IOCReport

loading gif

Files

File Path
Type
Category
Malicious
F99 SEP-15 Price Inquiry.xlsx
CDFV2 Encrypted
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\nano[1].exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
downloaded
malicious
C:\Users\user\AppData\Local\Temp\tmpC2C3.tmp
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\EA860E7A-A87F-4A88-92EF-38F744458171\run.dat
ISO-8859 text, with no line terminators
dropped
malicious
C:\Users\user\Desktop\~$F99 SEP-15 Price Inquiry.xlsx
data
dropped
malicious
C:\Users\Public\vbc.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\3020C4AA.png
PNG image data, 476 x 244, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\34B8769F.jpeg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 150x150, segment length 16, baseline, precision 8, 1275x1650, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\4B9F44A0.png
PNG image data, 684 x 477, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\5448D905.jpeg
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 333x151, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\7EDDCF3C.jpeg
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 191x263, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\7FA80342.png
PNG image data, 476 x 244, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\88F99796.png
PNG image data, 566 x 429, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\8BE733AE.png
PNG image data, 566 x 429, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\AC8CDDA9.jpeg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 0x0, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=2], baseline, precision 8, 474x379, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\B49FB8A3.png
PNG image data, 613 x 80, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\BD8CC067.jpeg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 150x150, segment length 16, baseline, precision 8, 1275x1650, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\BE46765B.png
PNG image data, 613 x 80, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\C2286014.jpeg
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 191x263, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\CBB16E31.emf
Windows Enhanced Metafile (EMF) image data version 0x10000
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\CCB31E7E.emf
Windows Enhanced Metafile (EMF) image data version 0x10000
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\D7985248.png
PNG image data, 684 x 477, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\E3C21.jpeg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 0x0, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=2], baseline, precision 8, 474x379, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\EB16E0D.jpeg
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 333x151, frames 3
dropped
clean
C:\Users\user\AppData\Roaming\EA860E7A-A87F-4A88-92EF-38F744458171\catalog.dat
data
dropped
clean
C:\Users\user\AppData\Roaming\smsBuojZSZn.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
clean
There are 16 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
'C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE' -Embedding
malicious
C:\Users\Public\vbc.exe
'C:\Users\Public\vbc.exe'
malicious
C:\Windows\SysWOW64\schtasks.exe
'C:\Windows\System32\schtasks.exe' /Create /TN 'Updates\smsBuojZSZn' /XML 'C:\Users\user\AppData\Local\Temp\tmpC2C3.tmp'
malicious
C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
clean

URLs

Name
IP
Malicious
http://207.246.99.155/covid/nano.exe
207.246.99.155
malicious
newmeforever.3utilities.com
malicious
newmeforever12.3utilities.com
malicious
http://www.%s.comPA
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://google.com
unknown
clean
http://www.day.com/dam/1.0
unknown
clean

Domains

Name
IP
Malicious
newmeforever.3utilities.com
79.134.225.19
malicious
newmeforever12.3utilities.com
unknown
malicious

IPs

IP
Domain
Country
Malicious
207.246.99.155
unknown
United States
malicious
79.134.225.19
newmeforever.3utilities.com
Switzerland
malicious

Registry

Path
Value
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
0t*
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
MTTT
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ReviewToken
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
2FBFB
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
FontCachePath
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
VBAFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
4b*
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
34C3C
