IOCReport

loading gif

Files

File Path
Type
Category
Malicious
2CW1YLhNIS.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\2CW1YLhNIS.exe.log
ASCII text, with CRLF line terminators
modified
malicious
C:\Users\user\AppData\Local\Temp\tmp9D57.tmp
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\UieOsrSocP.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\AppData\Roaming\UieOsrSocP.exe:Zone.Identifier
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\C79A3B\B52B3F.lck
very short file (no magic)
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3853321935-2125563209-4053062332-1002\bc49718863ee53e026d805ec372039e9_d06ed635-68f6-4e9a-955c-4899f5f57b9a
data
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\2CW1YLhNIS.exe
'C:\Users\user\Desktop\2CW1YLhNIS.exe'
malicious
C:\Windows\SysWOW64\schtasks.exe
'C:\Windows\System32\schtasks.exe' /Create /TN 'Updates\UieOsrSocP' /XML 'C:\Users\user\AppData\Local\Temp\tmp9D57.tmp'
malicious
C:\Users\user\Desktop\2CW1YLhNIS.exe
C:\Users\user\Desktop\2CW1YLhNIS.exe
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
clean

URLs

Name
IP
Malicious
http://kbfvzoboss.bid/alien/fre.php
malicious
http://63.141.228.141/32.php/QQojJUjm8ByeT
63.141.228.141
malicious
http://alphastand.win/alien/fre.php
malicious
http://alphastand.trade/alien/fre.php
malicious
http://alphastand.top/alien/fre.php
malicious
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
unknown
clean
http://www.ibsensoftware.com/
unknown
clean
https://stackpath.bootstrapcdn.com/bootstrap/4.5.0/css/bootstrap.min.css
unknown
clean

IPs

IP
Domain
Country
Malicious
63.141.228.141
unknown
United States
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
2D91000
unkown
page read and write
malicious
3D19000
unkown
page read and write
malicious
400000
unkown
page execute and read and write
malicious
B7B0000
unkown
page read and write
clean
1169000
unkown
page read and write
clean
C26D000
unkown
page read and write
clean
5210000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
11C0000
unkown
page readonly
clean
51F0000
unkown
page read and write
clean
B7EE000
unkown
page read and write
clean
53F0000
unkown
page read and write
clean
5400000
unkown
page read and write
clean
5400000
unkown
page execute and read and write
clean
7FF5BF3D4000
unkown
page readonly
clean
B7E9000
unkown
page read and write
clean
87C0000
unkown
page read and write
clean
5860000
unkown
page read and write
clean
2B6C000
unkown
page read and write
clean
5400000
unkown
page read and write
clean
5330000
unkown
page read and write
clean
22FD9610000
unkown
page readonly
clean
5860000
unkown
page read and write
clean
CF9000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
57C0000
unkown
page read and write
clean
5270000
unkown
page read and write
clean
C270000
unkown
page read and write
clean
56F0000
unkown
page read and write
clean
5280000
unkown
page read and write
clean
5700000
unkown
page read and write
clean
2DFE000
unkown
page read and write
clean
53F0000
unkown
page read and write
clean
5250000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
7FF5BF47A000
unkown
page readonly
clean
5260000
unkown
page read and write
clean
14C0000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
7FF5BF3F8000
unkown
page readonly
clean
116D000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
C150000
unkown
page read and write
clean
9D206CB000
unkown
page read and write
clean
5250000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
11F0000
unkown
page read and write
clean
14D0000
heap private
page read and write
clean
5340000
unkown
page execute and read and write
clean
1170000
unkown
page read and write
clean
7FF5BF3A7000
unkown
page readonly
clean
5FA0000
unkown
page read and write
clean
32CE000
unkown
page read and write
clean
115B000
unkown
page read and write
clean
2C9E000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
5860000
unkown
page read and write
clean
22FDA000000
unkown
page readonly
clean
151E000
unkown
page read and write
clean
7FF5BF38E000
unkown
page readonly
clean
5FA0000
unkown
page read and write
clean
5220000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
BD2E000
unkown
page read and write
clean
22FD9849000
unkown
page read and write
clean
B7B0000
unkown
page read and write
clean
113F000
heap default
page read and write
clean
11AD000
unkown
page read and write
clean
CE3000
unkown
page read and write
clean
105C000
unkown
page read and write
clean
5210000
unkown
page read and write
clean
6260000
unkown
