IOCReport

loading gif

Files

File Path
Type
Category
Malicious
Decline-172917164-06242021.xlsm
Microsoft Excel 2007+
initial sample
malicious
C:\Users\user\Desktop\~$Decline-172917164-06242021.xlsm
data
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\AD7B9C26.tif
TIFF image data, little-endian, direntries=19, height=1600, bps=53710, compression=LZW, PhotometricIntepretation=RGB, width=1600
dropped
clean
C:\Users\user\AppData\Local\Temp\95DE0000
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Decline-172917164-06242021.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Aug 26 14:08:15 2020, mtime=Fri Jun 25 14:24:40 2021, atime=Fri Jun 25 14:24:40 2021, length=328749, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Tue Oct 17 10:04:00 2017, mtime=Fri Jun 25 14:24:40 2021, atime=Fri Jun 25 14:24:40 2021, length=8192, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\Desktop\66DE0000
data
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 ..\Kro.fis
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 ..\Kro.fis1
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 ..\Kro.fis2
malicious

URLs

Name
IP
Malicious
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://185.234.247.7/44372.3504680556.dat
185.234.247.7
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://investor.msn.com/
unknown
clean
http://www.%s.comPA
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://5.253.62.174/44372.3504680556.dat
5.253.62.174
clean
http://servername/isapibackend.dll
unknown
clean
There are 3 hidden URLs, click here to show them.

IPs

IP
Domain
Country
Malicious
185.234.247.7
unknown
Russian Federation
clean
5.253.62.174
unknown
Russian Federation
clean
185.117.73.74
unknown
Netherlands
clean