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
35A21
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 21
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
LastPurgeTime
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EXCELFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Name
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
34C3C
clean
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
EquationEditorFilesIntl_1033
clean
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
SavedLegacySettings
clean
There are 33 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
402000
unkown
page execute and read and write
malicious
E30000
unkown image
page read and write
malicious
3971000
unkown
page read and write
malicious
26C0000
unkown
page read and write
malicious
3A27000
unkown
page read and write
malicious
3681000
unkown
page read and write
malicious
4A0000
unkown
page execute and read and write
clean
3AB4000
unkown
page read and write
clean
230000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
3A74000
unkown
page read and write
clean
69CE000
unkown
page read and write
clean
4A31000
unkown
page read and write
clean
3A94000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
1EB000
unkown
page read and write
clean
39F3000
unkown
page read and write
clean
490000
unkown
page read and write
clean
622000
unkown
page read and write
clean
39F3000
unkown
page read and write
clean
172000
unkown
page execute and read and write
clean
1AF000
unkown
page read and write
clean
199000
unkown
page read and write
clean
D30000
unkown image
page read and write
clean
550B000
unkown
page read and write
clean
640000
unkown
page read and write
clean
4C34000
heap private
page read and write
clean
510000
unkown
page read and write
clean
56A1000
unkown
page read and write
clean
49D0000
unkown
page read and write
clean
4A06000
unkown
page read and write
clean
39F3000
unkown
page read and write
clean
2A46000
unkown
page read and write
clean
E8C000
unkown
page read and write
clean
2380000
unkown
page execute and read and write
clean
496000
unkown
page read and write
clean
7EF50000
unkown
page execute and read and write
clean
3AB4000
unkown
page read and write
clean
5D1000
unkown
page read and write
clean
59C000
unkown
page read and write
clean
C20000
unkown
page read and write
clean
260000
unkown
page read and write
clean
630000
unkown
page read and write
clean
39F3000
unkown
page read and write
clean
39D4000
unkown
page read and write
clean
820000
unkown image
page readonly
clean
470000
unkown
page read and write
clean
496000
unkown
page read and write
clean
287C000
unkown
page read and write
clean
4B5000
unkown
page read and write
clean
640000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
5ED000
unkown
page read and write
clean
3A74000
unkown
page read and write
clean
750000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
4A0000
unkown
page read and write
clean
4AD000
unkown
page read and write
clean
6050000
unkown image
page readonly
clean
ED0000
unkown
page read and write
clean
3AB4000
unkown
page read and write
clean
47B0000
unkown
page read and write
clean
3A54000
unkown
page read and write
clean
5B3E000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
622000
unkown
page read and write
clean
490000
unkown
page read and write
clean
DC0000
unkown
page read and write
clean
490000
unkown
page read and write
clean
3A54000
unkown
page read and write
clean
DE0000
unkown
page execute and read and write
clean
4A4C000
unkown
page read and write
clean
460000
unkown image
page readonly
clean
56B2000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
3A94000
unkown
page read and write
clean
56A1000
unkown
page read and write
clean
3AB4000
unkown
page read and write
clean
6AB0000
heap private
page read and write
clean
16A000
unkown
page execute and read and write
clean
7EFC0000
unkown image
page readonly
clean
310000
unkown
page read and write
clean
496000
unkown
page read and write
clean
D12000
heap private
page execute and read and write
clean
78F000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
818000
heap private
page read and write
clean
310000
unkown image
page readonly
clean
4D30000
unkown image
page read and write
clean
790000
heap private
page execute and read and write
clean
4780000
unkown image
page read and write
clean
39F3000
unkown
page read and write
clean
2390000
unkown
page read and write
clean
3A63000
unkown
page read and write
clean
18F000
heap default
page read and write
clean
3A74000
unkown
page read and write
clean
665E000
unkown
page read and write
clean
20000
unkown
page read and write
clean
187000
unkown
