IOCReport

loading gif

Files

File Path
Type
Category
Malicious
VjLfUM5cMx.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{077FA0D4-11F8-11EC-90EB-ECF4BBEA1588}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{E1A18F6F-11F7-11EC-90EB-ECF4BBEA1588}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{077FA0D6-11F8-11EC-90EB-ECF4BBEA1588}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{E1A18F71-11F7-11EC-90EB-ECF4BBEA1588}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-17529550060\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-18270793970\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-21706820\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-4759708130\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-6757900\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-8760897390\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20259167780\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20332743330\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin8215062560\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\NewErrorPageTemplate[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\dnserror[1]
HTML document, UTF-8 Unicode (with BOM) text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\errorPageStrings[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\httpErrorPagesScripts[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\down[1]
PNG image data, 15 x 15, 8-bit colormap, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\NewErrorPageTemplate[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\dnserror[1]
HTML document, UTF-8 Unicode (with BOM) text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\errorPageStrings[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\down[1]
PNG image data, 15 x 15, 8-bit colormap, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\httpErrorPagesScripts[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\JavaDeployReg.log
ASCII text, with CRLF line terminators
modified
clean
C:\Users\user\AppData\Local\Temp\~DF53DFCC907A82F6AE.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DFB3B5364D27108BD7.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DFCE99751527B74E99.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DFD3F956B20687A278.TMP
data
dropped
clean
There are 19 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\VjLfUM5cMx.exe
'C:\Users\user\Desktop\VjLfUM5cMx.exe'
malicious
C:\Program Files (x86)\Internet Explorer\iexplore.exe
'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:2856 CREDAT:17410 /prefetch:2
malicious
C:\Program Files (x86)\Internet Explorer\iexplore.exe
'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:1492 CREDAT:17410 /prefetch:2
malicious
C:\Program Files\internet explorer\iexplore.exe
'C:\Program Files\Internet Explorer\iexplore.exe' -Embedding
clean
C:\Program Files\internet explorer\iexplore.exe
'C:\Program Files\Internet Explorer\iexplore.exe' -Embedding
clean

URLs

Name
IP
Malicious
https://haverit.xyz/index.htm
unknown
clean
https://haverit.xyz/index.htmr#
unknown
clean
http://www.nytimes.com/
unknown
clean
https://sectigo.com/CPS0
unknown
clean
http://ocsp.sectigo.com0
unknown
clean
https://haverit.xyz/index.htmdex.htm
unknown
clean
http://%s=%s&file://&os=%u.%u_%u_%u_x%uindex.html;
unknown
clean
http://www.youtube.com/
unknown
clean
http://www.wikipedia.com/
unknown
clean
http://www.amazon.com/
unknown
clean
https://haverit.xyz
unknown
clean
http://crl.sectigo.com/SectigoRSACodeSigningCA.crl0s
unknown
clean
http://www.live.com/
unknown
clean
https://haverit.xyz/0b
unknown
clean
https://haverit.xyz/Q
unknown
clean
http://crt.sectigo.com/SectigoRSACodeSigningCA.crt0#
unknown
clean
http://www.reddit.com/
unknown
clean
http://www.twitter.com/
unknown
clean
https://haverit.xyz/index.htm&E
unknown
clean
https://haverit.xyz/index.htmRoot
unknown
clean
http://www.google.com/
unknown
clean
There are 11 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
haverit.xyz
unknown
malicious

Registry

Path
Value
Malicious
C:\Program Files\internet explorer\iexplore.exe
{E1A18F6F-11F7-11EC-90EB-ECF4BBEA1588}
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
Blocked
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\internet explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\internet explorer\iexplore.exe
CVListPingLastYMD
clean
C:\Program Files\internet explorer\iexplore.exe
CVListPingBitmap
clean
C:\Program Files\internet explorer\iexplore.exe
CVListPingRandomizedBitmap
clean
C:\Program Files\internet explorer\iexplore.exe
DecayDateQueue
clean
C:\Program Files\internet explorer\iexplore.exe
LastProcessed
clean
C:\Program Files\internet explorer\iexplore.exe
DecayDateQueue
clean
C:\Program Files\internet explorer\iexplore.exe
LastProcessed
clean
C:\Program Files\internet explorer\iexplore.exe
{077FA0D4-11F8-11EC-90EB-ECF4BBEA1588}
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
