IOCReport

loading gif

Files

File Path
Type
Category
Malicious
Permission-1984690372-06252021.xlsm
Microsoft Excel 2007+
initial sample
malicious
C:\Users\user\Desktop\~$Permission-1984690372-06252021.xlsm
data
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\94954BDE.jpg
[TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS6 (Windows), datetime=2021:02:11 21:11:18], baseline, precision 8, 1860x1000, frames 3
dropped
clean
C:\Users\user\AppData\Local\Temp\EBCE0000
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Tue Oct 17 10:04:00 2017, mtime=Sat Jun 26 00:28:37 2021, atime=Sat Jun 26 00:28:37 2021, length=8192, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Permission-1984690372-06252021.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Aug 26 14:08:13 2020, mtime=Sat Jun 26 00:28:37 2021, atime=Sat Jun 26 00:28:37 2021, length=153117, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\Desktop\7CCE0000
data
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 ..\Kro.fis
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 ..\Kro.fis1
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 ..\Kro.fis2
malicious

URLs

Name
IP
Malicious
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://investor.msn.com/
unknown
clean
http://190.14.37.3/44372.7698814815.dat
190.14.37.3
clean
http://www.%s.comPA
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://servername/isapibackend.dll
unknown
clean
http://185.183.99.120/44372.7698814815.dat
185.183.99.120
clean
There are 3 hidden URLs, click here to show them.

IPs

IP
Domain
Country
Malicious
190.14.37.3
unknown
Panama
clean
185.183.99.120
unknown
Netherlands
clean
185.240.103.219
unknown
Russian Federation
clean