page execute and read and write
clean
48CE000
unkown
page read and write
clean
3AB4000
unkown
page read and write
clean
490000
unkown
page read and write
clean
212000
unkown
page execute and read and write
clean
527000
heap default
page read and write
clean
3A13000
unkown
page read and write
clean
39F4000
unkown
page read and write
clean
630000
unkown
page read and write
clean
120000
unkown
page read and write
clean
5CE000
unkown
page read and write
clean
3950000
unkown
page read and write
clean
3A94000
unkown
page read and write
clean
490000
unkown
page read and write
clean
3A54000
unkown
page read and write
clean
39F3000
unkown
page read and write
clean
58E0000
heap private
page read and write
clean
140000
heap private
page read and write
clean
300000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
382F000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
3A94000
unkown
page read and write
clean
140000
unkown image
page readonly
clean
268C000
unkown
page read and write
clean
2A0000
unkown
page read and write
clean
47C0000
unkown
page read and write
clean
3B14000
unkown
page read and write
clean
490000
unkown
page read and write
clean
47C0000
unkown
page read and write
clean
58C000
unkown
page read and write
clean
6440000
unkown
page read and write
clean
3A13000
unkown
page read and write
clean
3A54000
unkown
page read and write
clean
39F3000
unkown
page read and write
clean
3A54000
unkown
page read and write
clean
490000
unkown
page read and write
clean
5AD000
unkown
page read and write
clean
490000
unkown
page read and write
clean
3A34000
unkown
page read and write
clean
5EAF000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
4A0000
unkown image
page read and write
clean
3A54000
unkown
page read and write
clean
220000
unkown
page read and write
clean
3AF4000
unkown
page read and write
clean
47E0000
unkown
page read and write
clean
3A13000
unkown
page read and write
clean
3A34000
unkown
page read and write
clean
58E000
unkown
page read and write
clean
5AE000
unkown
page read and write
clean
7EF3C000
unkown
page read and write
clean
4B0000
unkown
page read and write
clean
5D7000
unkown
page read and write
clean
58C000
unkown
page read and write
clean
37CF000
unkown
page read and write
clean
22F0000
unkown image
page read and write
clean
3A13000
unkown
page read and write
clean
640000
unkown
page read and write
clean
301000
unkown
page read and write
clean
640000
unkown
page read and write
clean
4B0000
unkown
page read and write
clean
3AB4000
unkown
page read and write
clean
740000
unkown
page read and write
clean
634000
unkown
page read and write
clean
3A34000
unkown
page read and write
clean
587F000
unkown
page read and write
clean
C20000
unkown
page read and write
clean
39F3000
unkown
page read and write
clean
3A74000
unkown
page read and write
clean
4C9F000
unkown
page read and write
clean
C80000
heap private
page execute and read and write
clean
39F3000
unkown
page read and write
clean
2234000
heap private
page read and write
clean
ED0000
unkown
page read and write
clean
2380000
unkown
page read and write
clean
5E4000
unkown
page read and write
clean
700000
heap private
page execute and read and write
clean
490000
unkown
page read and write
clean
622000
unkown
page read and write
clean
39D4000
unkown
page read and write
clean
622000
unkown
page read and write
clean
3A34000
unkown
page read and write
clean
3A74000
unkown
page read and write
clean
604E000
unkown
page read and write
clean
64EE000
unkown
page read and write
clean
190000
unkown
page read and write
clean
3A93000
unkown
page read and write
clean
3930000
unkown
page read and write
clean
2A30000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
48D0000
unkown
page read and write
clean
47C8000
unkown
page read and write
clean
3D0000
unkown image
page read and write
clean
56A2000
unkown
page read and write
clean
47C0000
unkown image
page readonly
clean
3A74000
unkown
page read and write
clean
3A7000
unkown
page read and write
clean
6AB5000
heap private
page read and write
clean
495000
unkown
page read and write
clean
516000
unkown
page read and write
clean
39D3000
unkown
page read and write
clean
DE0000
unkown
page read and write
clean
222000
unkown
page read and write
clean
2380000
unkown
page read and write
clean
4A60000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
49D0000
unkown
page read and write
clean
49D5000
unkown
page read and write
clean
3A6000
unkown
page read and write | page guard
clean
3A13000
unkown
page read and write
clean
640000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
CD0000
unkown image
page readonly
clean
3A13000
unkown
