IOCReport

loading gif

Files

File Path
Type
Category
Malicious
KnZsSmDyF3.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\AppData\LocalLow\1xVPfvJcrg
SQLite 3.x database, last written using SQLite version 3032001
dropped
clean
C:\Users\user\AppData\LocalLow\Pyg336PceKk.zip
Zip archive data, at least v2.0 to extract
dropped
clean
C:\Users\user\AppData\LocalLow\RYwTiizs2t
SQLite 3.x database, last written using SQLite version 3032001
dropped
clean
C:\Users\user\AppData\LocalLow\frAQBc8Wsa
SQLite 3.x database, last written using SQLite version 3032001
dropped
clean
C:\Users\user\AppData\LocalLow\machineinfo.txt
ASCII text, with CRLF, CR line terminators
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\AccessibleHandler.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\AccessibleMarshal.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\IA2Marshal.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\MapiProxy.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\MapiProxy_InUse.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\api-ms-win-core-file-l1-2-0.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\api-ms-win-core-file-l2-1-0.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\api-ms-win-core-handle-l1-1-0.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\api-ms-win-core-heap-l1-1-0.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\api-ms-win-core-interlocked-l1-1-0.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\api-ms-win-core-libraryloader-l1-1-0.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\api-ms-win-core-localization-l1-2-0.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\api-ms-win-core-memory-l1-1-0.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\api-ms-win-core-namedpipe-l1-1-0.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\api-ms-win-core-processenvironment-l1-1-0.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\api-ms-win-core-processthreads-l1-1-0.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\api-ms-win-core-processthreads-l1-1-1.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\api-ms-win-core-profile-l1-1-0.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\api-ms-win-core-rtlsupport-l1-1-0.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\api-ms-win-core-string-l1-1-0.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\api-ms-win-core-synch-l1-1-0.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\api-ms-win-core-synch-l1-2-0.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\api-ms-win-core-sysinfo-l1-1-0.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\api-ms-win-core-timezone-l1-1-0.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\api-ms-win-core-util-l1-1-0.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\api-ms-win-crt-conio-l1-1-0.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\api-ms-win-crt-convert-l1-1-0.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\api-ms-win-crt-environment-l1-1-0.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\api-ms-win-crt-filesystem-l1-1-0.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\api-ms-win-crt-heap-l1-1-0.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\api-ms-win-crt-locale-l1-1-0.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\api-ms-win-crt-math-l1-1-0.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\api-ms-win-crt-multibyte-l1-1-0.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\api-ms-win-crt-private-l1-1-0.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\api-ms-win-crt-process-l1-1-0.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\api-ms-win-crt-runtime-l1-1-0.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\api-ms-win-crt-stdio-l1-1-0.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\api-ms-win-crt-string-l1-1-0.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\api-ms-win-crt-time-l1-1-0.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\api-ms-win-crt-utility-l1-1-0.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\breakpadinjector.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\freebl3.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\iV7fW1cG3y_.zip
Zip archive data, at least v2.0 to extract
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\ldap60.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\ldif60.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\lgpllibs.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\libEGL.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\mozMapi32.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\mozMapi32_InUse.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\mozglue.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\msvcp140.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\nss3.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\nssckbi.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\nssdbm3.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\prldap60.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\qipcap.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\softokn3.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\ucrtbase.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\nW6mI-7yS1k\vcruntime140.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\LocalLow\rQF69AzBla
SQLite 3.x database, last written using SQLite version 3032001
dropped
clean
C:\Users\user\AppData\LocalLow\sqlite3.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
There are 57 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\KnZsSmDyF3.exe
'C:\Users\user\Desktop\KnZsSmDyF3.exe'
malicious