Blocked
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\internet explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\internet explorer\iexplore.exe
DecayDateQueue
clean
C:\Program Files\internet explorer\iexplore.exe
LastProcessed
clean
There are 19 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
3640000
heap private
page read and write
malicious
3640000
heap private
page read and write
malicious
3640000
heap private
page read and write
malicious
3640000
heap private
page read and write
malicious
3640000
heap private
page read and write
malicious
3640000
heap private
page read and write
malicious
3640000
heap private
page read and write
malicious
3640000
heap private
page read and write
malicious
3640000
heap private
page read and write
malicious
3640000
heap private
page read and write
malicious
3640000
heap private
page read and write
malicious
3640000
heap private
page read and write
malicious
3640000
heap private
page read and write
malicious
3640000
heap private
page read and write
malicious
3640000
heap private
page read and write
malicious
3640000
heap private
page read and write
malicious
3640000
heap private
page read and write
malicious
3640000
heap private
page read and write
malicious
3640000
heap private
page read and write
malicious
3640000
heap private
page read and write
malicious
3640000
heap private
page read and write
malicious
3640000
heap private
page read and write
malicious
3640000
heap private
page read and write
malicious
3640000
heap private
page read and write
malicious
3640000
heap private
page read and write
malicious
3640000
heap private
page read and write
malicious
3640000
heap private
page read and write
malicious
3640000
heap private
page read and write
malicious
3640000
heap private
page read and write
malicious
3640000
heap private
page read and write
malicious
3640000
heap private
page read and write
malicious
3640000
heap private
page read and write
malicious
3640000
heap private
page read and write
malicious
1DDCC174000
unkown
page read and write
clean
7FF515FCA000
unkown image
page readonly
clean
D70000
unkown image
page readonly
clean
7FF515AA0000
unkown image
page readonly
clean
1DDCC121000
unkown
page read and write
clean
E7E000
unkown
page read and write
clean
5C0000
unkown
page execute and read and write
clean
10EF000
unkown image
page readonly
clean
1DDCC116000
unkown
page read and write
clean
682000
unkown
page read and write
clean
E20000
unkown
page read and write
clean
1DDCC602000
unkown
page read and write
clean
10AD000
unkown image
page readonly
clean
7DF59B402000
unkown image
page readonly
clean
1DDCC1A3000
unkown
page read and write
clean
439EAFF000
unkown
page read and write
clean
7DF5FA1F0000
unkown image
page readonly
clean
1DDCC178000
unkown
page read and write
clean
3D2D000
unkown
page read and write
clean
7FF515EDA000
unkown image
page readonly
clean
1DE7147A000
unkown
page read and write
clean
7FF5E4F23000
unkown image
page readonly
clean
24287288000
unkown
page read and write
clean
23CF6F56000
heap default
page read and write
clean
20053108000
unkown
page read and write
clean
7FF58627C000
unkown image
page readonly
clean
7FF515AA6000
unkown image
page readonly
clean
7DF52B052000
unkown image
page readonly
clean
D52567F000
unkown
page read and write
clean
7FF524C08000
unkown image
page readonly
clean
1DDCC189000
unkown
page read and write
clean
3EFD277000
unkown
page read and write
clean
66A000
unkown
page read and write
clean
7DF59B402000
unkown image
page readonly
clean
67F000
unkown
page read and write
clean
450000
unkown
page execute and read and write
clean
2005306F000
unkown
page read and write
clean
24287313000
unkown
page read and write
clean
7DF428F20000
unkown image
page readonly
clean
2660000
heap private
page read and write
clean
7FF5D904F000
unkown image
page readonly
clean
7FF5D9007000
unkown image
page readonly
clean
1DDCB8BC000
unkown
page read and write
clean
7FF5E4E30000
unkown image
page readonly
clean
7FF524BFE000
unkown image
page readonly
clean
7FF524BD8000
unkown image
page readonly
clean
1DDCB8F5000
unkown
page read and write
clean
7FF5D8FDC000
unkown image
page readonly
clean
7FF5D9069000
unkown image
page readonly
clean
9F0000
unkown image
page readonly
clean
5C1000
unkown
page execute read
clean
7FF524BAB000
unkown image
page readonly
clean
108E000
unkown image
page read and write
clean
23CF7570000
unkown image
page readonly
clean
68A000
unkown
page read and write
clean
D52577F000
unkown
page read and write
clean
1DDCC178000
unkown
page read and write
clean
7DF52B070000
unkown image
page readonly
clean
7FF5D8E41000
unkown image
page readonly
clean
20053802000
unkown
page read and write
clean
DCB8B7F000
unkown
page read and write
clean
69E000
unkown
page read and write
clean
7FF515ECC000
unkown image
page readonly
clean
1DDCC1A3000
unkown
page read and write
clean
2650000
heap private
page read and write
clean
1DDCB858000
