IOCReport

loading gif

Files

File Path
Type
Category
Malicious
shorefront.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{B147A46E-C485-11EB-90EB-ECF4BBEA1588}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{B147A470-C485-11EB-90EB-ECF4BBEA1588}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{B147A472-C485-11EB-90EB-ECF4BBEA1588}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\NewErrorPageTemplate[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\dnserror[1]
HTML document, UTF-8 Unicode (with BOM) text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\down[1]
PNG image data, 15 x 15, 8-bit colormap, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\errorPageStrings[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\httpErrorPagesScripts[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\down[1]
PNG image data, 15 x 15, 8-bit colormap, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\httpErrorPagesScripts[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\NewErrorPageTemplate[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\dnserror[1]
HTML document, UTF-8 Unicode (with BOM) text, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\errorPageStrings[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Temp\JavaDeployReg.log
ASCII text, with CRLF line terminators
modified
clean
C:\Users\user\AppData\Local\Temp\~DF2325E3FA7AA39907.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DF762A57E90D6A65CD.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DF896FBAE33087E32E.TMP
data
dropped
clean
There are 8 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Windows\System32\loaddll32.exe
loaddll32.exe 'C:\Users\user\Desktop\shorefront.dll'
malicious
C:\Windows\SysWOW64\rundll32.exe
rundll32.exe C:\Users\user\Desktop\shorefront.dll,Child
malicious
C:\Windows\SysWOW64\rundll32.exe
rundll32.exe 'C:\Users\user\Desktop\shorefront.dll',#1
malicious
C:\Windows\SysWOW64\rundll32.exe
rundll32.exe C:\Users\user\Desktop\shorefront.dll,Forcearea
malicious
C:\Windows\SysWOW64\rundll32.exe
rundll32.exe C:\Users\user\Desktop\shorefront.dll,Stationmeat
malicious
C:\Windows\SysWOW64\cmd.exe
cmd.exe /C rundll32.exe 'C:\Users\user\Desktop\shorefront.dll',#1
clean
C:\Program Files\internet explorer\iexplore.exe
'C:\Program Files\Internet Explorer\iexplore.exe' -Embedding
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:816 CREDAT:17410 /prefetch:2
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:816 CREDAT:17414 /prefetch:2
clean

URLs

Name
IP
Malicious
http://app.buboleinov.com/7dGVcD7hOw3lYt5/1yqoO_2BT5cAFQCvp3/7fGu2bPOM/Y70HlHuovLn2gp_2B2GH/4_2FYxaP
unknown
malicious
http://app.buboleinov.com/BHxjQVeA3bCRL3A0U_2Bhx/6Mf2XW6xM9nlO/OBBDiHLG/gVHcEz5iH6i5Er6PkMAnMWX/IOi2
unknown
malicious

Domains

Name
IP
Malicious
app.buboleinov.com
unknown
malicious

Registry

Path
Value
Malicious
C:\Program Files\internet explorer\iexplore.exe
{B147A46E-C485-11EB-90EB-ECF4BBEA1588}
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
Blocked
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\internet explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\internet explorer\iexplore.exe
Window_Placement
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
Blocked
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\internet explorer\iexplore.exe
DecayDateQueue
clean
C:\Program Files\internet explorer\iexplore.exe
LastProcessed
clean
There are 12 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
530000
unkown
page execute and read and write
malicious
2FE8000
heap private
page read and write
malicious
50E8000
heap private
page read and write
malicious
2FE8000
heap private
page read and write
malicious
2FE8000
heap private
page read and write
malicious
50E8000
heap private
page read and write
malicious
2FE8000
heap private
page read and write
malicious
2FE8000
heap private
page read and write
malicious
50E8000
heap private
page read and write
malicious
50E8000
heap private
page read and write
malicious
2FE8000
heap private
page read and write
malicious
30E0000
unkown
page execute and read and write
malicious
27F0000
unkown
page execute and read and write
malicious
2220000
unkown
page execute and read and write
malicious
3210000
unkown
page execute and read and write
malicious
50E8000
heap private
page read and write
malicious
50E8000
heap private
page read and write
malicious
2FE8000
heap private
page read and write
malicious
50E8000
heap private
page read and write
malicious
2FE8000
heap private
page read and write
malicious
50E8000
heap private
page read and write
malicious
2FE8000
heap private
page read and write
malicious
50E8000
heap private
page read and write
malicious
2057000
unkown
page readonly
clean
205D000
unkown
page readonly
clean
3423000
unkown
page read and write
clean
4779000
unkown
page readonly
clean
3150000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
4BCE000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
4F89000
heap private
page read and write
clean
7FF5D9CD5000
unkown
page readonly
clean
2B85000
unkown
page readonly
clean
7FF5D9D91000
unkown
page readonly
clean
4F0000
unkown
page read and write
clean
160000
unkown
page readonly
clean