URLs

Name
IP
Malicious
https://telete.in/org/img/t_logo.png
unknown
malicious
https://telete.in/jagressor_kz
malicious
https://telete.in/jagressor_kzn-
unknown
malicious
https://duckduckgo.com/chrome_newtab
unknown
clean
http://www.mozilla.com/en-US/blocklist/
unknown
clean
http://94.228.114.197//l/f/t--ny3oBagrSXdgRr-eA/ae3c4e3333af17553eef71298da070dcf215425f2y
unknown
clean
https://duckduckgo.com/ac/?q=
unknown
clean
http://94.228.114.197//l/f/t--ny3oBagrSXdgRr-eA/65fddda9bf877b11988a80a9c7a03ff1ac6a108f277U
unknown
clean
http://94.228.114.197/2t
unknown
clean
https://www.google.com/chrome/thank-you.html?statcb=0&installdataindex=empty&defaultbrowser=0renc
unknown
clean
https://www.google.com/images/branding/product/ico/googleg_lodp.ico
unknown
clean
http://cps.letsencrypt.org0
unknown
clean
https://support.google.com/chrome/?p=pV
unknown
clean
http://94.228.114.197//l/f/t--ny3oBagrSXdgRr-eA/ae3c4e3333af17553eef71298da070dcf215425f4
unknown
clean
http://r3.i.lencr.org/0Y
unknown
clean
https://support.google.com/chrome/answer/6258784
unknown
clean
http://94.228.114.197/
94.228.114.197
clean
http://ocsp.thawte.com0
unknown
clean
http://www.mozilla.com0
unknown
clean
https://www.google.com/chrome/static/images/favicons/favicon-16x16.png
unknown
clean
http://94.228.114.197/I_
unknown
clean
https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
unknown
clean
https://support.google.com/chrome/?p=plugin_flash
unknown
clean
https://search.yahoo.com/favicon.icohttps://search.yahoo.com/search
unknown
clean
http://94.228.114.197/S
unknown
clean
https://www.google.com/chrome/thank-you.html?statcb=0&installdataindex=empty&defaultbrowser=0n_
unknown
clean
http://94.228.114.197//l/f/t--ny3oBagrSXdgRr-eA/ae3c4e3333af17553eef71298da070dcf215425f
94.228.114.197
clean
https://www.google.com/chrome/thank-you.html?statcb=0&installdataindex=empty&defaultbrowser=0H
unknown
clean
https://www.google.com/chrome/thank-you.htmlstatcb=0&installdataindex=empty&defaultbrowser=0
unknown
clean
https://ac.ecosia.org/autocomplete?q=
unknown
clean
http://crl.thawte.com/ThawteTimestampingCA.crl0
unknown
clean
https://support.google.com/chrome/?p=plugin_shockwave
unknown
clean
http://x1.c.lencr.org/0
unknown
clean
http://x1.i.lencr.org/0
unknown
clean
http://r3.o.lencr.org0
unknown
clean
http://94.228.114.197
unknown
clean
https://www.google.com/chrome/thank-you.html?statcb=0&installdataindex=empty&defaultbrowser=0
unknown
clean
https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
unknown
clean
http://94.228.114.197/dhHq
unknown
clean
http://94.228.114.197//l/f/t--ny3oBagrSXdgRr-eA/65fddda9bf877b11988a80a9c7a03ff1ac6a108f=jsonoL
unknown
clean
http://www.sqlite.org/copyright.html.
unknown
clean
http://94.228.114.197//l/f/t--ny3oBagrSXdgRr-eA/65fddda9bf877b11988a80a9c7a03ff1ac6a108f
94.228.114.197
clean
http://cps.root-x1.letsencrypt.org0
unknown
clean
https://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
unknown
clean
https://wa228.114.197/
unknown
clean
There are 35 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
telete.in
195.201.225.248
malicious

IPs

IP
Domain
Country
Malicious
195.201.225.248
telete.in
Germany
malicious
94.228.114.197
unknown
Russian Federation
clean