page read and write
clean
239E000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
4DDD000
unkown
page read and write
clean
380F000
unkown
page read and write
clean
3B0000
unkown
page execute and read and write
clean
5ED0000
heap private
page read and write
clean
5D5E000
unkown
page read and write
clean
6E0E000
unkown
page read and write
clean
4A70000
unkown
page read and write
clean
39D4000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
2390000
unkown image
page read and write
clean
3D0000
heap default
page read and write
clean
3C0000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
5A3000
unkown
page read and write
clean
15C000
unkown
page execute and read and write
clean
4830000
unkown
page read and write
clean
4A20000
unkown image
page read and write
clean
3A34000
unkown
page read and write
clean
3813000
unkown
page read and write
clean
593D000
unkown
page read and write
clean
CF0000
heap private
page execute and read and write
clean
CD0000
unkown image
page readonly
clean
ED0000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
150000
unkown image
page read and write
clean
4C38000
heap private
page read and write
clean
24B000
unkown
page execute and read and write
clean
3A94000
unkown
page read and write
clean
39D4000
unkown
page read and write
clean
BB0000
unkown image
page readonly
clean
3A54000
unkown
page read and write
clean
20000
unkown
page read and write
clean
5CDE000
unkown
page read and write
clean
EF0000
unkown image
page readonly
clean
280000
unkown image
page readonly
clean
3A54000
unkown
page read and write
clean
800000
unkown image
page read and write
clean
300000
unkown
page read and write
clean
39D000
unkown
page read and write
clean
3A34000
unkown
page read and write
clean
56B2000
unkown
page read and write
clean
ED7000
unkown
page read and write
clean
500000
unkown
page read and write
clean
47C5000
unkown
page read and write
clean
1A3000
unkown
page read and write
clean
598000
unkown
page read and write
clean
300000
unkown
page read and write
clean
3A94000
unkown
page read and write
clean
3A34000
unkown
page read and write
clean
3A0000
heap private
page read and write
clean
300000
unkown
page read and write
clean
5CC000
unkown
page read and write
clean
3AB3000
unkown
page read and write
clean
56B2000
unkown
page read and write
clean
3A94000
unkown
page read and write
clean
5EE000
unkown
page read and write
clean
162000
unkown
page read and write
clean
2F6000
unkown
page read and write | page guard
clean
3A34000
unkown
page read and write
clean
490000
unkown
page read and write
clean
5AE000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
39F3000
unkown
page read and write
clean
CD2000
unkown image
page execute read
clean
6F0000
unkown
page read and write
clean
22F0000
unkown
page read and write
clean
DCE000
unkown image
page readonly
clean
ED8000
unkown
page read and write
clean
37A6000
unkown
page read and write
clean
1B8000
unkown
page read and write
clean
3A54000
unkown
page read and write
clean
3AB4000
unkown
page read and write
clean
3AD4000
unkown
page read and write
clean
6C7E000
unkown
page read and write
clean
A17000
heap private
page read and write
clean
596000
unkown
page read and write
clean
38AF000
unkown
page read and write
clean
65A000
heap private
page execute and read and write
clean
740000
unkown
page read and write
clean
56B2000
unkown
page read and write
clean
3A54000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
4970000
unkown
page read and write
clean
47F0000
heap private
page read and write
clean
490000
unkown
page read and write
clean
3B54000
unkown
page read and write
clean
39D4000
unkown
page read and write
clean
3A54000
unkown
page read and write
clean
640000
unkown
page read and write
clean
39D4000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
5AE000
unkown
page read and write
clean
62D000
unkown
page read and write
clean
7EF36000
unkown
page read and write
clean
490000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
497000
unkown
page read and write
clean
ED0000
unkown
page read and write
clean
3AB4000
unkown
page read and write
clean
2A5000
unkown
page read and write
clean
E2E000
unkown
page read and write
clean
3A13000
unkown
page read and write
clean
310000
unkown
page read and write
clean
56A2000
unkown
page read and write
clean
3A74000
unkown
page read and write
clean
39D4000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
167000
unkown
page execute and read and write
clean
7EFB0000
unkown image
page readonly
clean
202000
unkown
page execute and read and write
clean
ED6000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
EB4000
