IOCReport

loading gif

Files

File Path
Type
Category
Malicious
Permission-414467145-06252021.xlsm
Microsoft Excel 2007+
initial sample
malicious
C:\Users\user\Desktop\~$Permission-414467145-06252021.xlsm
data
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\4A07B784.jpg
[TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS6 (Windows), datetime=2021:02:11 21:11:18], baseline, precision 8, 1860x1000, frames 3
dropped
clean
C:\Users\user\AppData\Local\Temp\BECE0000
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Tue Oct 17 10:04:00 2017, mtime=Fri Jun 25 20:06:38 2021, atime=Fri Jun 25 20:06:38 2021, length=8192, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Permission-414467145-06252021.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Aug 26 14:08:15 2020, mtime=Fri Jun 25 20:06:38 2021, atime=Fri Jun 25 20:06:38 2021, length=153117, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\Desktop\4FCE0000
data
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 ..\Kro.fis
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 ..\Kro.fis1
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 ..\Kro.fis2
malicious

URLs

Name
IP
Malicious
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://185.183.99.120/44372.5879460648.dat
185.183.99.120
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://190.14.37.3/44372.5879460648.dat
190.14.37.3
clean
http://185.240.103.219/44372.5879460648.dat
185.240.103.219
clean
http://investor.msn.com/
unknown
clean
http://www.%s.comPA
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://servername/isapibackend.dll
unknown
clean
There are 4 hidden URLs, click here to show them.

IPs

IP
Domain
Country
Malicious
190.14.37.3
unknown
Panama
clean
185.183.99.120
unknown
Netherlands
clean
185.240.103.219
unknown
Russian Federation
clean