unkown
page read and write
clean
24287200000
unkown
page read and write
clean
20053013000
unkown
page read and write
clean
FFE000
unkown
page read and write
clean
5CE000
unkown
page readonly
clean
7FF515D31000
unkown image
page readonly
clean
DBD000
unkown
page read and write
clean
1DE71600000
unkown image
page readonly
clean
7DF5FA200000
unkown image
page readonly
clean
7FF524950000
unkown image
page readonly
clean
7FF515E4C000
unkown image
page readonly
clean
1DDCC150000
unkown
page read and write
clean
7DF52B062000
unkown image
page readonly
clean
7FF5E4F61000
unkown image
page readonly
clean
7FF5E5080000
unkown image
page readonly
clean
69E000
unkown
page read and write
clean
7FF5E5171000
unkown image
page readonly
clean
69E000
unkown
page read and write
clean
7FF5D901C000
unkown image
page readonly
clean
1DDCC16C000
unkown
page read and write
clean
1DDCB856000
unkown
page read and write
clean
1DDCB760000
heap private
page read and write
clean
1DDCC602000
unkown
page read and write
clean
7FF5D8D67000
unkown image
page readonly
clean
7FF5D8E93000
unkown image
page readonly
clean
1DE713E0000
unkown
page read and write
clean
7DF539D10000
unkown image
page readonly
clean
1DDCC181000
unkown
page read and write
clean
7FFB0000
unkown image
page readonly
clean
DCB870F000
unkown
page read and write
clean
7FF515D14000
unkown image
page readonly
clean
7FF585E50000
unkown image
page readonly
clean
7DF52B070000
unkown image
page readonly
clean
1DDCC172000
unkown
page read and write
clean
7DF4F80C0000
unkown image
page readonly
clean
20052F10000
unkown image
page readonly
clean
7FF515EE5000
unkown image
page readonly
clean
1DDCC1BA000
unkown
page read and write
clean
1000000
unkown image
page readonly
clean
1DDCC763000
unkown
page read and write
clean
7FF524C92000
unkown image
page readonly
clean
7FF5860E1000
unkown image
page readonly
clean
242870E0000
unkown image
page readonly
clean
242870C0000
unkown image
page read and write
clean
1DDCC189000
unkown
page read and write
clean
1DDCC172000
unkown
page read and write
clean
7FFC2000
unkown image
page readonly
clean
7FF5E48DD000
unkown image
page readonly
clean
67B000
unkown
page read and write
clean
1DDCC139000
unkown
page read and write
clean
7FF5D8FDA000
unkown image
page readonly
clean
1DDCB8C3000
unkown
page read and write
clean
7DF5EE160000
unkown image
page readonly
clean
1DDCC1AD000
unkown
page read and write
clean
7FF5D90E1000
unkown image
page readonly
clean
7FF524BF4000
unkown image
page readonly
clean
7DF59B420000
unkown image
page readonly
clean
24287213000
unkown
page read and write
clean
7FFC0000
unkown image
page readonly
clean
7FF5D8FF0000
unkown image
page readonly
clean
7FF5E50EE000
unkown image
page readonly
clean
1DDCC100000
unkown
page read and write
clean
1DDCB8A6000
unkown
page read and write
clean
1DE71486000
unkown
page read and write
clean
7FF5E50B7000
unkown image
page readonly
clean
1DDCC1C7000
unkown
page read and write
clean
7FF515EB4000
unkown image
page readonly
clean
7FF586040000
unkown image
page readonly
clean
7FF5D903A000
unkown image
page readonly
clean
628000
unkown
page read and write
clean
1DDCB850000
unkown
page read and write
clean
7FF586133000
unkown image
page readonly
clean
24287251000
unkown
page read and write
clean
7FF515837000
unkown image
page readonly
clean
1DE711C0000
unkown image
page readonly
clean
5FA000
heap default
page read and write
clean
68C000
unkown
page read and write
clean
6C2000
unkown
page read and write
clean
7FF515DE3000
unkown image
page readonly
clean
7FF5E516A000
unkown image
page readonly
clean
23CF6EA0000
unkown image
page read and write
clean
23CF6F6F000
unkown
page read and write
clean
7FF5E5085000
unkown image
page readonly
clean
3EFCE7B000
unkown
page read and write
clean
1DDCC189000
unkown
page read and write
clean
690000
unkown
page read and write
clean
7FF524BA5000
unkown image
page readonly
clean
1DDCB867000
unkown
page read and write
clean
23CF6EC0000
unkown image
page readonly
clean
7FF524C84000
unkown image
page readonly
clean
1DDCB770000
unkown image
page readonly
clean
1DDCBFE0000
unkown
page read and write
clean
9C000
unkown
page read and write
clean
7FF5D90DA000
unkown image
page readonly
clean
7FF58629B000
unkown image
page readonly
clean
DCB8F7E000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
D52587E000
unkown
page read and write
clean
7FFC2000
unkown image
page readonly
clean
7FF5D8BC5000
unkown image
page readonly
clean
1DDCB866000
unkown
page read and write
clean
1DE71429000
unkown
page read and write
clean
1DE71210000
heap default
page read and write
clean
1DDCB8EC000
unkown
page read and write
clean
1DE711C0000
unkown image
page readonly
clean
7FF5E4C46000
unkown image
page readonly
clean
7FF5D8847000
unkown image
page readonly
clean
6E56FAF000
unkown
page read and write
clean
1DDCB908000
unkown
page read and write
clean
DCB91FC000
unkown
page read and write
clean
7FF515F59000
unkown image