heap private
page execute and read and write
clean
249F000
unkown
page read and write
clean
ED0000
unkown
page read and write
clean
59C000
unkown
page read and write
clean
300000
unkown
page read and write
clean
3A74000
unkown
page read and write
clean
3A13000
unkown
page read and write
clean
3A74000
unkown
page read and write
clean
13A000
unkown
page execute and read and write
clean
4F2000
unkown
page read and write
clean
56C2000
unkown
page read and write
clean
635000
unkown
page read and write
clean
4B20000
unkown
page read and write
clean
2A20000
unkown
page read and write
clean
5EF000
heap default
page read and write
clean
6BED000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
DE8000
unkown
page read and write
clean
237F000
unkown
page read and write
clean
5D2000
unkown
page read and write
clean
47C9000
unkown
page read and write
clean
3AB4000
unkown
page read and write
clean
39D4000
unkown
page read and write
clean
640000
unkown
page read and write
clean
1A3000
unkown
page read and write
clean
495000
unkown
page read and write
clean
3AB4000
unkown
page read and write
clean
5A8E000
unkown
page read and write
clean
150000
unkown
page read and write
clean
3AB4000
unkown
page read and write
clean
4A37000
unkown
page read and write
clean
540000
heap default
page read and write
clean
497000
unkown
page read and write
clean
1B3000
unkown
page read and write
clean
3A34000
unkown
page read and write
clean
3AD4000
unkown
page read and write
clean
496000
unkown
page read and write
clean
3A34000
unkown
page read and write
clean
810000
heap private
page read and write
clean
495000
unkown
page read and write
clean
3781000
unkown
page read and write
clean
529C000
unkown
page read and write
clean
800000
unkown
page read and write
clean
490000
unkown
page read and write
clean
A20000
unkown image
page readonly
clean
D90000
unkown
page read and write
clean
496000
unkown
page read and write
clean
CD2000
unkown image
page execute read
clean
3A94000
unkown
page read and write
clean
3A94000
unkown
page read and write
clean
3AB4000
unkown
page read and write
clean
3AB4000
unkown
page read and write
clean
3A13000
unkown
page read and write
clean
2A0000
unkown image
page readonly
clean
290000
unkown
page read and write
clean
3A54000
unkown
page read and write
clean
3A34000
unkown
page read and write
clean
3AB4000
unkown
page read and write
clean
2A4E000
unkown
page read and write
clean
242000
unkown
page read and write
clean
9A0000
unkown image
page readonly
clean
5D2000
heap default
page read and write
clean
496000
unkown
page read and write
clean
194000
unkown
page read and write
clean
4B0000
unkown
page read and write
clean
588000
heap default
page read and write
clean
39D4000
unkown
page read and write
clean
210000
unkown
page read and write
clean
ED0000
unkown
page read and write
clean
3AB4000
unkown
page read and write
clean
422000
unkown
page execute and read and write
clean
DA0000
unkown image
page read and write
clean
2A18000
unkown
page read and write
clean
5B0E000
unkown
page read and write
clean
635000
unkown
page read and write
clean
A00000
unkown image
page read and write
clean
66AE000
unkown
page read and write
clean
622000
unkown
page read and write
clean
800000
unkown
page read and write
clean
67DF000
unkown
page read and write
clean
3A94000
unkown
page read and write
clean
38F0000
unkown
page read and write
clean
386F000
unkown
page read and write
clean
5AD000
unkown
page read and write
clean
3A74000
unkown
page read and write
clean
5DAE000
unkown
page read and write
clean
180000
heap default
page read and write
clean
37EF000
unkown
page read and write
clean
490000
unkown
page read and write
clean
39F3000
unkown
page read and write
clean
24A0000
heap private
page read and write
clean
47C5000
unkown
page read and write
clean
47C0000
unkown
page read and write
clean
ED0000
unkown
page read and write
clean
3A13000
unkown
page read and write
clean
4F0000
unkown
page read and write
clean
170000
unkown
page read and write
clean
3A34000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
3A74000
unkown
page read and write
clean
3A54000
unkown
page read and write
clean
E90000
heap private
page execute and read and write
clean
3A94000
unkown
page read and write
clean
CEC000
unkown
page read and write
clean
496000
unkown
page read and write
clean
5F3000
unkown
page read and write
clean
4EA0000
unkown
page read and write
clean
4DE0000
unkown image
page readonly
clean
4C70000
unkown
page read and write
clean
7EF40000
unkown
page execute and read and write
clean
6E0000
unkown image
page read and write
clean
3AD4000
unkown
page read and write
clean