page read and write
clean
22FD9900000
unkown
page read and write
clean
22FD9913000
unkown
page read and write
clean
5280000
unkown
page read and write
clean
5330000
unkown
page read and write
clean
2E07000
unkown
page read and write
clean
53F0000
unkown
page read and write
clean
5330000
unkown
page read and write
clean
11AD000
unkown
page read and write
clean
CF6000
unkown
page read and write
clean
22FD988C000
unkown
page read and write
clean
5331000
unkown
page read and write
clean
56D0000
unkown
page read and write
clean
116E000
unkown
page read and write
clean
11B6000
unkown
page read and write
clean
2E00000
unkown
page read and write
clean
5280000
unkown
page read and write
clean
5210000
unkown
page read and write
clean
57D0000
unkown
page read and write
clean
22FDA340000
unkown
page readonly
clean
1100000
heap default
page read and write
clean
5FA0000
unkown
page read and write
clean
BE80000
unkown
page readonly
clean
7FF5BF28B000
unkown
page readonly
clean
2B90000
heap private
page read and write
clean
2DAF000
unkown
page read and write
clean
7FF5BEBFD000
unkown
page readonly
clean
1190000
unkown
page read and write
clean
D14000
unkown
page read and write
clean
7FF5BF2FC000
unkown
page readonly
clean
4D10000
unkown
page read and write
clean
5240000
unkown
page read and write
clean
5FA1000
unkown
page read and write
clean
5280000
unkown
page readonly
clean
5210000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
5400000
unkown
page read and write
clean
5400000
unkown
page read and write
clean
A0C000
unkown image
page readonly
clean
11A6000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
1174000
unkown
page read and write
clean
9D20E77000
unkown
page read and write
clean
7FF5BF390000
unkown
page readonly
clean
1490000
unkown
page read and write
clean
2D11000
unkown
page read and write
clean
C160000
unkown
page read and write
clean
FB0000
unkown
page read and write
clean
116E000
unkown
page read and write
clean
BED0000
unkown
page readonly
clean
5FA0000
unkown
page read and write
clean
11CE000
heap default
page read and write
clean
BC2D000
unkown
page read and write
clean
CF3000
unkown
page read and write
clean
7FF5BF2E3000
unkown
page readonly
clean
9D20C7F000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
5860000
unkown
page read and write
clean
4D30000
unkown
page read and write
clean
7FF5BF1E1000
unkown
page readonly
clean
2CE0000
unkown
page read and write
clean
56F0000
unkown
page read and write
clean
22FD9855000
unkown
page read and write
clean
56E0000
unkown
page read and write
clean
C92000
unkown image
page readonly
clean
FC4000
unkown
page read and write
clean
5220000
unkown
page read and write
clean
8F0000
unkown image
page readonly
clean
7FF5BF40D000
unkown
page readonly
clean
5350000
unkown
page read and write
clean
1497000
unkown
page execute and read and write
clean
5860000
unkown
page read and write
clean
5280000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
A0C000
unkown image
page readonly
clean
56F0000
unkown
page readonly
clean
1190000
unkown
page read and write
clean
C90000
unkown image
page readonly
clean
CE7000
unkown
page read and write
clean
22FD986C000
unkown
page read and write
clean
6260000
unkown
page read and write
clean
7FF5BF474000
unkown
page readonly
clean
49F000
unkown
page execute and read and write
clean
9D20BFB000
unkown
page read and write
clean
7FF5BF481000
unkown
page readonly
clean
57E0000
unkown
page read and write
clean
7FF5BF37A000
unkown
page readonly
clean
5FA0000
unkown
page read and write
clean
5250000
unkown
page read and write
clean
11E0000
heap default
page read and write
clean
C130000
unkown
page read and write
clean
2E80000
heap private
page read and write
clean
115B000
unkown
page read and write
clean
2CAB000
unkown
page read and write
clean
5220000
unkown
page read and write
clean
7FF5BEF50000
unkown
page readonly
clean
5FA0000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
56D2000
unkown
page read and write
clean
DAC000
unkown image
page readonly
clean
5330000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
C11C000
unkown
page read and write
clean
5200000
unkown
page read and write
clean
14D9000
heap private
page read and write
clean
117C000
unkown
page read and write
clean
22FD9E02000
unkown
page read and write
clean
5860000
unkown
page read and write
clean
5280000
unkown
page read and write
clean
5260000
unkown
page read and write
clean
4D10000
unkown
page read and write
clean
8F0000
unkown image
page readonly
clean
FCD000
unkown