Memdumps

Base Address
Regiontype
Protect
Malicious
2770000
unkown
page read and write
malicious
400000
unkown image
page execute and read and write
malicious
2670000
unkown
page execute and read and write
malicious
7FF514C59000
unkown
page readonly
clean
DB0000
unkown
page read and write
clean
169A0F00000
unkown
page read and write
clean
2C1D000
unkown
page read and write
clean
60FB47F000
unkown
page read and write
clean
400000
unkown image
page readonly
clean
CC0000
heap private
page read and write
clean
326000
unkown
page read and write
clean
7FF514C76000
unkown
page readonly
clean
6E2F6000
unkown image
page write copy
clean
6E1D1000
unkown image
page execute read
clean
169A0E3C000
unkown
page read and write
clean
7FF514ACE000
unkown
page readonly
clean
4BA70000
unkown
page readonly
clean
169A0D70000
unkown
page readonly
clean
4C860000
unkown
page read and write
clean
7FF514CA4000
unkown
page readonly
clean
60FAD6E000
unkown
page read and write
clean
9E0000
unkown
page readonly
clean
CB0000
unkown
page read and write
clean
7FF514B41000
unkown
page readonly
clean
7FF514D09000
unkown
page readonly
clean
7FF514C18000
unkown
page readonly
clean
169A0F08000
unkown
page read and write
clean
4C8CB000
unkown
page read and write
clean
4C87A000
unkown
page read and write
clean
2ADD000
unkown
page read and write
clean
7FF514CA7000
unkown
page readonly
clean
AEE000
unkown
page read and write
clean
4C8B7000
unkown
page read and write
clean
DCD000
unkown
page read and write
clean
9C0000
unkown image
page read and write
clean
169A0C90000
unkown
page readonly
clean
169A0E55000
unkown
page read and write
clean
7FF514C3E000
unkown
page readonly
clean
7FF514C6D000
unkown
page readonly
clean
32F000
unkown
page read and write
clean
7FF514D09000
unkown
page readonly
clean
4B97F000
unkown
page read and write
clean
6E1D0000
unkown image
page readonly
clean
6E181000
unkown image
page execute read
clean
ECF000
unkown
page read and write
clean
28D0000
heap private
page read and write
clean
DC6000
unkown
page read and write
clean
29DF000
unkown
page read and write
clean
D54000
unkown
page read and write
clean
C8E000
unkown
page read and write
clean
7FF514CA0000
unkown
page readonly
clean
7FF514C02000
unkown
page readonly
clean
7FF514B7C000
unkown
page readonly
clean
2760000
heap private
page read and write
clean
4C8D3000
unkown
page read and write
clean
DBB000
unkown
page read and write
clean
169A0E2A000
unkown
page read and write
clean
4B995000
unkown
page read and write
clean
4BCFE000
unkown
page read and write
clean
7FF514C4F000
unkown
page readonly
clean
329000
unkown
page read and write
clean
401000
unkown image
page execute read
clean
28D7000
heap private
page read and write
clean
D56000
unkown
page read and write
clean
B2E000
unkown
page read and write
clean
DBC000
unkown
page read and write
clean
6E2FB000
unkown image
page readonly
clean
169A0E7D000
unkown
page read and write
clean
169A0E6C000
unkown
page read and write
clean
7FF514B1D000
unkown
page readonly
clean
4C861000
unkown
page read and write
clean
CB0000
unkown
page read and write
clean
B40000
heap default
page read and write
clean
6E2C0000
unkown image
page readonly
clean
DC3000
unkown
page read and write
clean
6E1D0000
unkown image
page readonly
clean
4B998000
unkown
page read and write
clean
28CE000
unkown
page read and write
clean
32C000
unkown
page read and write
clean
169A1602000
unkown
page read and write
clean
C90000
unkown
page readonly
clean
7FF514C2A000
unkown
page readonly
clean
60FB0F5000
unkown
page read and write
clean
9D6000
unkown image
page readonly
clean
6E199000
unkown image
page readonly
clean
C4F000
unkown
page read and write
clean
319000
unkown
page read and write
clean
7FF514C12000
unkown
page readonly
clean
D5C000
unkown
page read and write
clean
335000
unkown
page read and write
clean
7FF514C7C000
unkown
page readonly
clean
ED0000
unkown
page readonly
clean
B30000
unkown
page readonly
clean
60FADEE000
unkown
page read and write
clean
D70000
unkown
page read and write
clean
4B960000
unkown
page read and write
clean
D70000
unkown
page read and write
clean
6E1A0000
unkown image
page read and write
clean
4BE10000
unkown