22B3000
unkown
page read and write
clean
7FF5B3DCA000
unkown
page readonly
clean
3250000
unkown
page read and write
clean
5CA0000
unkown
page readonly
clean
3250000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
9D000
unkown
page read and write
clean
7FF5D9CD1000
unkown
page readonly
clean
2220000
unkown
page read and write
clean
4E0000
unkown
page execute and read and write
clean
32A0000
unkown
page read and write
clean
7FF52DE2C000
unkown
page readonly
clean
1DF7000
unkown
page readonly
clean
3250000
unkown
page read and write
clean
3181000
unkown
page execute read
clean
1F6B000
unkown
page readonly
clean
605E000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
32A0000
unkown
page read and write
clean
3150000
unkown
page read and write
clean
2BF0000
heap private
page read and write
clean
46E0000
unkown
page read and write
clean
2FEA000
heap private
page read and write
clean
2260000
unkown
page read and write
clean
7FF5D9EE8000
unkown
page readonly
clean
4810000
unkown
page readonly
clean
32A0000
unkown
page read and write
clean
7FF5D9EF4000
unkown
page readonly
clean
2220000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
4F0000
unkown
page read and write
clean
4F0000
unkown
page read and write
clean
46E0000
unkown
page read and write
clean
32A0000
unkown
page read and write
clean
7FF5B3DAC000
unkown
page readonly
clean
21605B13000
unkown
page read and write
clean
46DF000
unkown
page read and write
clean
2071000
unkown
page readonly
clean
3423000
unkown
page read and write
clean
60A0000
unkown
page read and write
clean
46E0000
unkown
page read and write
clean
2FE0000
unkown
page readonly
clean
477C000
unkown
page readonly
clean
2936000
heap default
page read and write
clean
6C500000
unkown image
page readonly
clean
7FF52E19F000
unkown
page readonly
clean
2220000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
205F000
unkown
page readonly
clean
2844000
unkown
page readonly
clean
7FF52E19C000
unkown
page readonly
clean
2B8D000
unkown
page readonly
clean
7FF5D9F26000
unkown
page readonly
clean
2A168F40000
unkown
page readonly
clean
3150000
unkown
page read and write
clean
2993000
unkown
page readonly
clean
7FF5D9F2D000
unkown
page readonly
clean
2DF0000
unkown
page execute and read and write
clean
295C000
unkown
page readonly
clean
4CF0000
heap private
page read and write
clean
21605A56000
unkown
page read and write
clean
3421000
unkown
page read and write
clean
6D8000
unkown
page read and write
clean
21605B02000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
2C33000
unkown
page readonly
clean
3250000
unkown
page read and write
clean
3150000
unkown
page read and write
clean
22A8000
unkown
page read and write
clean
3110000
unkown
page read and write
clean
1ADBF848000
unkown
page read and write
clean
318A000
unkown
page read and write
clean
32A0000
unkown
page read and write
clean
46E0000
unkown
page read and write
clean
7FF5B3DE8000
unkown
page readonly
clean
2A168261000
unkown
page read and write
clean
3150000
unkown
page read and write
clean
23D2EFA000
unkown
page read and write
clean
7FF52E254000
unkown
page readonly
clean
2086000
unkown
page readonly
clean
3250000
unkown
page read and write
clean
2FEB000
heap private
page read and write
clean
7FF52E051000
unkown
page readonly
clean
2925000
unkown
page read and write
clean
4F80000
heap private
page read and write
clean
2933000
unkown
page readonly
clean
342D000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
2A16823C000
unkown
page read and write
clean
1FF9000
unkown
page readonly
clean
3418000
unkown
page read and write
clean
1FC4000
unkown
page readonly
clean
679000
heap default
page read and write
clean
3373000
unkown
page read and write
clean
2A05000
unkown
page readonly
clean
3250000
unkown
page read and write
clean
46E0000
unkown
page read and write
clean
2670000
unkown
page readonly
clean
7FF5D9EFA000
unkown
page readonly
clean
4F0000
unkown
page read and write
clean
2B33000
unkown
page readonly
clean
4F0000
unkown
page read and write
clean
7FF5D9F1E000
unkown
page readonly
clean
6C506000
unkown image
page readonly
clean
4F0000
unkown
page read and write
clean
46E0000
unkown
page read and write
clean
22A5000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
A75F6FE000
unkown
page read and write
clean
2A168170000
heap private
page read and write
clean
2A16822A000
unkown
page read and write
clean
26D0000
unkown
page readonly
clean
3250000
unkown
page read and write
clean
7FF5B3DAF000
unkown
page readonly
clean
2A1684D0000
unkown
page readonly
clean
6EDE000
unkown
page read and write
clean
1F62000
unkown
page readonly
clean
3374000
heap default
page read and write
clean
1ADBFAD0000
unkown
page readonly
clean
2220000
unkown
page read and write
clean
299A000
unkown
page readonly
clean
7278000
heap private
page read and write
clean
2A1681D0000
heap default
page read and write
clean
21605A6C000
unkown
page read and write
clean
1ADC1270000
unkown
page read and write
clean
6E5E000
unkown
page read and write
clean
46E0000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
2A33000
unkown
page readonly
clean
46E0000
unkown
page read and write
clean
6C790000
unkown image
page readonly
clean
2B70000
unkown
page readonly