Registry

Path
Value
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
p`8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
MTTT
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ReviewToken
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ED0B7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
VBAFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DefaultSheetR2L
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
UseSystemSeparators
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ThousandsSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DecimalSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ED4CC
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ED5F5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ED6EE
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} {000214E6-0000-0000-C000-000000000046} 0xFFFF
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
)k8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
LastPurgeTime
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
103949
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
104309
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EXCELFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SavedLegacySettings
clean
There are 94 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
327000
unkown
page read and write
clean
387000
heap default
page read and write
clean
4582000
unkown
page readonly
clean
710000
unkown
page readonly
clean
70000
unkown
page readonly
clean
3D3000
heap default
page read and write
clean
230000
unkown
page read and write
clean
5F4000
heap private
page read and write
clean
1C3000
heap default
page read and write
clean
45E2000
unkown
page readonly
clean
203B000
heap private
page read and write
clean
4720000
unkown
page readonly
clean
432000
unkown
page read and write
clean
4564000
unkown
page readonly
clean
4522000
unkown
page readonly
clean
484000
heap private
page read and write
clean
4544000
unkown
page readonly
clean
70000
unkown
page readonly
clean
2200000
unkown
page write copy
clean
600000
unkown
page readonly
clean
4890000
unkown
page readonly
clean
4524000
unkown
page readonly
clean
2080000
heap private
page read and write
clean
160000
unkown
page read and write
clean
4672000
unkown
page readonly
clean
2180000
heap private
page read and write
clean
357000
unkown
page read and write
clean
417000
unkown
page read and write
clean
21BB000
heap private
page read and write
clean
120000
unkown
page readonly
clean
1AE000
heap default
page read and write
clean
4545000
unkown
page readonly
clean
3F65000
heap private
page read and write
clean
3950000
unkown
page readonly
clean
2FE000
unkown
page read and write
clean
4585000
unkown
page readonly
clean
45F6000
unkown
page readonly
clean
490000
unkown
page read and write
clean
42E000
unkown
page read and write
clean
5C4000
heap private
page read and write
clean
43B2000
unkown
page readonly
clean
4832000
unkown
page readonly
clean
1D20000
unkown
page readonly
clean
4382000
unkown
page readonly
clean
170000
unkown
page write copy
clean
3FE0000
unkown
page readonly
clean
4A0000
heap private
page read and write
clean
46E2000
unkown
page readonly
clean
43F4000
unkown
page readonly
clean
434000
unkown
page read and write
clean
4529000
unkown
page readonly
clean
44D9000
unkown
page readonly
clean
4388000
unkown
page readonly
clean
46A9000
unkown
page readonly
clean
5D0000
unkown
page readonly
clean
4615000
unkown
page readonly
clean
44D6000
unkown
page readonly
clean
3F20000
heap private
page read and write
clean
4872000
unkown
page readonly
clean
3E50000
unkown
page readonly
clean
4780000
unkown
page readonly
clean
20000
unkown
page readonly
clean
20000
unkown
page readonly
clean
4B6000
heap default
page read and write
clean
4AF7000
unkown
page readonly
clean
45B2000
unkown
page readonly
clean
3DA000
heap default
page read and write
clean
24B0000
unkown
page readonly
clean
440000
unkown
page read and write
clean
48D0000
unkown
page readonly
clean
1DE000
unkown
page read and write
clean
350000
unkown
page read and write
clean
2B0000
unkown
page read and write
clean
2EA000
heap default
page read and write
clean
357000
unkown
page read and write
clean
5C0000
heap private
page read and write
clean
2F4000
heap private
page read and write
clean
45E5000
unkown
page readonly
clean
4665000
unkown
page readonly
clean
1DA000
unkown
page read and write
clean
446000
unkown
page read and write
clean
46D5000
unkown
page readonly
clean
280000
unkown
page read and write
clean
44F2000
unkown
page readonly
clean
336000
unkown
page read and write
clean
4575000
unkown
page readonly
clean
380000
heap default
page read and write
clean
33D000
unkown
page read and write
clean
3AE0000
unkown
page readonly
clean
44C5000
unkown
page readonly
clean
402000
unkown
page read and write
clean
46F000
unkown
page read and write
clean
4465000
unkown
page readonly
clean
46E9000
unkown
page readonly
clean
3F29000
heap private
page read and write
clean
4A4000
heap private
page read and write
clean
4596000
unkown
page readonly
clean
170000
heap default
page read and write
clean
236000
unkown
page read and write
clean
297000
heap default
page read and write
clean
3E70000
unkown
page readonly
clean
300000
unkown
page read and write
clean
4502000
unkown
page readonly
clean
ACF000
unkown
page read and write
clean
45B5000
unkown
page readonly
clean
1D0000
heap private
page read and write
clean
4760000
unkown
page readonly
clean
41F8000
unkown
page readonly
clean
2085000
heap private
page read and write
clean
3F60000
heap private
page read and write
clean
1F2000
unkown
page read and write
clean
46A2000
unkown
page readonly
clean
4666000
unkown
page readonly
clean
21E000
unkown
page read and write
clean
20BB000
heap private
page read and write
clean
46B9000
unkown
page readonly
clean
4348000
unkown
page readonly
clean
470000
heap default
page read and write
clean
446000
unkown
page read and write
clean
2B6000
unkown
page read and write
clean
4612000
unkown
page readonly
clean
44A6000
unkown
page readonly
clean
3DD9000
heap private
page read and write
clean
45D2000
unkown
page readonly
clean
110000
unkown
page execute and read and write
clean
464000
unkown
page read and write
clean
43F2000
unkown
page readonly
clean
45D6000
unkown
page readonly
clean
164000
heap private
page read and write
clean
4452000
unkown
page readonly
clean
F0000
unkown
page read and write
clean
44F9000
unkown
page readonly
clean
110000
unkown
page execute and read and write
clean
46C5000
unkown
page readonly
clean
462D000
unkown
page readonly
clean
323000
unkown
page read and write
clean
4D2F000
unkown
page read and write
clean
4AB7000
unkown
page readonly
clean
45C6000
unkown
page readonly
clean
1FB0000
unkown
page write copy
clean
405000
unkown
page read and write