page readonly
clean
23CF7120000
unkown image
page readonly
clean
DCB868C000
unkown
page read and write
clean
7FF515F0C000
unkown image
page readonly
clean
7FF515A42000
unkown image
page readonly
clean
7FF5D8FF5000
unkown image
page readonly
clean
1DDCB8A5000
unkown
page read and write
clean
1DDCC602000
unkown
page read and write
clean
7FF5862A7000
unkown image
page readonly
clean
677000
unkown
page read and write
clean
7FF515DA1000
unkown image
page readonly
clean
660000
unkown
page read and write
clean
2005303C000
unkown
page read and write
clean
7FF515DDE000
unkown image
page readonly
clean
1DDCC61A000
unkown
page read and write
clean
24287260000
unkown
page read and write
clean
D524F1B000
unkown
page read and write
clean
1DDCC659000
unkown
page read and write
clean
1DDCC189000
unkown
page read and write
clean
7FF515A52000
unkown image
page readonly
clean
7FF58637A000
unkown image
page readonly
clean
3643000
heap private
page read and write
clean
7FF5D8F54000
unkown image
page readonly
clean
24287160000
unkown
page read and write
clean
7FF515FC4000
unkown image
page readonly
clean
1DE711A0000
unkown image
page read and write
clean
65E000
unkown
page read and write
clean
7DF59B412000
unkown image
page readonly
clean
3EFD47F000
unkown
page read and write
clean
7FF5E4C55000
unkown image
page readonly
clean
1094000
unkown image
page write copy
clean
1DDCBF70000
unkown image
page write copy
clean
69E000
unkown
page read and write
clean
1DE71470000
unkown
page read and write
clean
1090000
unkown image
page write copy
clean
7FF5244F7000
unkown image
page readonly
clean
7FF515A4E000
unkown image
page readonly
clean
439E8FB000
unkown
page read and write
clean
7DF5EE160000
unkown image
page readonly
clean
1DE71980000
unkown image
page readonly
clean
7FFD0000
unkown image
page readonly
clean
1DDCC185000
unkown
page read and write
clean
7DF539D10000
unkown image
page readonly
clean
1DDCB800000
unkown
page read and write
clean
439EBFE000
unkown
page read and write
clean
663000
unkown
page read and write
clean
1DDCBCD0000
unkown image
page readonly
clean
7FF5D901F000
unkown image
page readonly
clean
1DDCC702000
unkown
page read and write
clean
7FF58627A000
unkown image
page readonly
clean
1DDCC1AD000
unkown
page read and write
clean
20053113000
unkown
page read and write
clean
7DF5EE180000
unkown image
page readonly
clean
DCB8E77000
unkown
page read and write
clean
7FF5E50FD000
unkown image
page readonly
clean
1DDCC600000
unkown
page read and write
clean
FBC000
unkown
page read and write
clean
10EF000
unkown image
page readonly
clean
1DDCC1A3000
unkown
page read and write
clean
7FFB2000
unkown image
page readonly
clean
1006000
unkown image
page readonly
clean
7FF5159BE000
unkown image
page readonly
clean
7FF5D905E000
unkown image
page readonly
clean
E20000
unkown
page read and write
clean
7DF539D22000
unkown image
page readonly
clean
1DDCC1A4000
unkown
page read and write
clean
1DE71451000
unkown
page read and write
clean
440000
unkown image
page readonly
clean
20052ED0000
unkown image
page read and write
clean
1DDCC1A3000
unkown
page read and write
clean
1DDCC172000
unkown
page read and write
clean
642000
unkown
page read and write
clean
6E572F9000
unkown
page read and write
clean
1DDCC1AF000
unkown
page read and write
clean
61E000
heap default
page read and write
clean
7DF539D30000
unkown image
page readonly
clean
7FF5D8BB0000
unkown image
page readonly
clean
1DDCB750000
unkown image
page read and write
clean
7FF5E50AF000
unkown image
page readonly
clean
7FF586381000
unkown image
page readonly
clean
2005308C000
unkown
page read and write
clean
1DDCC17B000
unkown
page read and write
clean
24287110000
unkown image
page readonly
clean
7FF5862C7000
unkown image
page readonly
clean
7DF52B052000
unkown image
page readonly
clean
1DDCC659000
unkown
page read and write
clean
1001000
unkown image
page execute read
clean
65B000
unkown
page read and write
clean
1DE711E0000
unkown image
page readonly
clean
2428727D000
unkown
page read and write
clean
1DDCC17C000
unkown
page read and write
clean
5C0000
unkown
page read and write
clean
1DDCC1B4000
unkown
page read and write
clean
66A000
unkown
page read and write
clean
1DDCC602000
unkown
page read and write
clean
7FF5E4F7B000
unkown image
page readonly
clean
7FF5E4F41000
unkown image
page readonly
clean
1DDCC1A3000
unkown
page read and write
clean
7FF524BCC000
unkown image
page readonly
clean
682000
unkown
page read and write
clean
7DF539D12000
unkown image
page readonly
clean
1DDCC178000
unkown
page read and write
clean
D52537C000
unkown
page read and write
clean
7FF5E4FEC000
unkown image
page readonly
clean
7FF5862F8000
unkown image
page readonly
clean
1DDCBF40000
unkown image
page readonly
clean
1DDCC10F000
unkown
page read and write
clean
7FF515D8A000
unkown image
page readonly
clean
7FF515C57000
unkown image
page readonly
clean
7DF52B060000
unkown image
page readonly
clean
7FF515EAB000
unkown image
page readonly