page readonly
clean
7FF514810000
unkown
page readonly
clean
6E1A2000
unkown image
page readonly
clean
D63000
unkown
page read and write
clean
4B97B000
unkown
page read and write
clean
31DE000
unkown
page read and write
clean
286F000
unkown
page read and write
clean
274E000
unkown
page read and write
clean
2B1D000
unkown
page read and write
clean
9D6000
unkown image
page readonly
clean
2880000
heap private
page read and write
clean
D5C000
unkown
page read and write
clean
4BE50000
unkown
page read and write
clean
CB0000
unkown
page readonly
clean
4C8D5000
unkown
page read and write
clean
4B982000
unkown
page read and write
clean
26F9000
unkown
page execute and read and write
clean
7FF514D01000
unkown
page readonly
clean
4C8CD000
unkown
page read and write
clean
169A0C80000
heap default
page read and write
clean
60FB377000
unkown
page read and write
clean
CB0000
unkown
page read and write
clean
169A0F02000
unkown
page read and write
clean
199000
unkown
page read and write
clean
9C000
unkown
page read and write
clean
4B984000
unkown
page read and write
clean
169A1460000
unkown
page readonly
clean
31D000
unkown
page read and write
clean
6E2F8000
unkown image
page read and write
clean
4BDFF000
unkown
page read and write
clean
2750000
unkown
page readonly
clean
CD0000
heap default
page read and write
clean
169A0D60000
unkown
page readonly
clean
7FF514B47000
unkown
page readonly
clean
7FF514AF8000
unkown
page readonly
clean
61E00000
unkown image
page readonly
clean
4B989000
unkown
page read and write
clean
7FF514C16000
unkown
page readonly
clean
DBB000
unkown
page read and write
clean
6E180000
unkown image
page readonly
clean
60FACEB000
unkown
page read and write
clean
4C890000
unkown
page read and write
clean
7FF514800000
unkown
page readonly
clean
169A0E8A000
unkown
page read and write
clean
169A0E02000
unkown
page read and write
clean
9C4000
unkown image
page readonly
clean
7FF514C45000
unkown
page readonly
clean
30DE000
unkown
page read and write
clean
169A0E4F000
unkown
page read and write
clean
464000
unkown image
page write copy
clean
169A0F13000
unkown
page read and write
clean
169A0D80000
unkown
page read and write
clean
4B998000
unkown
page read and write
clean
4B996000
unkown
page read and write
clean
7FF514B13000
unkown
page readonly
clean
DC0000
unkown
page read and write
clean
60FB1FB000
unkown
page read and write
clean
9C4000
unkown image
page readonly
clean
4B97F000
unkown
page read and write
clean
169A0C20000
heap private
page read and write
clean
4C8BB000
unkown
page read and write
clean
6E180000
unkown image
page readonly
clean
4C890000
unkown
page read and write
clean
2F9E000
unkown
page read and write
clean
332000
unkown
page read and write
clean
4B9AF000
unkown
page read and write
clean
4C850000
unkown
page read and write
clean
7FF514A8F000
unkown
page readonly
clean
169A1000000
unkown
page readonly
clean
D36000
unkown
page read and write
clean
169A1800000
unkown
page readonly
clean
7FF514C00000
unkown
page readonly
clean
DC7000
unkown
page read and write
clean
1F0000
unkown
page read and write
clean
2C20000
unkown
page readonly
clean
169A0E00000
unkown
page read and write
clean
169A0E8E000
unkown
page read and write
clean
4C88B000
unkown
page read and write
clean
DCB000
unkown
page read and write
clean
309F000
unkown
page read and write
clean
4C869000
unkown
page read and write
clean
169A0E13000
unkown
page read and write
clean
7FF514C86000
unkown
page readonly
clean
CE6000
unkown
page execute and read and write
clean
400000
unkown image
page readonly
clean
CDA000
heap default
page read and write
clean
7FF514A2A000
unkown
page readonly
clean
7FF514CFE000
unkown
page readonly
clean
27F8000
unkown
page read and write
clean
7FF514ADA000
unkown
page readonly
clean
60FB57F000
unkown
page read and write
clean
7FF514C8C000
unkown
page readonly
clean
4C8AD000
unkown
page read and write
clean
CA0000
unkown
page readonly
clean
60FB27E000
unkown
page read and write
clean
7FF51495D000
unkown
page readonly
clean
DB0000
unkown
page read and write
clean
7FF5147FA000
unkown
page readonly
clean
7FF514C95000
unkown
page readonly
clean
There are 187 hidden memdumps, click here to show them.