clean
2B55000
unkown
page readonly
clean
3150000
unkown
page read and write
clean
7FF5B3DF9000
unkown
page readonly
clean
7FF52E16A000
unkown
page readonly
clean
3250000
unkown
page read and write
clean
1F35000
unkown
page readonly
clean
23D2F79000
unkown
page read and write
clean
1ADBF913000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
1ADBF86B000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
7FF52E261000
unkown
page readonly
clean
1FE3000
unkown
page readonly
clean
2220000
unkown
page read and write
clean
2A01000
unkown
page readonly
clean
2838000
unkown
page readonly
clean
1D76000
unkown
page readonly
clean
2BA0000
heap private
page read and write
clean
2A16825E000
unkown
page read and write
clean
6C562000
unkown image
page read and write
clean
4F0000
unkown
page execute and read and write
clean
21605A6C000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
3637000
heap private
page read and write
clean
7FF5D9B7F000
unkown
page readonly
clean
7FF52E16E000
unkown
page readonly
clean
7FF5B3C7E000
unkown
page readonly
clean
7FF52DF36000
unkown
page readonly
clean
2C33000
unkown
page readonly
clean
2425000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
2987000
unkown
page readonly
clean
342B000
unkown
page read and write
clean
47F0000
unkown
page read and write
clean
2BBB000
unkown
page readonly
clean
21605A68000
unkown
page read and write
clean
32A0000
unkown
page read and write
clean
A75F37B000
unkown
page read and write
clean
1ADBF86B000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
2A168313000
unkown
page read and write
clean
1ADBF86B000
unkown
page read and write
clean
471C000
unkown
page read and write
clean
7290000
unkown
page read and write
clean
3150000
unkown
page read and write
clean
2934000
heap default
page read and write
clean
2220000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
2C14000
unkown
page readonly
clean
2B9A000
unkown
page readonly
clean
4C4E000
unkown
page read and write
clean
2A16827D000
unkown
page read and write
clean
7FF52E25A000
unkown
page readonly
clean
469E000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
1DDD000
unkown
page readonly
clean
3250000
unkown
page read and write
clean
46E0000
unkown
page read and write
clean
6C55E000
unkown image
page execute and read and write
clean
4800000
heap private
page read and write
clean
7FF52E073000
unkown
page readonly
clean
32A0000
unkown
page read and write
clean
21605A6D000
unkown
page read and write
clean
2A1681F0000
unkown
page readonly
clean
4C10000
heap private
page read and write
clean
3250000
unkown
page read and write
clean
1ADBF86B000
unkown
page read and write
clean
32A0000
unkown
page read and write
clean
29B0000
unkown
page readonly
clean
7FF52E133000
unkown
page readonly
clean
46E0000
unkown
page read and write
clean
C4F4D7E000
unkown
page read and write
clean
4C0F000
unkown
page read and write
clean
4F0000
unkown
page read and write
clean
7FF5D9DB8000
unkown
page readonly
clean
1FED000
unkown
page readonly
clean
1ADBF829000
unkown
page read and write
clean
6C505000
unkown image
page read and write
clean
229E000
unkown
page read and write
clean
6C562000
unkown image
page read and write
clean
2FD0000
unkown
page readonly
clean
21605B00000
unkown
page read and write
clean
263B000
unkown
page read and write
clean
3240000
unkown
page read and write
clean
7FF52E1ED000
unkown
page readonly
clean
50A000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
686E000
unkown
page read and write
clean
5B50000
heap private
page read and write
clean
23D2B6B000
unkown
page read and write
clean
6CDD000
unkown
page read and write
clean
31F0000
heap default
page read and write
clean
32A0000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
1ADC1370000
unkown
page readonly
clean
C4F4B7F000
unkown
page read and write
clean
2A168254000
unkown
page read and write
clean
2250000
heap private
page read and write
clean
2220000
unkown
page read and write
clean
6C500000
unkown image
page readonly
clean
2103000
unkown
page readonly
clean
22BB000
unkown
page read and write
clean
35EE000
unkown
page read and write
clean
1ADBF802000
unkown
page read and write
clean
7FF5D9F0E000
unkown
page readonly
clean
7FF52E110000
unkown
page readonly
clean
35AF000
unkown
page read and write
clean
1F51000
unkown
page readonly
clean
7FF5B3D6C000
unkown
page readonly
clean
2421000
unkown
page read and write
clean
32A0000
unkown
page read and write
clean
650000
heap default
page read and write
clean
4F0000
unkown
page read and write
clean
695000
heap default
page read and write
clean
3150000
unkown
page read and write
clean
32A0000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
4EA0000
unkown
page read and write
clean
6C500000
unkown image
page readonly
clean
27D0000
unkown
page readonly
clean
7FF5D9EAA000
unkown
page readonly
clean
29B6000
unkown
page readonly
clean
32A0000
unkown
page read and write
clean
7FF52E1C4000
unkown
page readonly
clean
3250000
unkown
page read and write
clean
220000
unkown
page read and write
clean
601E000
unkown
page read and write
clean
3423000
unkown
page read and write
clean
1D0000
unkown
page readonly
clean
299F000
unkown
page readonly
clean
6C500000
unkown image
page readonly
clean
