IOCReport

loading gif

Files

File Path
Type
Category
Malicious
Permission-1532161794-06252021.xlsm
Microsoft Excel 2007+
initial sample
malicious
C:\Users\user\Desktop\~$Permission-1532161794-06252021.xlsm
data
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\1D80F52D.jpg
[TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS6 (Windows), datetime=2021:02:11 21:11:18], baseline, precision 8, 1860x1000, frames 3
dropped
clean
C:\Users\user\AppData\Local\Temp\6CCE0000
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Tue Oct 17 10:04:00 2017, mtime=Sat Jun 26 00:24:37 2021, atime=Sat Jun 26 00:24:37 2021, length=8192, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Permission-1532161794-06252021.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Aug 26 14:08:14 2020, mtime=Sat Jun 26 00:24:37 2021, atime=Sat Jun 26 00:24:37 2021, length=153117, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\Desktop\FCCE0000
data
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 ..\Kro.fis
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 ..\Kro.fis1
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 ..\Kro.fis2
malicious

URLs

Name
IP
Malicious
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://190.14.37.3/44372.7671056713.dat
190.14.37.3
clean
http://investor.msn.com/
unknown
clean
http://www.%s.comPA
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://185.183.99.120/44372.7671056713.dat
185.183.99.120
clean
http://servername/isapibackend.dll
unknown
clean
There are 3 hidden URLs, click here to show them.

IPs

IP
Domain
Country
Malicious
190.14.37.3
unknown
Panama
clean
185.183.99.120
unknown
Netherlands
clean
185.240.103.219
unknown
Russian Federation
clean