clean
19B000
unkown
page read and write
clean
23CF6F51000
unkown
page read and write
clean
7FF515EE0000
unkown image
page readonly
clean
629000
heap default
page read and write
clean
1DDCB916000
unkown
page read and write
clean
3643000
heap private
page read and write
clean
7FF5D8ED1000
unkown image
page readonly
clean
7FF5D8F5C000
unkown image
page readonly
clean
D52527F000
unkown
page read and write
clean
7FF524C0E000
unkown image
page readonly
clean
3E6F000
unkown
page read and write
clean
7FF5D8DA0000
unkown image
page readonly
clean
7DF5EE162000
unkown image
page readonly
clean
1DE71508000
unkown
page read and write
clean
7FF586171000
unkown image
page readonly
clean
1DDCC13A000
unkown
page read and write
clean
23CF6EC0000
unkown image
page readonly
clean
65B000
unkown
page read and write
clean
7FF515833000
unkown image
page readonly
clean
7FF515FD2000
unkown image
page readonly
clean
1DDCC16A000
unkown
page read and write
clean
1DDCC602000
unkown
page read and write
clean
7FF515F17000
unkown image
page readonly
clean
7FF5E5097000
unkown image
page readonly
clean
1DDCC1A3000
unkown
page read and write
clean
1DDCC002000
unkown
page read and write
clean
7DF437BE0000
unkown image
page readonly
clean
7FF5E50CA000
unkown image
page readonly
clean
7FF5E4FE4000
unkown image
page readonly
clean
1DDCC1B4000
unkown
page read and write
clean
1DDCB84B000
unkown
page read and write
clean
1F0000
unkown
page read and write
clean
1DDCB7F0000
unkown
page read and write
clean
65C000
unkown
page read and write
clean
20053000000
unkown
page read and write
clean
7FF524BE4000
unkown image
page readonly
clean
7DF52B060000
unkown image
page readonly
clean
1DDCB857000
unkown
page read and write
clean
DCB90F8000
unkown
page read and write
clean
7FF5862E4000
unkown image
page readonly
clean
1100000
unkown image
page readonly
clean
7FF58628A000
unkown image
page readonly
clean
7FF5E50D4000
unkown image
page readonly
clean
682000
unkown
page read and write
clean
1DDCC1C7000
unkown
page read and write
clean
1DDCB8EA000
unkown
page read and write
clean
1DDCB902000
unkown
page read and write
clean
7FF5D884D000
unkown image
page readonly
clean
3D6E000
unkown
page read and write
clean
1DDCC185000
unkown
page read and write
clean
7FF585E56000
unkown image
page readonly
clean
7FF5E50DF000
unkown image
page readonly
clean
7FF524C8A000
unkown image
page readonly
clean
1DDCB85A000
unkown
page read and write
clean
439E3AB000
unkown
page read and write
clean
23CF71F0000
unkown image
page readonly
clean
3EFD37F000
unkown
page read and write
clean
7DF52B062000
unkown image
page readonly
clean
7FF515DC1000
unkown image
page readonly
clean
7FF515F4E000
unkown image
page readonly
clean
24287266000
unkown
page read and write
clean
1098000
unkown image
page read and write
clean
7DF59B410000
unkown image
page readonly
clean
7FF515AF7000
unkown image
page readonly
clean
1DDCC1B4000
unkown
page read and write
clean
1DDCC137000
unkown
page read and write
clean
7FF5E507E000
unkown image
page readonly
clean
30000
unkown image
page read and write
clean
200532D0000
unkown image
page readonly
clean
1DDCC15F000
unkown
page read and write
clean
20053029000
unkown
page read and write
clean
7FF515EF7000
unkown image
page readonly
clean
1003000
unkown image
page readonly
clean
7FFC0000
unkown image
page readonly
clean
68B000
unkown
page read and write
clean
7FF515AF5000
unkown image
page readonly
clean
EB0000
heap private
page read and write
clean
1DDCB888000
unkown
page read and write
clean
1DDCC1A4000
unkown
page read and write
clean
684000
unkown
page read and write
clean
7FF5862BC000
unkown image
page readonly
clean
6E5737E000
unkown
page read and write
clean
1093000
unkown image
page read and write
clean
DCB8D7A000
unkown
page read and write
clean
7FF586306000
unkown image
page readonly
clean
1DDCC171000
unkown
page read and write
clean
1DDCC122000
unkown
page read and write
clean
7DF5FA202000
unkown image
page readonly
clean
7FF5862FE000
unkown image
page readonly
clean
1DDCC602000
unkown
page read and write
clean
20052F40000
heap default
page read and write
clean
5CA000
unkown
page readonly
clean
677000
unkown
page read and write
clean
1DE71513000
unkown
page read and write
clean
1DDCBE50000
unkown image
page readonly
clean
20052F70000
unkown
page read and write
clean
682000
unkown
page read and write
clean
7FF5D8FEE000
unkown image
page readonly
clean
65D000
unkown
page read and write
clean
7FF5D90E2000
unkown image
page readonly
clean
679000
unkown
page read and write
clean
669000
unkown
page read and write
clean
1099000
unkown image
page execute and read and write
clean
1DDCB8D8000
unkown
page read and write
clean
439E7FC000
unkown
page read and write
clean
290000
unkown
page read and write
clean
7FF5E50C4000
unkown image
page readonly
clean
1DDCB770000
unkown image
page readonly
clean
20052EF0000
unkown image
page readonly
clean
68B000
unkown
page read and write
clean
1DDCC1AB000