Registry

Path
Value
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
,/9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
MTTT
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ReviewToken
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EC69A
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
VBAFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DefaultSheetR2L
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
UseSystemSeparators
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ThousandsSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DecimalSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ECA80
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ECB7A
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ECC44
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ECCA2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} {000214E6-0000-0000-C000-000000000046} 0xFFFF
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
.99
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
LastPurgeTime
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F9222
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F9482
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EXCELFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SavedLegacySettings
clean
There are 95 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
20F0000
heap private
page read and write
clean
46F2000
unkown
page readonly
clean
F0000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
4645000
unkown
page readonly
clean
210000
unkown
page read and write
clean
47C2000
unkown
page readonly
clean
46C5000
unkown
page readonly
clean
20BB000
heap private
page read and write
clean
4534000
unkown
page readonly
clean
465D000
unkown
page readonly
clean
1CB0000
unkown
page readonly
clean
4472000
unkown
page readonly
clean
2C5000
unkown
page read and write
clean
1C4000
unkown
page read and write
clean
45F2000
unkown
page readonly
clean
1D6000
unkown
page read and write
clean
4990000
unkown
page readonly
clean
195000
unkown
page read and write
clean
4522000
unkown
page readonly
clean
2A0000
unkown
page read and write
clean
3BA0000
unkown
page readonly
clean
48A0000
unkown
page readonly
clean
4045000
heap private
page read and write
clean
2C5000
unkown
page read and write
clean
45C5000
unkown
page readonly
clean
1BA000
unkown
page read and write
clean
22D000
unkown
page read and write
clean
3F59000
heap private
page read and write
clean
47E5000
unkown
page readonly
clean
20F5000
heap private
page read and write
clean
1CC0000
unkown
page readonly
clean
216000
unkown
page read and write
clean
73F000
unkown
page read and write
clean
3F0000
unkown
page write copy
clean
47B5000
unkown
page readonly
clean
210000
unkown
page readonly
clean
4378000
unkown
page readonly
clean
3E0000
unkown
page read and write
clean
2005000
heap private
page read and write
clean
45F6000
unkown
page readonly
clean
45D2000
unkown
page readonly
clean
47E2000
unkown
page readonly
clean
300000
unkown
page read and write
clean
2ED000
unkown
page read and write
clean
1D0000
unkown
page read and write
clean
210000
unkown
page read and write
clean
2BE000
unkown
page read and write
clean
19C000
unkown
page read and write
clean
240000
heap default
page read and write
clean
2AE000
unkown
page read and write
clean
4602000
unkown
page readonly
clean
4656000
unkown
page readonly
clean
110000
heap default
page read and write
clean
247000
heap default
page read and write
clean
3E8F000
unkown
page read and write
clean
110000
unkown
page execute and read and write
clean
44D2000
unkown
page readonly
clean
4642000
unkown
page readonly
clean
1BE000
unkown
page read and write
clean
3F50000
unkown
page readonly
clean
20000
unkown
page readonly
clean
1D50000
unkown
page readonly
clean
1FD000
unkown
page read and write
clean
4372000
unkown
page readonly
clean
3F55000
heap private
page read and write
clean
820000
unkown
page readonly
clean
4746000
unkown
page readonly
clean
210000
unkown
page read and write
clean
4769000
unkown
page readonly
clean
31B000
unkown
page read and write
clean
1ED000
unkown
page read and write
clean
4572000
unkown
page readonly
clean
4792000
unkown
page readonly
clean
1F4000
unkown
page read and write
clean
47C9000
unkown
page readonly
clean
1D2000
unkown
page read and write
clean
4672000
unkown
page readonly
clean
4785000
unkown
page readonly
clean
4C4000
heap private
page read and write
clean
1A7000
unkown
page read and write
clean
1ED000
unkown
page read and write
clean
117000
heap default
page read and write
clean
2D3000
unkown
page read and write
clean
60000
unkown
page readonly
clean
4664000
unkown
page readonly
clean
720000
unkown
page readonly
clean
216000
unkown
page read and write
clean
203B000
heap private
page read and write
clean
120000
unkown
page readonly
clean
130000
unkown
page readonly
clean
2570000
unkown
page readonly
clean
46B6000
unkown
page readonly
clean
4565000
unkown
page readonly
clean
46D2000
unkown
page readonly
clean
4DDE000
unkown
page read and write
clean
2080000
unkown
page readonly
clean
710000
unkown
page readonly
clean
45A2000
unkown
page readonly
clean
F9000
unkown
page read and write
clean
80000
unkown
page read and write
clean
4562000
unkown
page readonly
clean
1D0000
unkown
page read and write
clean
340000
unkown
page read and write
clean
48E0000
unkown
page readonly
clean
46E6000
unkown
page readonly
clean
1DC000
unkown
page read and write
clean
216000
unkown
page read and write
clean
163000
heap default
page read and write
clean
3B0000
unkown
page read and write
clean
2220000
unkown
page read and write
clean
4462000
unkown
page readonly
clean
4552000
unkown
page readonly
clean
16A000
heap default
page read and write
clean
44B4000
unkown
page readonly
clean
45E5000
unkown
page readonly
clean
2160000
unkown
page write copy
clean
150000
heap default
page read and write
clean
4622000
unkown
page readonly
clean
210000
unkown
page read and write
clean
3A80000
unkown
page readonly
clean
4716000
unkown
page readonly
clean
31D000
heap default
page read and write
clean
2250000
unkown
page write copy
clean
566000
unkown
page read and write
clean
400000
heap private
page read and write
clean
4C6000
unkown
page read and write
clean
416000
unkown
page read and write
clean
46D9000
unkown
page readonly
clean
E0000
unkown
page read and write
clean
45B2000
unkown
page readonly
clean
44B2000
unkown
page readonly
clean
3A0000
unkown
page readonly
clean
192000
unkown
page read and write
clean
195000
unkown
page read and write
clean
45A6000
unkown
page readonly
clean
480000
heap private
page read and write
clean
326000
heap default
page read and write
clean
204000
unkown
page read and write
clean
1C2000
unkown
page read and write
clean
630000
unkown
page readonly
clean
1E7000
unkown