Registry

Path
Value
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
#=8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
MTTT
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ReviewToken
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EC7F1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
VBAFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DefaultSheetR2L
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
UseSystemSeparators
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ThousandsSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DecimalSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ECB3B
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ECC06
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ECCD1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ECD6D
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} {000214E6-0000-0000-C000-000000000046} 0xFFFF
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ie8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F9119
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F9369
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
LastPurgeTime
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EXCELFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SavedLegacySettings
clean
There are 95 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
4358000
unkown
page readonly
clean
1DB0000
unkown
page readonly
clean
4582000
unkown
page readonly
clean
356000
heap default
page read and write
clean
44F2000
unkown
page readonly
clean
266000
unkown
page read and write
clean
34D000
heap default
page read and write
clean
3E2F000
unkown
page read and write
clean
3F70000
unkown
page readonly
clean
47E2000
unkown
page readonly
clean
2170000
unkown
page read and write
clean
4C6000
unkown
page read and write
clean
45F9000
unkown
page readonly
clean
44D2000
unkown
page readonly
clean
20C0000
unkown
page write copy
clean
2120000
heap private
page read and write
clean
2D6000
unkown
page read and write
clean
4840000
unkown
page readonly
clean
810000
unkown
page readonly
clean
45B2000
unkown
page readonly
clean
20E000
unkown
page read and write
clean
3F4000
heap private
page read and write
clean
156000
unkown
page read and write
clean
3F50000
unkown
page readonly
clean
24D000
unkown
page read and write
clean
4C1F000
unkown
page read and write
clean
45C5000
unkown
page readonly
clean
4645000
unkown
page readonly
clean
4422000
unkown
page readonly
clean
4622000
unkown
page readonly
clean
3ED9000
heap private
page read and write
clean
4A0000
unkown
page execute and read and write
clean
2370000
unkown
page readonly
clean
299000
unkown
page read and write
clean
DE000
unkown
page read and write
clean
215B000
heap private
page read and write
clean
4534000
unkown
page readonly
clean
146000
unkown
page read and write
clean
3FD0000
unkown
page readonly
clean
3ED5000
heap private
page read and write
clean
C3000
heap default
page read and write
clean
BDE000
unkown
page read and write
clean
4659000
unkown
page readonly
clean
44E2000
unkown
page readonly
clean
4629000
unkown
page readonly
clean
4B4000
unkown
page read and write
clean
60000
unkown
page readonly
clean
4AD000
unkown
page read and write
clean
39A0000
unkown
page readonly
clean
3D5000
heap private
page read and write
clean
45D6000
unkown
page readonly
clean
680000
unkown
page readonly
clean
4E4000
unkown
page read and write
clean
4559000
unkown
page readonly
clean
4A67000
unkown
page readonly
clean
2320000
unkown
page readonly
clean
280000
unkown
page read and write
clean
120000
unkown
page read and write
clean
3E00000
heap private
page read and write
clean
4552000
unkown
page readonly
clean
46E000
unkown
page read and write
clean
4554000
unkown
page readonly
clean
46D5000
unkown
page readonly
clean
AE000
heap default
page read and write
clean
2270000
unkown
page read and write
clean
310000
heap default
page read and write
clean
4C0000
unkown
page read and write
clean
4625000
unkown
page readonly
clean
260000
unkown
page read and write
clean
3950000
unkown
page readonly
clean
170000
unkown
page readonly
clean
4452000
unkown
page readonly
clean
4B0000
unkown
page readonly
clean
46A5000
unkown
page readonly
clean
1F0000
unkown
page read and write
clean
1C50000
unkown
page readonly
clean
3EA0000
unkown
page readonly
clean
40B000
heap private
page read and write
clean
590000
unkown
page readonly
clean
20A000
unkown
page read and write
clean
482000
unkown
page read and write
clean
FC000
unkown
page read and write
clean
2360000
unkown
page readonly
clean
4452000
unkown
page readonly
clean
70000
heap default
page read and write
clean
690000
unkown
page readonly
clean
407000
heap default
page read and write
clean
114000
heap private
page read and write
clean
11E000
unkown
page read and write
clean
11D000
unkown
page read and write
clean
4595000
unkown
page readonly
clean
45D6000
unkown
page readonly
clean
4659000
unkown
page readonly
clean
400000
heap default
page read and write
clean
3B0000
unkown
page write copy
clean
4552000
unkown
page readonly
clean
1F50000
unkown
page readonly
clean
4770000
unkown
page readonly
clean
4532000
unkown
page readonly
clean
6AF000
unkown
page read and write
clean
4AE000
unkown
page read and write
clean
45C5000
unkown
page readonly
clean
45A6000
unkown
page readonly
clean
3D6000
unkown
page read and write
clean
4675000
unkown
page readonly
clean
146000
unkown
page read and write
clean
4C0000
unkown
page read and write
clean
4C0000
unkown
page read and write
clean
45D9000
unkown
page readonly
clean
1F3000
heap default
page read and write
clean
4529000
unkown
page readonly
clean
2B6000
unkown
page read and write
clean
3F39000
heap private
page read and write
clean
4522000
unkown
page readonly
clean
6B0000
unkown
page readonly
clean
4582000
unkown
page readonly
clean
463D000
unkown
page readonly
clean
3990000
unkown
page readonly
clean
154000
unkown
page read and write
clean
45E2000
unkown
page readonly
clean
42F2000
unkown
page readonly
clean
44B4000
unkown
page readonly
clean
130000
unkown
page read and write
clean
260000
unkown
page read and write
clean
3ED0000
heap private
page read and write
clean
110000
heap private
page read and write
clean
DA000
unkown
page read and write
clean
3DFE000
unkown
page read and write
clean
F0000
unkown
page readonly
clean
130000
unkown
page read and write
clean
44D4000
unkown
page readonly
clean
6B0000
unkown
page readonly
clean
4DD000
unkown
page read and write
clean
3D0000
heap private
page read and write
clean
2125000
heap private
page read and write
clean
4404000
unkown
page readonly
clean
20000
unkown
page readonly
clean
254000
unkown
page read and write
clean
524000
heap private
page read and write
clean
4512000
unkown
page readonly
clean
4C0000
unkown
page read and write
clean
44B2000
unkown
page readonly
clean
122000
unkown
page read and write
clean
266000
unkown