6C50F000
unkown image
page execute read
clean
32BE000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
9A000
unkown
page read and write
clean
50EB000
heap private
page read and write
clean
7FF52DFC9000
unkown
page readonly
clean
32A0000
unkown
page read and write
clean
3150000
unkown
page read and write
clean
2A168C00000
unkown
page readonly
clean
6C50E000
unkown image
page readonly
clean
2220000
unkown
page read and write
clean
2F40000
unkown
page read and write
clean
7FF5D9F9A000
unkown
page readonly
clean
7FF52DE47000
unkown
page readonly
clean
3250000
unkown
page read and write
clean
2B9F000
unkown
page readonly
clean
6C503000
unkown image
page readonly
clean
3250000
unkown
page read and write
clean
4608000
heap private
page read and write
clean
32A0000
unkown
page read and write
clean
3220000
heap private
page read and write
clean
3630000
heap private
page read and write
clean
356E000
unkown
page read and write
clean
32A0000
unkown
page read and write
clean
7FF5B3C23000
unkown
page readonly
clean
32A0000
unkown
page read and write
clean
2C01000
unkown
page readonly
clean
3114000
unkown
page read and write
clean
2955000
unkown
page readonly
clean
6E9E000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
1ADBF86B000
unkown
page read and write
clean
7FF5D9F04000
unkown
page readonly
clean
7FF52DE3F000
unkown
page readonly
clean
3250000
unkown
page read and write
clean
1F7000
heap private
page read and write
clean
6770000
unkown
page readonly
clean
21605A69000
unkown
page read and write
clean
7FF5B3E71000
unkown
page readonly
clean
7FF5D9EAE000
unkown
page readonly
clean
2C05000
unkown
page readonly
clean
46E0000
unkown
page read and write
clean
318C000
unkown
page readonly
clean
1DE8000
unkown
page readonly
clean
2220000
unkown
page read and write
clean
60E000
unkown
page read and write
clean
4771000
unkown
page execute read
clean
3250000
unkown
page read and write
clean
1ADBF840000
unkown
page read and write
clean
2639000
heap private
page read and write
clean
3250000
unkown
page read and write
clean
2A16825A000
unkown
page read and write
clean
7FF5B3C7B000
unkown
page readonly
clean
3177000
heap private
page read and write
clean
6C55C000
unkown image
page read and write
clean
7FF5D9E50000
unkown
page readonly
clean
FBF000
unkown
page readonly
clean
30F0000
unkown
page readonly
clean
22BA000
unkown
page read and write
clean
5C20000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
21605A6D000
unkown
page read and write
clean
27B0000
unkown
page execute and read and write
clean
3250000
unkown
page read and write
clean
4210000
heap private
page read and write
clean
3250000
unkown
page read and write
clean
46E0000
unkown
page read and write
clean
170000
unkown
page readonly
clean
28B0000
heap default
page read and write
clean
293A000
unkown
page read and write
clean
7FF5B3E6A000
unkown
page readonly
clean
22A8000
unkown
page read and write
clean
7FF52DF95000
unkown
page readonly
clean
3250000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
46E0000
unkown
page read and write
clean
7FF52E170000
unkown
page readonly
clean
2220000
unkown
page read and write
clean
4F0000
unkown
page read and write
clean
2B6C000
unkown
page readonly
clean
2458000
unkown
page read and write
clean
65B000
heap default
page read and write
clean
206F000
unkown
page readonly
clean
2220000
unkown
page read and write
clean
1B0000
unkown
page readonly
clean
4C8F000
unkown
page read and write
clean
362F000
unkown
page read and write
clean
3421000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
2A1681E0000
unkown
page readonly
clean
C4F4BF9000
unkown
page read and write
clean
7FF5D9FA1000
unkown
page readonly
clean
46E0000
unkown
page read and write
clean
32A0000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
1E0000
unkown
page read and write
clean
2A28000
unkown
page readonly
clean
342A000
unkown
page read and write
clean
6C500000
unkown image
page readonly
clean
7FF52E112000
unkown
page readonly
clean
3250000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
32A0000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
3150000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
3150000
unkown
page read and write
clean
7FF5D9C6B000
unkown
page readonly
clean
7FF5B3D6A000
unkown
page readonly
clean
2220000
unkown
page read and write
clean
2260000
unkown
page read and write
clean
3EF0000
heap private
page read and write
clean
3250000
unkown
page read and write
clean
46E0000
unkown
page read and write
clean
32A0000
unkown
page read and write
clean
2BB6000
unkown
page readonly
clean
2220000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
21605A68000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
4F0000
unkown
page read and write
clean
7FF5B3E64000
unkown
page readonly
clean
1ADBF900000
unkown
page read and write
clean
1ADBF800000
unkown
page read and write
clean
2A168A02000
unkown
page read and write
clean
7FF5D9DB3000
unkown
page readonly
clean
520000
unkown
page readonly
clean
2220000
unkown
page read and write
clean
1F20000
unkown
page readonly
clean
27B0000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
22BB000
unkown
page read and write
clean
5B0F000
unkown
page read and write
clean
6E80000