page read and write
clean
306000
unkown
page read and write
clean
48C0000
unkown
page readonly
clean
2080000
heap private
page read and write
clean
2D7000
unkown
page read and write
clean
100000
unkown
page read and write
clean
4C0000
heap private
page read and write
clean
3FF0000
unkown
page readonly
clean
544000
heap private
page read and write
clean
404000
heap private
page read and write
clean
3F70000
unkown
page readonly
clean
2E0000
heap default
page read and write
clean
4952000
unkown
page readonly
clean
4799000
unkown
page readonly
clean
46C2000
unkown
page readonly
clean
4722000
unkown
page readonly
clean
524000
heap private
page read and write
clean
474D000
unkown
page readonly
clean
44F4000
unkown
page readonly
clean
4749000
unkown
page readonly
clean
43F2000
unkown
page readonly
clean
39B0000
unkown
page readonly
clean
4645000
unkown
page readonly
clean
590000
unkown
page readonly
clean
157000
heap default
page read and write
clean
4546000
unkown
page readonly
clean
2100000
unkown
page readonly
clean
5A0000
unkown
page readonly
clean
4AE7000
unkown
page readonly
clean
300000
unkown
page read and write
clean
17E000
unkown
page read and write
clean
540000
heap private
page read and write
clean
2E7000
heap default
page read and write
clean
4662000
unkown
page readonly
clean
3ED9000
heap private
page read and write
clean
29A000
heap default
page read and write
clean
42F2000
unkown
page readonly
clean
4820000
unkown
page readonly
clean
46A2000
unkown
page readonly
clean
2170000
unkown
page readonly
clean
4532000
unkown
page readonly
clean
4762000
unkown
page readonly
clean
17A000
unkown
page read and write
clean
46A5000
unkown
page readonly
clean
4900000
unkown
page readonly
clean
293000
heap default
page read and write
clean
3D0000
heap private
page read and write
clean
49F0000
unkown
page readonly
clean
2C0000
unkown
page read and write
clean
494000
heap private
page read and write
clean
130000
unkown
page write copy
clean
1D6000
unkown
page read and write
clean
45C6000
unkown
page readonly
clean
40E0000
unkown
page readonly
clean
2280000
unkown
page read and write
clean
140000
unkown
page write copy
clean
4705000
unkown
page readonly
clean
40C0000
unkown
page readonly
clean
4659000
unkown
page readonly
clean
14E000
heap default
page read and write
clean
4652000
unkown
page readonly
clean
4692000
unkown
page readonly
clean
216000
unkown
page read and write
clean
4615000
unkown
page readonly
clean
1A3000
unkown
page read and write
clean
7B0000
unkown
page readonly
clean
22B000
unkown
page read and write
clean
1D0000
unkown
page read and write
clean
31D000
unkown
page read and write
clean
4574000
unkown
page readonly
clean
4629000
unkown
page readonly
clean
2C2000
unkown
page read and write
clean
250000
unkown
page readonly
clean
4679000
unkown
page readonly
clean
1D6000
unkown
page read and write
clean
4624000
unkown
page readonly
clean
45D6000
unkown
page readonly
clean
70000
unkown
page read and write
clean
20000
unkown
page readonly
clean
4BD7000
unkown
page readonly
clean
490000
unkown
page read and write
clean
42F8000
unkown
page readonly
clean
20000
unkown
page readonly
clean
1FC0000
unkown
page write copy
clean
324000
unkown
page read and write
clean
2F6000
unkown
page read and write
clean
70000
unkown
page readonly
clean
1D0000
unkown
page read and write
clean
4468000
unkown
page readonly
clean
4632000
unkown
page readonly
clean
4862000
unkown
page readonly
clean
520000
heap private
page read and write
clean
202000
unkown
page read and write
clean
18E000
heap default
page read and write
clean
306000
unkown
page read and write
clean
32B000
heap default
page read and write
clean
49D0000
unkown
page readonly
clean
3F50000
heap private
page read and write
clean
4049000
heap private
page read and write
clean
4659000
unkown
page readonly
clean
1FE000
unkown
page read and write
clean
2EE000
unkown
page read and write
clean
2000000
heap private
page read and write
clean
45F9000
unkown
page readonly
clean
2D6000
unkown
page read and write
clean
3D4000
heap private
page read and write
clean
45DD000
unkown
page readonly
clean
4576000
unkown
page readonly
clean
4595000
unkown
page readonly
clean
4675000
unkown
page readonly
clean
3FD0000
unkown
page readonly
clean
67F000
unkown
page read and write
clean
1A3000
heap default
page read and write
clean
1AA000
heap default
page read and write
clean
70000
unkown
page read and write
clean
3ED0000
heap private
page read and write
clean
4626000
unkown
page readonly
clean
2F4000
unkown
page read and write
clean
1EB000
unkown
page read and write
clean
4735000
unkown
page readonly
clean
46F5000
unkown
page readonly
clean
120000
unkown
page execute and read and write
clean
212B000
heap private
page read and write
clean
2CC000
unkown
page read and write
clean
4860000
unkown
page readonly
clean
1C9000
unkown
page read and write
clean
3ED5000
heap private
page read and write
clean
4040000
heap private
page read and write
clean
2F2000
unkown
page read and write
clean
14F000
unkown
page read and write
clean
376000
unkown
page read and write
clean
2AA000
unkown
page read and write
clean
490000
heap private
page read and write
clean
1D5000
unkown
page read and write
clean
119000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
1BD000
unkown
page read and write
clean
2085000
heap private
page read and write
clean
23AE000
unkown
page read and write
clean
1D0000
unkown
page read and write
clean
300000
unkown
page read and write
clean
46A9000
unkown
page readonly
clean
4622000
unkown
page readonly
clean
530000
unkown
page read and write
clean
4D6000
unkown
page read and write
clean
4A67000
unkown
page readonly
clean
234000
unkown
page read and write
clean
2470000
unkown
page read and write
clean
306000
unkown
page read and write
clean
1D6000
unkown
page read and write
clean
306000
unkown
page read and write
clean
1D5000
unkown
page read and write
clean
44D4000
unkown
page readonly
clean
45D9000
unkown
page readonly
clean
300000
unkown
page read and write
clean
4615000
unkown
page readonly
clean
4880000
unkown
page readonly
clean
45B5000
unkown
page readonly
clean
4695000
unkown
page readonly
clean
484000
heap private
page read and write
clean
49B0000
unkown
page readonly
clean
4554000
unkown
page readonly
clean
1E3000
unkown
page read and write
clean
4535000
unkown
page readonly
clean
4552000
unkown
page readonly
clean
4582000
unkown
page readonly
clean
46D5000
unkown
page readonly
clean
27E000
heap default
page read and write
clean
2380000
unkown
page readonly
clean
44F2000
unkown
page readonly
clean
4644000
unkown
page readonly
clean
1BE000
unkown
page read and write
clean
290000
unkown
page execute and read and write
clean
4840000
unkown
page readonly
clean
2450000
unkown
page readonly
clean
There are 306 hidden memdumps, click here to show them.