page read and write
clean
146000
unkown
page read and write
clean
684000
heap private
page read and write
clean
394000
heap private
page read and write
clean
485000
unkown
page read and write
clean
4575000
unkown
page readonly
clean
480000
heap private
page read and write
clean
3A0000
unkown
page read and write
clean
22C000
unkown
page read and write
clean
130000
unkown
page read and write
clean
4582000
unkown
page readonly
clean
A2F000
unkown
page read and write
clean
450D000
unkown
page readonly
clean
4842000
unkown
page readonly
clean
35B000
heap default
page read and write
clean
3C0000
unkown
page write copy
clean
45B2000
unkown
page readonly
clean
4C0000
unkown
page read and write
clean
500000
unkown
page readonly
clean
4790000
unkown
page readonly
clean
4820000
unkown
page readonly
clean
4C6000
unkown
page read and write
clean
4565000
unkown
page readonly
clean
4352000
unkown
page readonly
clean
2260000
unkown
page read and write
clean
237000
unkown
page read and write
clean
45A000
heap default
page read and write
clean
77000
heap default
page read and write
clean
1A7000
heap default
page read and write
clean
410000
unkown
page read and write
clean
1F9B000
heap private
page read and write
clean
43E000
heap default
page read and write
clean
4860000
unkown
page readonly
clean
4222000
unkown
page readonly
clean
4689000
unkown
page readonly
clean
3FB0000
unkown
page readonly
clean
4880000
unkown
page readonly
clean
124000
unkown
page read and write
clean
44A6000
unkown
page readonly
clean
2A0000
unkown
page read and write
clean
500000
unkown
page write copy
clean
103000
unkown
page read and write
clean
446000
unkown
page read and write
clean
680000
heap private
page read and write
clean
1E0000
unkown
page read and write
clean
4476000
unkown
page readonly
clean
260000
unkown
page read and write
clean
70000
unkown
page readonly
clean
43F2000
unkown
page readonly
clean
485000
unkown
page read and write
clean
2030000
unkown
page write copy
clean
137000
unkown
page read and write
clean
4509000
unkown
page readonly
clean
1F65000
heap private
page read and write
clean
4589000
unkown
page readonly
clean
3B0000
unkown
page readonly
clean
453000
heap default
page read and write
clean
3A0000
unkown
page execute and read and write
clean
48C000
unkown
page read and write
clean
4750000
unkown
page readonly
clean
F5000
unkown
page read and write
clean
43E4000
unkown
page readonly
clean
146000
unkown
page read and write
clean
1A0000
heap default
page read and write
clean
225000
unkown
page read and write
clean
45A5000
unkown
page readonly
clean
4880000
unkown
page readonly
clean
1F60000
heap private
page read and write
clean
45DD000
unkown
page readonly
clean
222000
unkown
page read and write
clean
2A0000
unkown
page read and write
clean
3A0000
unkown
page readonly
clean
4552000
unkown
page readonly
clean
1A0000
heap private
page read and write
clean
48E0000
unkown
page readonly
clean
3F35000
heap private
page read and write
clean
42F8000
unkown
page readonly
clean
225000
unkown
page read and write
clean
4576000
unkown
page readonly
clean
3F0000
heap private
page read and write
clean
390000
heap private
page read and write
clean
4522000
unkown
page readonly
clean
E0000
unkown
page read and write
clean
F0000
unkown
page read and write
clean
493000
unkown
page read and write
clean
170000
unkown
page read and write
clean
130000
unkown
page read and write
clean
1C20000
unkown
page readonly
clean
21A0000
unkown
page read and write
clean
279000
unkown
page read and write
clean
4482000
unkown
page readonly
clean
44F4000
unkown
page readonly
clean
137000
unkown
page read and write
clean
4C6000
unkown
page read and write
clean
4675000
unkown
page readonly
clean
1A4000
heap private
page read and write
clean
484000
heap private
page read and write
clean
497000
unkown
page read and write
clean
530000
unkown
page readonly
clean
4514000
unkown
page readonly
clean
45A6000
unkown
page readonly
clean
44F5000
unkown
page readonly
clean
24E000
unkown
page read and write
clean
4997000
unkown
page readonly
clean
137000
unkown
page read and write
clean
4652000
unkown
page readonly
clean
1DE000
heap default
page read and write
clean
107000
unkown
page read and write
clean
4228000
unkown
page readonly
clean
4595000
unkown
page readonly
clean
4636000
unkown
page readonly
clean
CA000
heap default
page read and write
clean
48C0000
unkown
page readonly
clean
4639000
unkown
page readonly
clean
4546000
unkown
page readonly
clean
46B9000
unkown
page readonly
clean
3F30000
heap private
page read and write
clean
1FA000
heap default
page read and write
clean
44B2000
unkown
page readonly
clean
43E2000
unkown
page readonly
clean
44C5000
unkown
page readonly
clean
3E05000
heap private
page read and write
clean
260000
unkown
page read and write
clean
4DB000
unkown
page read and write
clean
284000
unkown
page read and write
clean
45F5000
unkown
page readonly
clean
F5000
unkown
page read and write
clean
4424000
unkown
page readonly
clean
160000
unkown
page read and write
clean
190000
unkown
page execute and read and write
clean
4495000
unkown
page readonly
clean
4615000
unkown
page readonly
clean
B1F000
unkown
page read and write
clean
4C6000
unkown
page read and write
clean
266000
unkown
page read and write
clean
20000
unkown
page readonly
clean
520000
heap private
page read and write
clean
4C6000
unkown
page read and write
clean
4682000
unkown
page readonly
clean
44D6000
unkown
page readonly
clean
4606000
unkown
page readonly
clean
4612000
unkown
page readonly
clean
4712000
unkown
page readonly
clean
F2000
unkown
page read and write
clean
26D000
unkown
page read and write
clean
27D000
unkown
page read and write
clean
4402000
unkown
page readonly
clean
4B2000
unkown
page read and write
clean
20B0000
unkown
page write copy
clean
3E09000
heap private
page read and write
clean
137000
unkown
page read and write
clean
1FE0000
unkown
page readonly
clean
2D6000
unkown
page read and write
clean
48A0000
unkown
page readonly
clean
4506000
unkown
page readonly
clean
266000
unkown
page read and write
clean
4652000
unkown
page readonly
clean
233000
unkown
page read and write
clean
46A000
unkown
page read and write
clean
4535000
unkown
page readonly
clean
4465000
unkown
page readonly
clean
4AC7000
unkown
page readonly
clean
490000
unkown
page read and write
clean
317000
heap default
page read and write
clean
4322000
unkown
page readonly
clean
27B000
unkown
page read and write
clean
46B2000
unkown
page readonly
clean
1F20000
unkown
page read and write
clean
14B000
unkown
page read and write
clean
252000
unkown
page read and write
clean
45F2000
unkown
page readonly
clean
4545000
unkown
page readonly
clean
A9000
unkown
page read and write
clean
3E80000
unkown
page readonly
clean
20000
unkown
page readonly
clean
47B0000
unkown
page readonly
clean
14D000
unkown
page read and write
clean
There are 310 hidden memdumps, click here to show them.