page execute and read and write
clean
5FA0000
unkown
page read and write
clean
10EE000
unkown
page read and write
clean
56E0000
unkown
page read and write
clean
629E000
unkown
page read and write
clean
1179000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
5230000
unkown
page read and write
clean
32D7000
unkown
page read and write
clean
118F000
unkown
page read and write
clean
9D20D7C000
unkown
page read and write
clean
C271000
unkown
page read and write
clean
5D70000
unkown
page read and write
clean
2CA4000
unkown
page read and write
clean
5360000
heap private
page read and write
clean
11E5000
heap default
page read and write
clean
C16D000
unkown
page read and write
clean
5230000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
56D0000
unkown
page read and write
clean
5330000
unkown
page read and write
clean
22FD97C0000
unkown
page readonly
clean
C270000
unkown
page read and write
clean
119D000
unkown
page read and write
clean
2E3D000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
10F0000
unkown
page read and write
clean
1195000
unkown
page read and write
clean
11B2000
unkown
page read and write
clean
11C1000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
6260000
unkown
page read and write
clean
7FF5BF409000
unkown
page readonly
clean
5250000
unkown
page read and write
clean
56E0000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
FE0000
heap private
page read and write
clean
10F2000
unkown
page read and write
clean
119C000
unkown
page read and write
clean
2CA0000
unkown
page read and write
clean
14B0000
unkown
page read and write
clean
7FF5BEA98000
unkown
page readonly
clean
B7B0000
unkown
page read and write
clean
5330000
unkown
page read and write
clean
CF0000
unkown
page read and write
clean
5330000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
57BC000
unkown
page read and write
clean
12FE000
unkown
page read and write
clean
8503000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
5263000
unkown
page read and write
clean
6260000
unkown
page read and write
clean
4D10000
unkown
page read and write
clean
2DEF000
unkown
page read and write
clean
5210000
unkown
page read and write
clean
5350000
unkown
page read and write
clean
7FF5BF3BC000
unkown
page readonly
clean
D05000
unkown
page read and write
clean
5FA0000
unkown
page execute and read and write
clean
1131000
heap default
page read and write
clean
1169000
unkown
page read and write
clean
3D11000
unkown
page read and write
clean
4D20000
unkown
page read and write
clean
C270000
unkown
page read and write
clean
DAC000
unkown image
page readonly
clean
22FD986C000
unkown
page read and write
clean
1199000
unkown
page read and write
clean
7FF5BEF65000
unkown
page readonly
clean
E16000
unkown
page read and write
clean
B7C4000
unkown
page read and write
clean
BBEF000
unkown
page read and write
clean
2B80000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
5210000
unkown
page read and write
clean
2E00000
unkown
page read and write
clean
5330000
unkown
page read and write
clean
55E0000
unkown
page readonly
clean
1178000
unkown
page read and write
clean
1171000
unkown
page read and write
clean
C90000
unkown image
page readonly
clean
5F6E000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
7FF5BF3E4000
unkown
page readonly
clean
5FA0000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
C90000
unkown image
page readonly
clean
4EAB000
unkown
page read and write
clean
7FF5BF3FE000
unkown
page readonly
clean
4D10000
unkown
page read and write
clean
5350000
unkown
page read and write
clean
57D0000
unkown
page read and write
clean
C92000
unkown image
page readonly
clean
1169000
unkown
page read and write
clean
BE6E000
unkown
page read and write
clean
56E0000
unkown
page read and write
clean
7FF5BF482000
unkown
page readonly
clean
7FF5BF2DD000
unkown
page readonly
clean
2B2E000
unkown
page read and write
clean
119D000
unkown
page read and write
clean
4D10000
unkown
page read and write
clean
5280000
unkown
page read and write
clean
7FF5BF406000
unkown
page readonly
clean
9D20F7F000
unkown
page read and write
clean
1179000
unkown
page read and write
clean
4D4E000
unkown
page read and write
clean
119D000
unkown
page read and write
clean
BA7000
unkown
page read and write
clean
5280000
unkown
page read and write
clean
11B0000
unkown
page read and write
clean
BF0000
unkown
page read and write
clean
BD6E000
unkown
page read and write
clean
4D10000
unkown
page read and write
clean
5260000
unkown
page read and write
clean
CFF000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