unkown
page read and write
clean
7FF515F34000
unkown image
page readonly
clean
DCB8FFF000
unkown
page read and write
clean
20053081000
unkown
page read and write
clean
20053100000
unkown
page read and write
clean
7DF5FA1F2000
unkown image
page readonly
clean
7FF5E5164000
unkown image
page readonly
clean
3EFCF7E000
unkown
page read and write
clean
439E67E000
unkown
page read and write
clean
DFE000
unkown
page read and write
clean
23CF6F20000
unkown
page read and write
clean
7DF59B400000
unkown image
page readonly
clean
1DDCB84F000
unkown
page read and write
clean
1DE71413000
unkown
page read and write
clean
7FF586007000
unkown image
page readonly
clean
7FF5E506C000
unkown image
page readonly
clean
7FF586374000
unkown image
page readonly
clean
1A0000
unkown image
page readonly
clean
20052EF0000
unkown image
page readonly
clean
1DDCB8B0000
unkown
page read and write
clean
3643000
heap private
page read and write
clean
1DDCC1BA000
unkown
page read and write
clean
7FF5D9058000
unkown image
page readonly
clean
1DDCB849000
unkown
page read and write
clean
7DF52B050000
unkown image
page readonly
clean
264E000
unkown
page read and write
clean
7FF515F24000
unkown image
page readonly
clean
7FF5E4DF7000
unkown image
page readonly
clean
242870E0000
unkown image
page readonly
clean
7FF515F3F000
unkown image
page readonly
clean
7FF5862DA000
unkown image
page readonly
clean
1010000
unkown image
page execute read
clean
6A1000
unkown
page read and write
clean
7FF515EAF000
unkown image
page readonly
clean
1DDCC1AB000
unkown
page read and write
clean
7FFD0000
unkown image
page readonly
clean
7FF51573D000
unkown image
page readonly
clean
662000
unkown
page read and write
clean
65D000
unkown
page read and write
clean
1DDCC184000
unkown
page read and write
clean
23CF71E0000
heap private
page read and write
clean
1DDCC763000
unkown
page read and write
clean
E20000
unkown
page read and write
clean
7FF515DDB000
unkown image
page readonly
clean
7FF586295000
unkown image
page readonly
clean
23CF6F7F000
unkown
page read and write
clean
DCB878E000
unkown
page read and write
clean
7FF5862EF000
unkown image
page readonly
clean
68D000
unkown
page read and write
clean
684000
unkown
page read and write
clean
7FF515E82000
unkown image
page readonly
clean
DCB8C77000
unkown
page read and write
clean
660000
unkown
page read and write
clean
7FF515F56000
unkown image
page readonly
clean
7FF5D9034000
unkown image
page readonly
clean
7FF515D16000
unkown image
page readonly
clean
23CF6F80000
unkown
page read and write
clean
1DE71456000
unkown
page read and write
clean
1DDCC1A3000
unkown
page read and write
clean
7DF539D20000
unkown image
page readonly
clean
23CF6F00000
unkown
page read and write
clean
7DF4992D0000
unkown image
page readonly
clean
1DDCC700000
unkown
page read and write
clean
3BB0000
unkown
page read and write
clean
694000
unkown
page read and write
clean
1DDCC162000
unkown
page read and write
clean
1DE712F0000
unkown image
page readonly
clean
67E000
unkown
page read and write
clean
7FF5D8EEB000
unkown image
page readonly
clean
1DDCC182000
unkown
page read and write
clean
7DF539D20000
unkown image
page readonly
clean
7DF5FA202000
unkown image
page readonly
clean
1DDCC121000
unkown
page read and write
clean
7FF515DE8000
unkown image
page readonly
clean
7FF515AB5000
unkown image
page readonly
clean
1005000
unkown image
page read and write
clean
7FF58628E000
unkown image
page readonly
clean
242874D0000
unkown image
page readonly
clean
7DF5EE172000
unkown image
page readonly
clean
7DF5FA200000
unkown image
page readonly
clean
7FF5D906D000
unkown image
page readonly
clean
694000
unkown
page read and write
clean
1DDCC17E000
unkown
page read and write
clean
7FF586151000
unkown image
page readonly
clean
65D000
unkown
page read and write
clean
694000
unkown
page read and write
clean
7DF59B412000
unkown image
page readonly
clean
7DF52B050000
unkown image
page readonly
clean
1DDCBFE0000
unkown
page read and write
clean
7FF515F0F000
unkown image
page readonly
clean
7FF524C91000
unkown image
page readonly
clean
7FF5D9027000
unkown image
page readonly
clean
7FF5D8FEA000
unkown image
page readonly
clean
1DE71502000
unkown
page read and write
clean
1DDCC171000
unkown
page read and write
clean
7FF5D8BB6000
unkown image
page readonly
clean
24287302000
unkown
page read and write
clean
7FF5D8FFB000
unkown image
page readonly
clean
7FF515C9B000
unkown image
page readonly
clean
20053650000
unkown image
page readonly
clean
24287130000
heap default
page read and write
clean
7FF515E93000
unkown image
page readonly
clean
7FF5E4FD3000
unkown image
page readonly
clean
1DDCBFE0000
unkown
page read and write
clean
1DDCC16F000
unkown
page read and write
clean
677000
unkown
page read and write
clean
7DF4EC030000
unkown image
page readonly
clean
24287850000
unkown image
page readonly
clean
DC0000
unkown
page execute and read and write
clean
24287308000
unkown
page read and write
clean
1DDCB854000