heap private
page read and write
clean
420E000
unkown
page read and write
clean
46E0000
unkown
page read and write
clean
C4F4A7B000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
21605A6F000
unkown
page read and write
clean
33FA000
heap default
page read and write
clean
3250000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
6C506000
unkown image
page readonly
clean
2220000
unkown
page read and write
clean
206A000
unkown
page readonly
clean
46E0000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
A75F5F7000
unkown
page read and write
clean
1ADBF780000
heap default
page read and write
clean
7FF5D9F29000
unkown
page readonly
clean
32A0000
unkown
page read and write
clean
3290000
unkown
page read and write
clean
23C0000
heap default
page read and write
clean
32A0000
unkown
page read and write
clean
23D2FFF000
unkown
page read and write
clean
2A14000
unkown
page readonly
clean
46E0000
unkown
page read and write
clean
6D1E000
unkown
page read and write
clean
A75F07C000
unkown
page read and write
clean
2049000
unkown
page readonly
clean
2220000
unkown
page read and write
clean
298D000
unkown
page readonly
clean
3250000
unkown
page read and write
clean
7FF52E1DE000
unkown
page readonly
clean
5B54000
heap private
page read and write
clean
2B87000
unkown
page readonly
clean
3250000
unkown
page read and write
clean
46E0000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
21605A6F000
unkown
page read and write
clean
418D000
unkown
page read and write
clean
334A000
heap default
page read and write
clean
7FF52E1BA000
unkown
page readonly
clean
21605A29000
unkown
page read and write
clean
C4F4C7A000
unkown
page read and write
clean
30F0000
unkown
page read and write
clean
2EFA000
unkown
page read and write
clean
2B8E000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
2B79000
unkown
page readonly
clean
2985000
unkown
page readonly
clean
7FF5B3DF6000
unkown
page readonly
clean
7FF5D9D09000
unkown
page readonly
clean
2B0F000
unkown
page read and write
clean
46E0000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
2025000
unkown
page readonly
clean
3250000
unkown
page read and write
clean
293A000
unkown
page readonly
clean
2220000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
222F000
unkown
page read and write
clean
1EEA000
unkown
page readonly
clean
2D40000
unkown
page readonly
clean
7FF52E175000
unkown
page readonly
clean
2220000
unkown
page read and write
clean
27F0000
unkown
page readonly
clean
46E0000
unkown
page read and write
clean
7FF5B3CE4000
unkown
page readonly
clean
3EEE000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
2DE0000
unkown
page readonly
clean
2280000
heap default
page read and write
clean
3250000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
32A0000
unkown
page read and write
clean
32B0000
heap default
page read and write
clean
3250000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
DB000
unkown
page read and write
clean
1ADBF86B000
unkown
page read and write
clean
1FD2000
unkown
page readonly
clean
7FF52E1D8000
unkown
page readonly
clean
990000
unkown
page readonly
clean
32C0000
unkown
page readonly
clean
4F0000
unkown
page read and write
clean
6C503000
unkown image
page readonly
clean
3150000
unkown
page read and write
clean
3150000
unkown
page read and write
clean
1F4A000
unkown
page readonly
clean
2B29000
unkown
page readonly
clean
6950000
heap private
page read and write
clean
4F5E000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
2055000
unkown
page readonly
clean
3230000
unkown
page readonly
clean
3250000
unkown
page read and write
clean
21605A6D000
unkown
page read and write
clean
2CFA000
unkown
page read and write
clean
4770000
unkown
page read and write
clean
3180000
unkown
page read and write
clean
2A168308000
unkown
page read and write
clean
46E0000
unkown
page read and write
clean
3150000
unkown
page read and write
clean
46E0000
unkown
page read and write
clean
2790000
heap default
page read and write
clean
6EE0000
unkown
page read and write
clean
32FF000
unkown
page read and write
clean
21605A6D000
unkown
page read and write
clean
2040000
unkown
page readonly
clean
46E0000
unkown
page read and write
clean
3418000
unkown
page read and write
clean
6D569000
unkown image
page write copy
clean
32A0000
unkown
page read and write
clean
22AC000
unkown
page read and write
clean
20D1000
unkown
page readonly
clean
46E0000
unkown
page read and write
clean
7FF52DF91000
unkown
page readonly
clean
6C50F000
unkown image
page execute read
clean
3250000
unkown
page read and write
clean
2454000
unkown
page read and write
clean
22B1000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
21605A00000
unkown
page read and write
clean
21605A6D000
unkown
page read and write
clean
21605A6F000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
7FF5B3AF7000
unkown
page readonly
clean
3190000
unkown
page read and write
clean
2970000
unkown
page readonly
clean
2220000
unkown
page read and write
clean
50EB000
heap private
page read and write
clean
7FF52E1B4000
unkown
page readonly
clean
2082000
unkown
page readonly
clean
2F3C000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
2063000
unkown
page readonly
clean
1F29000
unkown
page readonly
clean