8760000
unkown
page read and write
clean
56E0000
unkown
page read and write
clean
54B0000
unkown
page readonly
clean
D11000
unkown
page read and write
clean
7FF5BF37C000
unkown
page readonly
clean
5FA0000
unkown
page read and write
clean
1190000
unkown
page read and write
clean
5770000
heap private
page read and write
clean
63A0000
unkown
page read and write
clean
7FF5BEF56000
unkown
page readonly
clean
5FB0000
heap private
page read and write
clean
1210000
heap default
page read and write
clean
56F0000
unkown
page read and write
clean
5280000
unkown
page read and write
clean
1310000
unkown
page readonly
clean
5FA0000
unkown
page read and write
clean
5210000
unkown
page read and write
clean
11AD000
unkown
page read and write
clean
5280000
unkown
page read and write
clean
4D10000
unkown
page read and write
clean
149B000
unkown
page execute and read and write
clean
2CFF000
unkown
page read and write
clean
56E3000
unkown
page read and write
clean
E20000
unkown
page readonly
clean
117B000
unkown
page read and write
clean
1186000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
2CC5000
unkown
page read and write
clean
1218000
heap default
page read and write
clean
5230000
unkown
page read and write
clean
53AD000
unkown
page read and write
clean
2CF0000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
4D10000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
22FD9902000
unkown
page read and write
clean
D0E000
unkown
page read and write
clean
9D207CF000
unkown
page read and write
clean
116B000
unkown
page read and write
clean
53F0000
unkown
page read and write
clean
118E000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
4D10000
unkown
page read and write
clean
BEE0000
unkown
page readonly
clean
2B70000
unkown
page execute and read and write
clean
119C000
unkown
page read and write
clean
528A000
unkown
page read and write
clean
8F2000
unkown image
page readonly
clean
B7B0000
unkown
page read and write
clean
6250000
unkown
page read and write
clean
87B0000
unkown
page read and write
clean
5220000
unkown
page read and write
clean
5363000
heap private
page read and write
clean
D02000
unkown
page read and write
clean
BFA0000
unkown
page read and write
clean
BAAF000
unkown
page read and write
clean
C4AE000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
5280000
unkown
page read and write
clean
11BB000
unkown
page read and write
clean
10F6000
unkown
page execute and read and write
clean
5280000
unkown
page read and write
clean
2D00000
heap private
page execute and read and write
clean
119F000
unkown
page read and write
clean
61C0000
unkown
page read and write
clean
7FF5BF28E000
unkown
page readonly
clean
BAEE000
unkown
page read and write
clean
22FD9A00000
unkown
page readonly
clean
5210000
unkown
page read and write
clean
2CBD000
unkown
page read and write
clean
B7E9000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
5260000
unkown
page read and write
clean
11A6000
unkown
page read and write
clean
4D10000
unkown
page read and write
clean
7FF5BF233000
unkown
page readonly
clean
7FF5BF3EF000
unkown
page readonly
clean
56D0000
unkown
page read and write
clean
5330000
unkown
page read and write
clean
5FC0000
unkown
page read and write
clean
119C000
unkown
page read and write
clean
B7D7000
unkown
page read and write
clean
9D2074E000
unkown
page read and write
clean
5210000
unkown
page read and write
clean
5330000
unkown
page read and write
clean
7FF5BF38A000
unkown
page readonly
clean
53EF000
unkown
page read and write
clean
1190000
unkown
page read and write
clean
4D10000
unkown
page read and write
clean
63B0000
unkown
page read and write
clean
22FD986F000
unkown
page read and write
clean
22FD9908000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
5860000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
22FD97D0000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
57D0000
unkown
page read and write
clean
FC3000
unkown
page execute and read and write
clean
5FA0000
unkown
page read and write
clean
5330000
unkown
page read and write
clean
5860000
unkown
page read and write
clean
2CD1000
unkown
page read and write
clean
119C000
unkown
page read and write
clean
116E000
unkown
page read and write
clean
F24000
unkown
page read and write
clean
C4B0000
unkown
page read and write
clean
4D10000
unkown
page read and write
clean
1520000
unkown
page readonly
clean
4D8E000
unkown
page read and write
clean
11AD000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
1178000
unkown
page read and write