unkown
page read and write
clean
1DDCC602000
unkown
page read and write
clean
1DDCB813000
unkown
page read and write
clean
1DDCC1AB000
unkown
page read and write
clean
6C2000
unkown
page read and write
clean
7FF515EBF000
unkown image
page readonly
clean
61B000
heap default
page read and write
clean
109D000
unkown image
page read and write
clean
7FF5E50F6000
unkown image
page readonly
clean
1DDCC1A3000
unkown
page read and write
clean
242870D0000
heap private
page read and write
clean
23CF73F0000
unkown image
page readonly
clean
7FEB0000
unkown image
page readonly
clean
7FF5244F3000
unkown image
page readonly
clean
7FF5861DD000
unkown image
page readonly
clean
7DF539D12000
unkown image
page readonly
clean
7FF5E50AC000
unkown image
page readonly
clean
1DDCC184000
unkown
page read and write
clean
1DDCBAD0000
unkown image
page readonly
clean
1DDCC602000
unkown
page read and write
clean
1DDCC139000
unkown
page read and write
clean
7FF585E65000
unkown image
page readonly
clean
7FF5861E3000
unkown image
page readonly
clean
7FF5D90D4000
unkown image
page readonly
clean
3EFCEFE000
unkown
page read and write
clean
7FF515E2D000
unkown image
page readonly
clean
2005304E000
unkown
page read and write
clean
1DE71426000
unkown
page read and write
clean
1DDCC702000
unkown
page read and write
clean
7FF515F48000
unkown image
page readonly
clean
7DF5EE170000
unkown image
page readonly
clean
7FF515EDE000
unkown image
page readonly
clean
7DF59B410000
unkown image
page readonly
clean
106A000
unkown image
page readonly
clean
23CF6F6F000
unkown
page read and write
clean
200534D0000
unkown image
page readonly
clean
7FF515CE0000
unkown image
page readonly
clean
3EFD17B000
unkown
page read and write
clean
7FF515FD1000
unkown image
page readonly
clean
7FF58618B000
unkown image
page readonly
clean
1DDCB7D0000
unkown image
page readonly
clean
20052EE0000
heap private
page read and write
clean
7FF5E50E8000
unkown image
page readonly
clean
1001000
unkown image
page execute read
clean
67C000
unkown
page read and write
clean
7FF5E5172000
unkown image
page readonly
clean
7FF524BCF000
unkown image
page readonly
clean
1DDCC602000
unkown
page read and write
clean
3AAF000
unkown
page read and write
clean
1DDCC602000
unkown
page read and write
clean
7FF5E508B000
unkown image
page readonly
clean
1DDCC1AD000
unkown
page read and write
clean
23CF6F40000
heap default
page read and write
clean
7FFB2000
unkown image
page readonly
clean
7FF515EEB000
unkown image
page readonly
clean
1DDCC176000
unkown
page read and write
clean
66D000
unkown
page read and write
clean
1DE7143C000
unkown
page read and write
clean
1DDCC121000
unkown
page read and write
clean
24287100000
unkown image
page readonly
clean
7FF515E33000
unkown image
page readonly
clean
7FF5E4FCD000
unkown image
page readonly
clean
7DF5EE180000
unkown image
page readonly
clean
1DE7144B000
unkown
page read and write
clean
1DDCBFF0000
unkown image
page read and write
clean
1DDCC139000
unkown
page read and write
clean
64A000
unkown
page read and write
clean
7FF524BA0000
unkown image
page readonly
clean
23CF6F65000
unkown
page read and write
clean
7FF515737000
unkown image
page readonly
clean
7FF58630D000
unkown image
page readonly
clean
69E000
unkown
page read and write
clean
260F000
unkown
page read and write
clean
7FF5861FC000
unkown image
page readonly
clean
7FF5D8F43000
unkown image
page readonly
clean
1000000
unkown image
page readonly
clean
BF0000
unkown image
page readonly
clean
7FF5E4ED1000
unkown image
page readonly
clean
106A000
unkown image
page readonly
clean
669000
unkown
page read and write
clean
7FF5E4F7E000
unkown image
page readonly
clean
6E56F2F000
unkown
page read and write
clean
1DDCC178000
unkown
page read and write
clean
7FF5E506A000
unkown image
page readonly
clean
1DDCC16C000
unkown
page read and write
clean
1DDCC1AC000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
5CC000
unkown
page read and write
clean
624000
heap default
page read and write
clean
7FF5D9044000
unkown image
page readonly
clean
7FF515CA6000
unkown image
page readonly
clean
1DE7148F000
unkown
page read and write
clean
1DDCC1AD000
unkown
page read and write
clean
1DDCC173000
unkown
page read and write
clean
1DDCC1AB000
unkown
page read and write
clean
7DF5FA210000
unkown image
page readonly
clean
7FFB0000
unkown image
page readonly
clean
7DF5EE170000
unkown image
page readonly
clean
7FF524BEA000
unkown image
page readonly
clean
1DDCC1AD000
unkown
page read and write
clean
7FF5861F4000
unkown image
page readonly
clean
678000
unkown
page read and write
clean
691000
unkown
page read and write
clean
1DDCB913000
unkown
page read and write
clean
7FF5D8EEE000
unkown image
page readonly
clean
7FF5D8EB1000
unkown image
page readonly
clean
1DDCC602000
unkown
page read and write
clean
7FF586309000
unkown image
page readonly
clean
439E9F7000
unkown
page read and write
clean
7FF515F2A000
unkown image
page readonly
clean
24287300000
unkown