363A000
heap private
page read and write
clean
2740000
unkown
page read and write
clean
2A60000
unkown
page readonly
clean
4DE0000
unkown
page readonly
clean
27C6000
unkown
page readonly
clean
3423000
unkown
page read and write
clean
32A0000
unkown
page read and write
clean
202C000
unkown
page readonly
clean
228A000
heap default
page read and write
clean
3150000
unkown
page read and write
clean
41CE000
unkown
page read and write
clean
216059A0000
unkown
page write copy
clean
21605A71000
unkown
page read and write
clean
68AF000
unkown
page read and write
clean
2F3B000
unkown
page read and write
clean
3189000
unkown
page readonly
clean
296C000
unkown
page readonly
clean
3340000
heap default
page read and write
clean
2220000
unkown
page read and write
clean
32A0000
unkown
page read and write
clean
1ADBF7E0000
unkown
page readonly
clean
2220000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
1DFE000
unkown
page readonly
clean
216074B0000
unkown
page readonly
clean
5008000
heap private
page read and write
clean
2795000
heap default
page read and write
clean
46E0000
unkown
page read and write
clean
7FF5B3955000
unkown
page readonly
clean
2A33000
unkown
page readonly
clean
3170000
heap private
page read and write
clean
7FF5B3DDF000
unkown
page readonly
clean
6C505000
unkown image
page read and write
clean
3250000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
1F0C000
unkown
page readonly
clean
2220000
unkown
page read and write
clean
216073B0000
unkown
page read and write
clean
2B3A000
unkown
page readonly
clean
3250000
unkown
page read and write
clean
32A0000
unkown
page read and write
clean
1ADBF720000
heap private
page read and write
clean
32FE000
unkown
page read and write
clean
94B000
unkown
page read and write
clean
50C000
unkown
page readonly
clean
6C55E000
unkown image
page execute and read and write
clean
1FD8000
unkown
page readonly
clean
7FF52D9CD000
unkown
page readonly
clean
32A0000
unkown
page read and write
clean
30D0000
unkown
page execute and read and write
clean
570000
heap default
page read and write
clean
500000
unkown
page read and write
clean
C4F4AFF000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
2A47000
unkown
page readonly
clean
7FF5D9EBB000
unkown
page readonly
clean
1ADBF902000
unkown
page read and write
clean
22BC000
unkown
page read and write
clean
1ADBF86B000
unkown
page read and write
clean
7FF52E187000
unkown
page readonly
clean
2BB2000
unkown
page readonly
clean
1F1C000
unkown
page readonly
clean
2DA0000
unkown
page read and write
clean
2C28000
unkown
page readonly
clean
4D0000
unkown
page read and write
clean
1F30000
unkown
page readonly
clean
216059F0000
unkown
page readonly
clean
1F0000
heap private
page read and write
clean
3421000
unkown
page read and write
clean
29C6000
unkown
page readonly
clean
32A0000
unkown
page read and write
clean
5B60000
unkown
page readonly
clean
3250000
unkown
page read and write
clean
19B000
unkown
page read and write
clean
22BB000
unkown
page read and write
clean
1ADBF790000
unkown
page write copy
clean
1F05000
unkown
page readonly
clean
21605A3F000
unkown
page read and write
clean
31FF000
unkown
page read and write
clean
7FF5B3D7E000
unkown
page readonly
clean
293B000
heap default
page read and write
clean
46E0000
unkown
page read and write
clean
7FF5B3DD4000
unkown
page readonly
clean
2B63000
unkown
page readonly
clean
337A000
unkown
page read and write
clean
46E0000
unkown
page read and write
clean
27E0000
heap private
page read and write
clean
3250000
unkown
page read and write
clean
501000
unkown
page execute read
clean
7FF5B3D97000
unkown
page readonly
clean
2979000
unkown
page readonly
clean
3200000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
2A168213000
unkown
page read and write
clean
1ADBF813000
unkown
page read and write
clean
C4F4CFE000
unkown
page read and write
clean
7FF5B3C61000
unkown
page readonly
clean
140000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
7FF5D9F21000
unkown
page readonly
clean
2220000
unkown
page read and write
clean
2A16828D000
unkown
page read and write
clean
46E0000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
6D56C000
unkown image
page readonly
clean
47EE000
unkown
page read and write
clean
2B8F000
unkown
page readonly
clean
3250000
unkown
page read and write
clean
7FF5B3E72000
unkown
page readonly
clean
2BA1000
unkown
page readonly
clean
6C501000
unkown image
page execute read
clean
6C500000
unkown image
page readonly
clean
1ADBF86B000
unkown
page read and write
clean
46E0000
unkown
page read and write
clean
21605A6B000
unkown
page read and write
clean
6D569000
unkown image
page write copy
clean
21605A6B000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
327E000
unkown
page read and write
clean
1F13000
unkown
page readonly
clean
3250000
unkown
page read and write
clean
22B1000
unkown
page read and write
clean
3368000
heap default
page read and write
clean
3250000
unkown
page read and write
clean
7FF5B3D8B000
unkown
page readonly
clean
1EE3000
unkown
page readonly
clean
2220000
unkown
page read and write
clean
7FF5B3DEE000
unkown
page readonly
clean
7FF5D9EDF000
unkown
page readonly
clean
7FF52E1E6000
unkown
page readonly
clean
21605C00000
unkown
page readonly