clean
7FF5BF3C7000
unkown
page readonly
clean
2CCC000
unkown
page read and write
clean
4D10000
unkown
page read and write
clean
5400000
unkown
page read and write
clean
22FD9600000
heap default
page read and write
clean
5FA0000
unkown
page read and write
clean
F6E000
unkown
page read and write
clean
119D000
unkown
page read and write
clean
B9AE000
unkown
page read and write
clean
EF0000
unkown
page readonly
clean
C271000
unkown
page read and write
clean
3E1A000
unkown
page read and write
clean
5220000
unkown
page read and write
clean
1175000
unkown
page read and write
clean
C270000
unkown
page read and write
clean
4EB0000
unkown
page readonly
clean
5860000
unkown
page read and write
clean
22FD9829000
unkown
page read and write
clean
22FD9802000
unkown
page read and write
clean
3E4E000
unkown
page read and write
clean
5210000
unkown
page read and write
clean
6260000
unkown
page read and write
clean
8F2000
unkown image
page readonly
clean
AAB000
unkown
page read and write
clean
5210000
unkown
page read and write
clean
5210000
unkown
page read and write
clean
C01E000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
BE70000
unkown
page readonly
clean
5FA0000
unkown
page read and write
clean
11A6000
unkown
page read and write
clean
B7B1000
unkown
page read and write
clean
7FF5BF2F4000
unkown
page readonly
clean
5280000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
119F000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
7FF5BF3DA000
unkown
page readonly
clean
1177000
unkown
page read and write
clean
116D000
unkown
page read and write
clean
22FD9800000
unkown
page read and write
clean
5330000
unkown
page read and write
clean
5210000
unkown
page read and write
clean
BF80000
unkown
page readonly
clean
5350000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
C140000
unkown
page read and write
clean
5210000
unkown
page read and write
clean
7F5E0000
unkown
page execute and read and write
clean
22FD95A0000
heap private
page read and write
clean
22FD984F000
unkown
page read and write
clean
4D18000
unkown
page read and write
clean
4D10000
unkown
page read and write
clean
141E000
unkown
page read and write
clean
5400000
unkown
page read and write
clean
2CC0000
unkown
page read and write
clean
7FF5BF107000
unkown
page readonly
clean
2B9B000
heap private
page read and write
clean
5FA0000
unkown
page read and write
clean
5400000
unkown
page read and write
clean
22FD9813000
unkown
page read and write
clean
CFC000
unkown
page read and write
clean
FDD000
unkown
page execute and read and write
clean
5220000
unkown
page readonly
clean
5FA0000
unkown
page read and write
clean
C3AE000
unkown
page read and write
clean
5330000
unkown
page read and write
clean
5400000
unkown
page read and write
clean
E12000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
22FD983C000
unkown
page read and write
clean
2E90000
unkown
page readonly
clean
22FD96E0000
unkown
page readonly
clean
2DB1000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
639E000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
7FF5BF395000
unkown
page readonly
clean
5FA0000
unkown
page read and write
clean
1492000
unkown
page read and write
clean
FAE000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
2CB7000
unkown
page read and write
clean
F24000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
113C000
heap default
page read and write
clean
117F000
unkown
page read and write
clean
8F0000
unkown image
page readonly
clean
2CFE000
unkown
page read and write
clean
D08000
unkown
page read and write
clean
4D10000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
4D17000
unkown
page read and write
clean
14E0000
unkown
page readonly
clean
5FA0000
unkown
page read and write
clean
F20000
heap default
page read and write
clean
10FA000
unkown
page execute and read and write
clean
FD0000
unkown
page read and write
clean
D0B000
unkown
page read and write
clean
55D0000
heap private
page execute and read and write
clean
57D0000
unkown
page read and write
clean
7FF5BF39B000
unkown
page readonly
clean
119D000
unkown
page read and write
clean
117E000
unkown
page read and write
clean
1198000
heap default
page read and write
clean
4D10000
unkown
page read and write
clean
56D0000
unkown
page read and write
clean
5330000
unkown
page read and write
clean
5FA0000
unkown
page read and write
clean
7FF5BF271000
unkown
page readonly
clean
5330000
unkown
page read and write
clean
7FF5BF3BF000
unkown
page readonly
clean
There are 523 hidden memdumps, click here to show them.