Registry

Path
Value
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
828
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
MTTT
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ReviewToken
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ECA03
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
VBAFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DefaultSheetR2L
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
UseSystemSeparators
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ThousandsSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DecimalSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ECD5D
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ECE57
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ECF22
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ECFAE
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} {000214E6-0000-0000-C000-000000000046} 0xFFFF
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
:<8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F8FB2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F9212
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
LastPurgeTime
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EXCELFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SavedLegacySettings
clean
There are 95 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
4562000
unkown
page readonly
clean
2A0000
unkown
page read and write
clean
1E6000
heap default
page read and write
clean
30B000
unkown
page read and write
clean
2BB000
unkown
page read and write
clean
4696000
unkown
page readonly
clean
1F0000
unkown
page write copy
clean
2A6000
unkown
page read and write
clean
3C50000
unkown
page readonly
clean
48D2000
unkown
page readonly
clean
44D5000
unkown
page readonly
clean
24DE000
unkown
page read and write
clean
2F6000
unkown
page read and write
clean
4655000
unkown
page readonly
clean
1E9000
unkown
page read and write
clean
2A0000
unkown
page read and write
clean
E4000
heap private
page read and write
clean
386000
unkown
page read and write
clean
32E000
unkown
page read and write
clean
357000
unkown
page read and write
clean
45E4000
unkown
page readonly
clean
70000
unkown
page read and write
clean
4872000
unkown
page readonly
clean
36E000
unkown
page read and write
clean
5B6000
unkown
page read and write
clean
26C000
unkown
page read and write
clean
4612000
unkown
page readonly
clean
4910000
unkown
page readonly
clean
1F0000
unkown
page write copy
clean
4456000
unkown
page readonly
clean
130000
unkown
page read and write
clean
1B0000
unkown
page read and write
clean
4672000
unkown
page readonly
clean
22C0000
unkown
page read and write
clean
48C5000
unkown
page readonly
clean
4060000
unkown
page readonly
clean
2339000
heap private
page read and write
clean
47A2000
unkown
page readonly
clean
21B0000
heap private
page read and write
clean
5D0000
heap private
page read and write
clean
170000
unkown
page read and write
clean
4539000
unkown
page readonly
clean
283000
heap default
page read and write
clean
2335000
heap private
page read and write
clean
3E0000
heap private
page read and write
clean
2DD000
unkown
page read and write
clean
4125000
heap private
page read and write
clean
30D000
unkown
page read and write
clean
36D000
unkown
page read and write
clean
366000
unkown
page read and write
clean
4750000
unkown
page readonly
clean
4486000
unkown
page readonly
clean
4815000
unkown
page readonly
clean
4404000
unkown
page readonly
clean
4569000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
4735000
unkown
page readonly
clean
345000
unkown
page read and write
clean
8C0000
unkown
page readonly
clean
2100000
heap private
page read and write
clean
4849000
unkown
page readonly
clean
265000
unkown
page read and write
clean
5D4000
heap private
page read and write
clean
F9000
unkown
page read and write
clean
460000
heap private
page read and write
clean
B2F000
unkown
page read and write
clean
170000
unkown
page read and write
clean
29E000
unkown
page read and write
clean
43C4000
unkown
page readonly
clean
380000
unkown
page read and write
clean
4970000
unkown
page readonly
clean
4742000
unkown
page readonly
clean
4977000
unkown
page readonly
clean
44B6000
unkown
page readonly
clean
44A5000
unkown
page readonly
clean
4829000
unkown
page readonly
clean
E9000
unkown
page read and write
clean
20000
unkown
page readonly
clean
4625000
unkown
page readonly
clean
1D00000
unkown
page readonly
clean
4895000
unkown
page readonly
clean
160000
unkown
page read and write
clean
28E000
unkown
page read and write
clean
4749000
unkown
page readonly
clean
4AB0000
unkown
page readonly
clean
20000
unkown
page readonly
clean
45A4000
unkown
page readonly
clean
4462000
unkown
page readonly
clean
570000
heap private
page read and write
clean
294000
unkown
page read and write
clean
46C9000
unkown
page readonly
clean
2B2000
unkown
page read and write
clean
3A70000
unkown
page readonly
clean
482D000
unkown
page readonly
clean
44ED000
unkown
page readonly
clean
3FC9000
heap private
page read and write
clean
3FC5000
heap private
page read and write
clean
2C3000
unkown
page read and write
clean
46CD000
unkown
page readonly
clean
2160000
unkown
page readonly
clean
386000
unkown
page read and write
clean
190000
unkown
page execute and read and write
clean
43E2000
unkown
page readonly
clean
46B5000
unkown
page readonly
clean
2520000
unkown
page read and write
clean
2DE000
unkown
page read and write
clean
2B5000
unkown
page read and write
clean
47B5000
unkown
page readonly
clean
45C4000
unkown
page readonly
clean
4A70000
unkown
page readonly
clean
213B000
heap private
page read and write
clean
55F000
unkown
page read and write
clean
4765000
unkown
page readonly
clean
44E9000
unkown
page readonly
clean
236B000
heap private
page read and write
clean
386000
unkown
page read and write
clean
3C0000
unkown
page read and write
clean
29A000
unkown
page read and write
clean
4525000
unkown
page readonly
clean
2B5000
unkown
page read and write
clean
4302000
unkown
page readonly
clean
4742000
unkown
page readonly
clean
4AD0000
unkown
page readonly
clean
1EB000
heap default
page read and write
clean
110000
unkown
page execute and read and write
clean
4642000
unkown
page readonly
clean
4492000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
464000
heap private
page read and write
clean
1A0000
unkown
page readonly
clean
720000
unkown
page readonly
clean
47D2000
unkown
page readonly
clean
3F0000
unkown
page read and write
clean
2A0000
unkown
page read and write
clean
1DD000
heap default
page read and write
clean
314000
unkown
page read and write
clean
6EF000
unkown
page read and write
clean
5E0000
unkown
page readonly
clean
374000
unkown
page read and write
clean
2A6000
unkown
page read and write
clean
190000
unkown
page execute and read and write