clean
2B4D000
unkown
page readonly
clean
3250000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
21605A6D000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
1FB5000
unkown
page readonly
clean
2FA0000
unkown
page read and write
clean
7FF5D9B6C000
unkown
page readonly
clean
282D000
unkown
page readonly
clean
201D000
unkown
page readonly
clean
3250000
unkown
page read and write
clean
6C55C000
unkown image
page read and write
clean
203B000
unkown
page readonly
clean
2220000
unkown
page read and write
clean
7FF5D9DAB000
unkown
page readonly
clean
28BA000
heap default
page read and write
clean
46E0000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
33F0000
heap default
page read and write
clean
20E4000
unkown
page readonly
clean
298F000
unkown
page readonly
clean
3250000
unkown
page read and write
clean
2DD0000
unkown
page readonly
clean
7FF52E1A8000
unkown
page readonly
clean
23D2BEE000
unkown
page read and write
clean
1F14000
unkown
page readonly
clean
1ADBF856000
unkown
page read and write
clean
7FF5D9EC7000
unkown
page readonly
clean
3290000
unkown
page read and write
clean
7FF5B3DB7000
unkown
page readonly
clean
7FF5D9EB5000
unkown
page readonly
clean
3250000
unkown
page read and write
clean
32A0000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
7FF52E17B000
unkown
page readonly
clean
7FF5B3946000
unkown
page readonly
clean
3224000
heap private
page read and write
clean
26D0000
unkown
page readonly
clean
7FF5D9F94000
unkown
page readonly
clean
21605A02000
unkown
page read and write
clean
46E0000
unkown
page read and write
clean
1FE2000
unkown
page readonly
clean
200A000
unkown
page readonly
clean
21605A6F000
unkown
page read and write
clean
2A168400000
unkown
page readonly
clean
46E0000
unkown
page read and write
clean
180000
unkown
page execute and read and write
clean
22B1000
unkown
page read and write
clean
22C0000
heap private
page read and write
clean
3640000
unkown
page readonly
clean
20D5000
unkown
page readonly
clean
3250000
unkown
page read and write
clean
2270000
unkown
page read and write
clean
29B2000
unkown
page readonly
clean
2220000
unkown
page read and write
clean
46E0000
unkown
page read and write
clean
2FF0000
unkown
page execute and read and write
clean
2220000
unkown
page read and write
clean
2033000
unkown
page readonly
clean
2A22000
unkown
page readonly
clean
317A000
heap private
page read and write
clean
32A0000
unkown
page read and write
clean
7FF5D9EDC000
unkown
page readonly
clean
46E0000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
46E0000
unkown
page read and write
clean
50EA000
heap private
page read and write
clean
7FF5B3DC4000
unkown
page readonly
clean
7FF5B3CCD000
unkown
page readonly
clean
A75F17E000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
46E0000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
1FFC000
unkown
page readonly
clean
23D307F000
unkown
page read and write
clean
2D3B000
unkown
page read and write
clean
609F000
unkown
page read and write
clean
32A0000
unkown
page read and write
clean
32A0000
unkown
page read and write
clean
32A0000
unkown
page read and write
clean
7FF5D9FA2000
unkown
page readonly
clean
46E0000
unkown
page read and write
clean
2003000
unkown
page readonly
clean
2963000
unkown
page readonly
clean
3250000
unkown
page read and write
clean
7FF5D970D000
unkown
page readonly
clean
2220000
unkown
page read and write
clean
46E0000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
2A168300000
unkown
page read and write
clean
21605A6F000
unkown
page read and write
clean
20F2000
unkown
page readonly
clean
2A16828A000
unkown
page read and write
clean
3200000
unkown
page execute and read and write
clean
2A2D000
unkown
page readonly
clean
2103000
unkown
page readonly
clean
32A0000
unkown
page read and write
clean
7FF5B3DFD000
unkown
page readonly
clean
5ACE000
unkown
page read and write
clean
7FF5B3BD1000
unkown
page readonly
clean
2925000
unkown
page read and write
clean
7FF5B3D7A000
unkown
page readonly
clean
3250000
unkown
page read and write
clean
1F35000
unkown
page readonly
clean
32A0000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
2A16825C000
unkown
page read and write
clean
7FF5D9E73000
unkown
page readonly
clean
1F66000
unkown
page readonly
clean
30D0000
unkown
page read and write
clean
7FF52E1E1000
unkown
page readonly
clean
7FF52E1CE000
unkown
page readonly
clean
2C22000
unkown
page readonly
clean
477A000
unkown
page read and write
clean
3371000
heap default
page read and write
clean
A75F3FF000
unkown
page read and write
clean
2260000
unkown
page read and write
clean
1FA000
heap private
page read and write
clean
2860000
unkown
page readonly
clean
465F000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
3000000
unkown
page readonly
clean
294D000
unkown
page readonly
clean
2270000
unkown
page read and write
clean
A75F0FE000
unkown
page read and write
clean
32A0000
unkown
page read and write
clean
6D6000
heap default
page read and write
clean
3250000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
46E0000
unkown
page read and write
clean
A75F4FE000
unkown
page read and write
clean
2B93000
unkown
page readonly
clean
21605A6F000
unkown
page read and write
clean
84E000
unkown
page read and write