3A34000
unkown
page read and write
clean
3AD4000
unkown
page read and write
clean
5DB000
heap default
page read and write
clean
4A3D000
unkown
page read and write
clean
400000
unkown
page execute and read and write
clean
620000
unkown
page read and write
clean
490000
unkown
page read and write
clean
960000
unkown image
page readonly
clean
6440000
unkown
page read and write
clean
49D0000
unkown
page read and write
clean
6440000
unkown
page read and write
clean
39D4000
unkown
page read and write
clean
18D000
unkown
page read and write
clean
6F0000
unkown image
page readonly
clean
500000
unkown
page read and write
clean
53D000
unkown
page read and write
clean
490000
unkown
page read and write
clean
22F0000
unkown
page read and write
clean
2A1000
unkown
page read and write
clean
47D0000
unkown
page read and write
clean
3A34000
unkown
page read and write
clean
622000
unkown
page read and write
clean
7D0000
unkown image
page readonly
clean
2A0000
unkown
page read and write
clean
39D4000
unkown
page read and write
clean
622000
unkown
page read and write
clean
39D4000
unkown
page read and write
clean
ED5000
unkown
page read and write
clean
2781000
unkown
page read and write
clean
2270000
unkown image
page readonly
clean
3B34000
unkown
page read and write
clean
3A13000
unkown
page read and write
clean
490000
unkown
page read and write
clean
39F3000
unkown
page read and write
clean
23A0000
heap private
page read and write
clean
3A74000
unkown
page read and write
clean
4750000
unkown
page read and write
clean
3B0000
unkown image
page readonly
clean
4C9E000
unkown
page read and write | page guard
clean
740000
unkown image
page read and write
clean
2252000
heap private
page read and write
clean
39D4000
unkown
page read and write
clean
677000
heap private
page execute and read and write
clean
3A94000
unkown
page read and write
clean
490000
unkown
page read and write
clean
C90000
unkown image
page read and write
clean
5E7000
unkown
page read and write
clean
4A8000
unkown
page read and write
clean
3A13000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
49D0000
unkown
page read and write
clean
47C8000
unkown
page read and write
clean
18D000
unkown
page read and write
clean
490000
unkown
page read and write
clean
388F000
unkown
page read and write
clean
3AB4000
unkown
page read and write
clean
4EC9000
unkown
page read and write
clean
1A3000
unkown
page read and write
clean
56A0000
unkown
page read and write
clean
78E000
unkown
page read and write | page guard
clean
1B3000
heap default
page read and write
clean
758000
unkown
page read and write
clean
3A34000
unkown
page read and write
clean
640000
unkown
page read and write
clean
568000
heap default
page read and write
clean
62EE000
unkown
page read and write
clean
3A54000
unkown
page read and write
clean
5920000
unkown
page read and write
clean
4B3D000
unkown
page read and write
clean
39F3000
unkown
page read and write
clean
3A13000
unkown
page read and write
clean
DB0000
unkown
page execute and read and write
clean
3C0000
unkown image
page readonly
clean
3A74000
unkown
page read and write
clean
3A94000
unkown
page read and write
clean
490000
unkown
page read and write
clean
4FE000
unkown
page read and write
clean
56B2000
unkown
page read and write
clean
6E0000
unkown
page read and write
clean
490000
unkown
page read and write
clean
47C0000
unkown
page read and write
clean
4A6000
unkown
page read and write
clean
4A1D000
unkown
page read and write
clean
3AF4000
unkown
page read and write
clean
56A2000
unkown
page read and write
clean
3A94000
unkown
page read and write
clean
3A74000
unkown
page read and write
clean
3A74000
unkown
page read and write
clean
DD0000
unkown image
page read and write
clean
3AD4000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
3AD4000
unkown
page read and write
clean
800000
unkown
page read and write
clean
49D0000
unkown
page execute and read and write
clean
47C0000
unkown
page read and write
clean
3A74000
unkown
page read and write
clean
490000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
D90000
unkown image
page read and write
clean
2230000
heap private
page read and write
clean
3A13000
unkown
page read and write
clean
808000
unkown
page read and write
clean
490000
unkown
page read and write
clean
640000
unkown
page read and write
clean
49F6000
unkown
page read and write
clean
490000
unkown
page execute and read and write
clean
47C0000
unkown
page read and write
clean
5A3000
unkown
page read and write
clean
757000
unkown
page read and write
clean
22A000
unkown
page execute and read and write
clean
47C0000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