clean
16D000
unkown
page read and write
clean
262000
unkown
page read and write
clean
4642000
unkown
page readonly
clean
345000
unkown
page read and write
clean
2440000
unkown
page readonly
clean
2E4000
unkown
page read and write
clean
2E0000
unkown
page read and write
clean
3FC0000
heap private
page read and write
clean
372000
unkown
page read and write
clean
760000
unkown
page readonly
clean
4702000
unkown
page readonly
clean
265000
unkown
page read and write
clean
21E000
heap default
page read and write
clean
313000
heap default
page read and write
clean
70000
unkown
page readonly
clean
2C7000
heap default
page read and write
clean
4636000
unkown
page readonly
clean
20000
unkown
page readonly
clean
4785000
unkown
page readonly
clean
1A7000
heap default
page read and write
clean
31A000
heap default
page read and write
clean
46A2000
unkown
page readonly
clean
1CC0000
unkown
page readonly
clean
292000
unkown
page read and write
clean
5A0000
unkown
page readonly
clean
2B0000
unkown
page write copy
clean
2A0000
unkown
page read and write
clean
2335000
heap private
page read and write
clean
4724000
unkown
page readonly
clean
48A9000
unkown
page readonly
clean
4445000
unkown
page readonly
clean
574000
heap private
page read and write
clean
2C7000
unkown
page read and write
clean
4712000
unkown
page readonly
clean
2F6000
unkown
page read and write
clean
4532000
unkown
page readonly
clean
32A000
unkown
page read and write
clean
43E4000
unkown
page readonly
clean
24A000
unkown
page read and write
clean
4CB7000
unkown
page readonly
clean
20E0000
unkown
page write copy
clean
21B5000
heap private
page read and write
clean
316000
unkown
page read and write
clean
730000
heap private
page read and write
clean
2620000
unkown
page readonly
clean
4879000
unkown
page readonly
clean
34C000
unkown
page read and write
clean
43C2000
unkown
page readonly
clean
21EB000
heap private
page read and write
clean
580000
unkown
page read and write
clean
3F6000
unkown
page read and write
clean
F0000
unkown
page readonly
clean
41C0000
unkown
page readonly
clean
4719000
unkown
page readonly
clean
4770000
unkown
page readonly
clean
2F0000
unkown
page read and write
clean
2BD000
unkown
page read and write
clean
4129000
heap private
page read and write
clean
23C0000
unkown
page readonly
clean
2FE000
heap default
page read and write
clean
330000
unkown
page read and write
clean
2A0000
unkown
page read and write
clean
4A90000
unkown
page readonly
clean
4B57000
unkown
page readonly
clean
590000
heap private
page read and write
clean
2F6000
unkown
page read and write
clean
46E9000
unkown
page readonly
clean
F0000
unkown
page read and write
clean
353000
unkown
page read and write
clean
233000
heap default
page read and write
clean
46C6000
unkown
page readonly
clean
380000
unkown
page read and write
clean
1E0000
heap default
page read and write
clean
43E8000
unkown
page readonly
clean
46E2000
unkown
page readonly
clean
4548000
unkown
page readonly
clean
4730000
unkown
page readonly
clean
2F6000
unkown
page read and write
clean
4842000
unkown
page readonly
clean
45C2000
unkown
page readonly
clean
4120000
heap private
page read and write
clean
43E2000
unkown
page readonly
clean
2BC000
unkown
page read and write
clean
41A0000
unkown
page readonly
clean
4A6000
unkown
page read and write
clean
700000
unkown
page readonly
clean
60000
unkown
page readonly
clean
1E60000
unkown
page readonly
clean
1A0000
heap default
page read and write
clean
2105000
heap private
page read and write
clean
28D000
unkown
page read and write
clean
47C6000
unkown
page readonly
clean
4432000
unkown
page readonly
clean
120000
unkown
page readonly
clean
4585000
unkown
page readonly
clean
3E80000
unkown
page readonly
clean
4722000
unkown
page readonly
clean
2000000
unkown
page readonly
clean
47F6000
unkown
page readonly
clean
4475000
unkown
page readonly
clean
46F2000
unkown
page readonly
clean
4790000
unkown
page readonly
clean
4685000
unkown
page readonly
clean
380000
unkown
page read and write
clean
2A6000
unkown
page read and write
clean
4704000
unkown
page readonly
clean
1FC0000
unkown
page readonly
clean
426000
unkown
page read and write
clean
3E60000
unkown
page readonly
clean
2D6000
unkown
page read and write
clean
44C2000
unkown
page readonly
clean
3E4000
heap private
page read and write
clean
230000
heap default
page read and write
clean
2330000
heap private
page read and write
clean
277000
unkown
page read and write
clean
4555000
unkown
page readonly
clean
386000
unkown
page read and write
clean
39F0000
unkown
page readonly
clean
4DBE000
unkown
page read and write
clean
48A2000
unkown
page readonly
clean
740000
unkown
page readonly
clean
26E000
heap default
page read and write
clean
2330000
heap private
page read and write
clean
4950000
unkown
page readonly
clean
4744000
unkown
page readonly
clean
39D000
unkown
page read and write
clean
45A2000
unkown
page readonly
clean
4502000
unkown
page readonly
clean
4802000
unkown
page readonly
clean
E0000
heap private
page read and write
clean
4F0000
unkown
page read and write
clean
4402000
unkown
page readonly
clean
4040000
unkown
page readonly
clean
4509000
unkown
page readonly
clean
1E7000
heap default
page read and write
clean
E0000
unkown
page read and write
clean
4772000
unkown
page readonly
clean
470000
unkown
page read and write
clean
2180000
unkown
page write copy
clean
46E000
unkown
page read and write
clean
734000
heap private
page read and write
clean
380000
unkown
page read and write
clean
44E6000
unkown
page readonly
clean
4796000
unkown
page readonly
clean
44E2000
unkown
page readonly
clean
4705000
unkown
page readonly
clean
39B000
unkown
page read and write
clean
47E5000
unkown
page readonly
clean
24E000
unkown
page read and write
clean
4865000
unkown
page readonly
clean
28A000
heap default
page read and write
clean
4202000
unkown
page readonly
clean
2230000
unkown
page read and write
clean
4826000
unkown
page readonly
clean
3A4000
unkown
page read and write
clean
273000
unkown
page read and write
clean
2E2000
unkown
page read and write
clean
2A6000
unkown
page read and write
clean
2C4000
unkown
page read and write
clean
1B0000
unkown
page write copy
clean
1A0000
unkown
page readonly
clean
4208000
unkown
page readonly
clean
237000
heap default
page read and write
clean
2F0000
unkown
page read and write
clean
4E1E000
unkown
page read and write
clean
100000
unkown
page readonly
clean
23A000
heap default
page read and write
clean
4A32000
unkown
page readonly
clean
2C0000
heap default
page read and write
clean
342000
unkown
page read and write
clean
4666000
unkown
page readonly
clean
4930000
unkown
page readonly
clean
4542000
unkown
page readonly
clean
594000
heap private
page read and write
clean
45E2000
unkown
page readonly
clean
There are 306 hidden memdumps, click here to show them.