page read and write
clean
1DDCB848000
unkown
page read and write
clean
460000
heap default
page read and write
clean
1DDCC184000
unkown
page read and write
clean
1DE711B0000
heap private
page read and write
clean
1DDCC602000
unkown
page read and write
clean
68B000
unkown
page read and write
clean
1DDCB853000
unkown
page read and write
clean
23CF6EE0000
unkown image
page readonly
clean
7FF5E50F9000
unkown image
page readonly
clean
7FF5859BD000
unkown image
page readonly
clean
1DDCB829000
unkown
page read and write
clean
1DDCC189000
unkown
page read and write
clean
7DF5FA1F2000
unkown image
page readonly
clean
1DDCC18D000
unkown
page read and write
clean
10AB000
unkown image
page read and write
clean
3643000
heap private
page read and write
clean
7FF5E4C40000
unkown image
page readonly
clean
10AD000
unkown image
page readonly
clean
6E5727A000
unkown
page read and write
clean
7FF515E44000
unkown image
page readonly
clean
1DDCB84D000
unkown
page read and write
clean
1DDCB7C0000
heap default
page read and write
clean
7DF59B400000
unkown image
page readonly
clean
439E6FE000
unkown
page read and write
clean
7FF515D83000
unkown image
page readonly
clean
1DDCC137000
unkown
page read and write
clean
6E573FC000
unkown
page read and write
clean
20053102000
unkown
page read and write
clean
1DDCC138000
unkown
page read and write
clean
108E000
unkown image
page write copy
clean
24287140000
unkown image
page readonly
clean
242876D0000
unkown image
page readonly
clean
20052F50000
unkown image
page readonly
clean
669000
unkown
page read and write
clean
1DDCB83C000
unkown
page read and write
clean
E30000
heap private
page read and write
clean
7FF5D8F3D000
unkown image
page readonly
clean
1DDCC603000
unkown
page read and write
clean
1DDCC18A000
unkown
page read and write
clean
7FF586382000
unkown image
page readonly
clean
3BAF000
unkown
page read and write
clean
1DE71400000
unkown
page read and write
clean
1DDCB86F000
unkown
page read and write
clean
1DDCC1A3000
unkown
page read and write
clean
23CF6F6F000
unkown
page read and write
clean
65B000
unkown
page read and write
clean
7FF515D21000
unkown image
page readonly
clean
1DDCB7A0000
unkown image
page readonly
clean
5F0000
heap default
page read and write
clean
D524F9F000
unkown
page read and write
clean
68D000
unkown
page read and write
clean
1DDCC137000
unkown
page read and write
clean
1DDCC17F000
unkown
page read and write
clean
1DDCC1BE000
unkown
page read and write
clean
7FF58618E000
unkown image
page readonly
clean
68C000
unkown
page read and write
clean
7DF5EE162000
unkown image
page readonly
clean
7DF539D30000
unkown image
page readonly
clean
7FF524C1D000
unkown image
page readonly
clean
20053055000
unkown
page read and write
clean
7FF5E48D7000
unkown image
page readonly
clean
3643000
heap private
page read and write
clean
24287A02000
unkown
page read and write
clean
7FF5D9066000
unkown image
page readonly
clean
7DF5EE172000
unkown image
page readonly
clean
1DE71A02000
unkown
page read and write
clean
1DE711F0000
unkown image
page readonly
clean
1DDCB84C000
unkown
page read and write
clean
7DF59B420000
unkown image
page readonly
clean
7FF515C90000
unkown image
page readonly
clean
1DE71500000
unkown
page read and write
clean
1DDCC176000
unkown
page read and write
clean
6E56EAA000
unkown
page read and write
clean
2428722A000
unkown
page read and write
clean
7DF539D22000
unkown image
page readonly
clean
7FF5862D4000
unkown image
page readonly
clean
7FF586290000
unkown image
page readonly
clean
684000
unkown
page read and write
clean
2428723C000
unkown
page read and write
clean
23CF7130000
unkown image
page readonly
clean
7DF5FA210000
unkown image
page readonly
clean
7FF5862BF000
unkown image
page readonly
clean
7FF5E507A000
unkown image
page readonly
clean
1DE71800000
unkown image
page readonly
clean
7FF524C19000
unkown image
page readonly
clean
1DDCC1A3000
unkown
page read and write
clean
20052F20000
unkown image
page readonly
clean
1DDCC192000
unkown
page read and write
clean
1DDCC1C7000
unkown
page read and write
clean
68D000
unkown
page read and write
clean
D525577000
unkown
page read and write
clean
1DDCB790000
unkown image
page readonly
clean
66D000
unkown
page read and write
clean
1DDCC1A5000
unkown
page read and write
clean
23CF71E5000
heap private
page read and write
clean
7FF515E80000
unkown image
page readonly
clean
1DDCC18A000
unkown
page read and write
clean
20053002000
unkown
page read and write
clean
7FF515ECA000
unkown image
page readonly
clean
23CF6F66000
unkown
page read and write
clean
1000000
unkown image
page readonly
clean
67B000
unkown
page read and write
clean
7DF5FA1F0000
unkown image
page readonly
clean
3643000
heap private
page read and write
clean
28C000
unkown
page read and write
clean
1DDCB8E1000
unkown
page read and write
clean
D52547B000
unkown
page read and write
clean
1DDCC192000
unkown
page read and write
clean
There are 748 hidden memdumps, click here to show them.