clean
45F5000
unkown
page readonly
clean
413000
unkown
page read and write
clean
45B000
unkown
page read and write
clean
4DCF000
unkown
page read and write
clean
2FA000
unkown
page read and write
clean
4522000
unkown
page readonly
clean
69F000
unkown
page read and write
clean
4626000
unkown
page readonly
clean
F0000
unkown
page readonly
clean
2000000
heap private
page read and write
clean
236000
unkown
page read and write
clean
4606000
unkown
page readonly
clean
46E2000
unkown
page readonly
clean
120000
unkown
page readonly
clean
4482000
unkown
page readonly
clean
440000
unkown
page read and write
clean
4AD000
heap default
page read and write
clean
350000
unkown
page read and write
clean
42D000
unkown
page read and write
clean
2100000
unkown
page readonly
clean
3EE000
unkown
page read and write
clean
315000
unkown
page read and write
clean
36D000
unkown
page read and write
clean
E0000
unkown
page read and write
clean
21E0000
unkown
page write copy
clean
4967000
unkown
page readonly
clean
203000
unkown
page read and write
clean
4740000
unkown
page readonly
clean
4435000
unkown
page readonly
clean
357000
unkown
page read and write
clean
1EE000
unkown
page read and write
clean
4870000
unkown
page readonly
clean
4342000
unkown
page readonly
clean
41F2000
unkown
page readonly
clean
2E3000
heap default
page read and write
clean
3DD0000
heap private
page read and write
clean
3A90000
unkown
page readonly
clean
48B0000
unkown
page readonly
clean
22A0000
unkown
page read and write
clean
5F0000
heap private
page read and write
clean
480000
heap private
page read and write
clean
312000
unkown
page read and write
clean
4482000
unkown
page readonly
clean
46B2000
unkown
page readonly
clean
230000
unkown
page read and write
clean
1F5000
unkown
page read and write
clean
446000
unkown
page read and write
clean
1CF0000
unkown
page readonly
clean
4000000
unkown
page readonly
clean
4649000
unkown
page readonly
clean
3F69000
heap private
page read and write
clean
270000
unkown
page read and write
clean
F0000
unkown
page read and write
clean
4625000
unkown
page readonly
clean
3EA000
unkown
page read and write
clean
D9000
unkown
page read and write
clean
3DD5000
heap private
page read and write
clean
21D000
unkown
page read and write
clean
2005000
heap private
page read and write
clean
440000
unkown
page read and write
clean
40C000
unkown
page read and write
clean
236000
unkown
page read and write
clean
3DCF000
unkown
page read and write
clean
E0000
unkown
page read and write
clean
390000
unkown
page read and write
clean
4910000
unkown
page readonly
clean
590000
unkown
page readonly
clean
48D0000
unkown
page readonly
clean
466D000
unkown
page readonly
clean
130000
unkown
page read and write
clean
3FA0000
unkown
page readonly
clean
4422000
unkown
page readonly
clean
4504000
unkown
page readonly
clean
440000
unkown
page read and write
clean
24D000
unkown
page read and write
clean
20000
unkown
page readonly
clean
4495000
unkown
page readonly
clean
4629000
unkown
page readonly
clean
36B000
unkown
page read and write
clean
3BE000
heap default
page read and write
clean
4682000
unkown
page readonly
clean
4655000
unkown
page readonly
clean
33E000
unkown
page read and write
clean
236000
unkown
page read and write
clean
374000
unkown
page read and write
clean
4689000
unkown
page readonly
clean
4584000
unkown
page readonly
clean
3C6000
unkown
page read and write
clean
350000
unkown
page read and write
clean
1FC000
unkown
page read and write
clean
222000
unkown
page read and write
clean
4442000
unkown
page readonly
clean
45D000
unkown
page read and write
clean
1E9000
unkown
page read and write
clean
4C6000
unkown
page read and write
clean
2CE000
heap default
page read and write
clean
2B6000
unkown
page read and write
clean
1F5000
unkown
page read and write
clean
44DD000
unkown
page readonly
clean
357000
unkown
page read and write
clean
2080000
unkown
page readonly
clean
48B0000
unkown
page readonly
clean
4515000
unkown
page readonly
clean
4695000
unkown
page readonly
clean
160000
heap private
page read and write
clean
230000
unkown
page read and write
clean
1F0000
unkown
page write copy
clean
4476000
unkown
page readonly
clean
43D2000
unkown
page readonly
clean
1FF0000
unkown
page readonly
clean
4B0000
unkown
page read and write
clean
4642000
unkown
page readonly
clean
27D000
unkown
page read and write
clean
315000
unkown
page read and write
clean
1D4000
heap private
page read and write
clean
1CA000
heap default
page read and write
clean
2320000
unkown
page readonly
clean
4562000
unkown
page readonly
clean
280000
unkown
page read and write
clean
207000
unkown
page read and write
clean
2F0000
heap private
page read and write
clean
4544000
unkown
page readonly
clean
224000
unkown
page read and write
clean
477000
heap default
page read and write
clean
2160000
unkown
page write copy
clean
3F25000
heap private
page read and write
clean
22C0000
unkown
page read and write
clean
290000
heap default
page read and write
clean
43D4000
unkown
page readonly
clean
279000
unkown
page read and write
clean
4572000
unkown
page readonly
clean
780000
unkown
page readonly
clean
2A0000
unkown
page readonly
clean
344000
unkown
page read and write
clean
480000
unkown
page read and write
clean
42F2000
unkown
page readonly
clean
2185000
heap private
page read and write
clean
1CB0000
unkown
page readonly
clean
446000
unkown
page read and write
clean
31C000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
4542000
unkown
page readonly
clean
230000
unkown
page read and write
clean
45A2000
unkown
page readonly
clean
4446000
unkown
page readonly
clean
130000
unkown
page read and write
clean
350000
unkown
page read and write
clean
4669000
unkown
page readonly
clean
4559000
unkown
page readonly
clean
44B2000
unkown
page readonly
clean
4542000
unkown
page readonly
clean
4E6000
unkown
page read and write
clean
4705000
unkown
page readonly
clean
4552000
unkown
page readonly
clean
405000
unkown
page read and write
clean
342000
unkown
page read and write
clean
60000
unkown
page readonly
clean
45C5000
unkown
page readonly
clean
48F0000
unkown
page readonly
clean
4B6000
unkown
page read and write
clean
290000
unkown
page execute and read and write
clean
177000
heap default
page read and write
clean
4636000
unkown
page readonly
clean
4BB000
heap default
page read and write
clean
4642000
unkown
page readonly
clean
3FC0000
unkown
page readonly
clean
43B4000
unkown
page readonly
clean
4679000
unkown
page readonly
clean
4602000
unkown
page readonly
clean
24B000
unkown
page read and write
clean
2460000
unkown
page readonly
clean
46A5000
unkown
page readonly
clean
254000
unkown
page read and write
clean
6E0000
unkown
page readonly
clean
750000
unkown
page readonly
clean
There are 306 hidden memdumps, click here to show them.