clean
1FE3000
unkown
page readonly
clean
D20000
unkown
page readonly
clean
56D000
unkown
page read and write
clean
6C501000
unkown image
page execute read
clean
3440000
unkown
page readonly
clean
23CC000
unkown
page read and write
clean
6C8000
unkown
page read and write
clean
21605A13000
unkown
page read and write
clean
4F0000
unkown
page read and write
clean
7FF52DE3A000
unkown
page readonly
clean
1E96000
unkown
page readonly
clean
7FF5D9F18000
unkown
page readonly
clean
2220000
unkown
page read and write
clean
6D56C000
unkown image
page readonly
clean
29BB000
unkown
page readonly
clean
2220000
unkown
page read and write
clean
2DC0000
unkown
page readonly
clean
7FF5B3CEC000
unkown
page readonly
clean
2220000
unkown
page read and write
clean
2780000
unkown
page readonly
clean
1F43000
unkown
page readonly
clean
27A0000
unkown
page execute and read and write
clean
3150000
unkown
page read and write
clean
23D2E7E000
unkown
page read and write
clean
68B0000
unkown
page read and write
clean
7FF52DF2B000
unkown
page readonly
clean
2760000
unkown
page readonly
clean
3100000
unkown
page read and write
clean
2BEE000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
21605860000
heap private
page read and write
clean
2A16827D000
unkown
page read and write
clean
46E0000
unkown
page read and write
clean
5B4E000
unkown
page read and write
clean
1FB1000
unkown
page readonly
clean
3250000
unkown
page read and write
clean
7FF5B3D85000
unkown
page readonly
clean
32A0000
unkown
page read and write
clean
2B5C000
unkown
page readonly
clean
46E0000
unkown
page read and write
clean
7FF5D9B87000
unkown
page readonly
clean
400000
unkown
page readonly
clean
32A0000
unkown
page read and write
clean
433F000
unkown
page read and write
clean
216058D0000
unkown
page readonly
clean
2A38000
unkown
page readonly
clean
3250000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
32A0000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
1EFD000
unkown
page readonly
clean
7FF5B3D80000
unkown
page readonly
clean
46E0000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
46E0000
unkown
page read and write
clean
1E10000
unkown
page readonly
clean
3250000
unkown
page read and write
clean
216058C0000
heap default
page read and write
clean
3250000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
46E0000
unkown
page read and write
clean
2600000
unkown
page readonly
clean
190000
unkown
page read and write
clean
341C000
unkown
page read and write
clean
2A168202000
unkown
page read and write
clean
1ADBFA00000
unkown
page readonly
clean
7FF5D9B7A000
unkown
page readonly
clean
7FF52E1E9000
unkown
page readonly
clean
509000
unkown
page readonly
clean
342B000
unkown
page read and write
clean
7FF5B3CD3000
unkown
page readonly
clean
3250000
unkown
page read and write
clean
46E0000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
208B000
unkown
page readonly
clean
32A0000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
7FF5D9EB0000
unkown
page readonly
clean
1F3F000
unkown
page readonly
clean
4C90000
unkown
page read and write
clean
46E0000
unkown
page read and write
clean
1F3D000
unkown
page readonly
clean
6960000
unkown
page readonly
clean
20F8000
unkown
page readonly
clean
2220000
unkown
page read and write
clean
2A168200000
unkown
page read and write
clean
7FF5B3940000
unkown
page readonly
clean
1ED9000
unkown
page readonly
clean
5BC000
unkown
page read and write
clean
4589000
heap private
page read and write
clean
7FF5D9E52000
unkown
page readonly
clean
4B8F000
unkown
page read and write
clean
2A168930000
unkown
page read and write
clean
2FEB000
heap private
page read and write
clean
2A168266000
unkown
page read and write
clean
30FF000
unkown
page read and write
clean
32A0000
unkown
page read and write
clean
1C0000
unkown
page readonly
clean
2220000
unkown
page read and write
clean
333F000
unkown
page read and write
clean
6AE0000
unkown
page readonly
clean
2770000
unkown
page readonly
clean
7FF5D9C76000
unkown
page readonly
clean
1F37000
unkown
page readonly
clean
46E0000
unkown
page read and write
clean
7FF52E262000
unkown
page readonly
clean
6954000
heap private
page read and write
clean
3250000
unkown
page read and write
clean
3150000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
2FC0000
unkown
page readonly
clean
2B4E000
unkown
page read and write
clean
6C500000
unkown image
page readonly
clean
2936000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
26B8000
heap private
page read and write
clean
2A168302000
unkown
page read and write
clean
475B000
unkown
page read and write
clean
7FF52E06B000
unkown
page readonly
clean
7FF52E078000
unkown
page readonly
clean
2929000
unkown
page readonly
clean
190000
unkown
page execute and read and write
clean
3250000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
2260000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
6C6000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
22BD000
unkown
page read and write
clean
32A0000
unkown
page read and write
clean
6C50E000
unkown image
page readonly
clean
1F4F000
unkown
page readonly
clean
32A0000
unkown
page read and write
clean
29A1000
unkown
page readonly
clean
There are 969 hidden memdumps, click here to show them.