000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
3923000
unkown
page read and write
clean
537000
unkown
page read and write
clean
422000
unkown
page execute and read and write
clean
901000
unkown
page read and write
clean
4D0000
unkown
page read and write
clean
5E11000
unkown
page read and write
clean
39C4000
unkown
page read and write
clean
39A4000
unkown
page read and write
clean
39E4000
unkown
page read and write
clean
2140000
unkown
page read and write
clean
2160000
unkown
page read and write
clean
5D2E000
unkown
page read and write
clean
4F4E000
unkown
page read and write
clean
2200000
unkown
page read and write
clean
3964000
unkown
page read and write
clean
5E12000
unkown
page read and write
clean
5E11000
unkown
page read and write
clean
39C4000
unkown
page read and write
clean
830000
heap default
page read and write
clean
901000
unkown
page read and write
clean
4F7000
unkown
page read and write
clean
3944000
unkown
page read and write
clean
3903000
unkown
page read and write
clean
5A1000
unkown
page read and write
clean
5E11000
unkown
page read and write
clean
3944000
unkown
page read and write
clean
3944000
unkown
page read and write
clean
530000
unkown
page read and write
clean
AC0000
unkown
page read and write
clean
2130000
unkown
page read and write
clean
530000
unkown
page read and write
clean
There are 663 hidden memdumps, click here to show them.