3A54000
unkown
page read and write
clean
596000
unkown
page read and write
clean
470000
unkown
page read and write
clean
3AD4000
unkown
page read and write
clean
3A23000
unkown
page read and write
clean
49C000
unkown
page read and write
clean
3A34000
unkown
page read and write
clean
47C0000
unkown
page read and write
clean
5CB0000
heap private
page read and write
clean
60E000
unkown
page read and write
clean
3A34000
unkown
page read and write
clean
2681000
unkown
page read and write
clean
56C2000
unkown
page read and write
clean
300000
unkown
page execute and read and write
clean
5D7000
heap default
page read and write
clean
49D4000
unkown
page read and write
clean
525E000
unkown
page read and write
clean
3A34000
unkown
page read and write
clean
3A13000
unkown
page read and write
clean
39F3000
unkown
page read and write
clean
4B8C000
unkown
page read and write
clean
226000
unkown
page execute and read and write
clean
640000
unkown image
page readonly
clean
47F5000
heap private
page read and write
clean
DE0000
unkown
page read and write
clean
CD0000
unkown image
page readonly
clean
480000
unkown
page read and write
clean
49D0000
unkown
page read and write
clean
384F000
unkown
page read and write
clean
520000
heap default
page read and write
clean
A00000
unkown
page read and write
clean
3A13000
unkown
page read and write
clean
620000
unkown
page read and write
clean
D40000
unkown image
page read and write
clean
3A54000
unkown
page read and write
clean
191000
unkown
page read and write
clean
59F000
heap default
page read and write
clean
3A94000
unkown
page read and write
clean
622000
unkown
page read and write
clean
564000
heap default
page read and write
clean
A00000
unkown
page read and write
clean
CF5000
heap private
page execute and read and write
clean
950000
unkown image
page readonly
clean
496E000
unkown
page read and write
clean
3A54000
unkown
page read and write
clean
49F9000
unkown
page read and write
clean
152000
unkown
page execute and read and write
clean
3A74000
unkown
page read and write
clean
C1D000
unkown
page read and write
clean
233C000
unkown
page read and write
clean
3A13000
unkown
page read and write
clean
2A0000
unkown
page read and write
clean
740000
unkown
page read and write
clean
635000
unkown
page read and write
clean
3F0000
unkown
page execute and read and write
clean
4F0000
unkown
page read and write
clean
59C000
unkown
page read and write
clean
650000
heap private
page execute and read and write
clean
7EFB2000
unkown image
page readonly
clean
2A0000
unkown
page read and write
clean
3A94000
unkown
page read and write
clean
22F0000
unkown
page read and write
clean
39F3000
unkown
page read and write
clean
132000
unkown
page execute and read and write
clean
7EFD0000
unkown image
page readonly
clean
39D4000
unkown
page read and write
clean
606E000
unkown
page read and write
clean
39F3000
unkown
page read and write
clean
1A0000
unkown
page read and write
clean
638000
unkown
page read and write
clean
2738000
unkown
page read and write
clean
56C2000
unkown
page read and write
clean
4B0000
unkown
page read and write
clean
5C4D000
unkown
page read and write
clean
47C0000
unkown
page read and write
clean
56A2000
unkown
page read and write
clean
39D4000
unkown
page read and write
clean
697F000
unkown
page read and write
clean
18B000
unkown
page execute and read and write
clean
38D0000
unkown
page read and write
clean
DCE000
unkown image
page readonly
clean
490000
unkown
page read and write
clean
5A5000
unkown
page read and write
clean
3C0000
unkown
page read and write
clean
160000
unkown image
page read and write
clean
E97000
heap private
page execute and read and write
clean
648000
unkown
page read and write
clean
39D4000
unkown
page read and write
clean
643E000
unkown
page read and write
clean
3A34000
unkown
page read and write
clean
F0000
unkown image
page readonly
clean
4C30000
heap private
page read and write
clean
3B74000
unkown
page read and write
clean
53CE000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
490000
unkown
page read and write
clean
615000
unkown
page read and write
clean
782000
heap private
page read and write
clean
494000
unkown
page read and write
clean
567B000
unkown
page read and write
clean
474C000
unkown
page read and write
clean
490000
unkown
page read and write
clean
697E000
unkown
page read and write | page guard
clean
18D000
unkown
page read and write
clean
3A13000
unkown
page read and write
clean
49A8000
unkown
page read and write
clean
C6C000
unkown
page read and write
clean
39F3000
unkown
page read and write
clean
490000
unkown
page read and write
clean
3A9000
heap private
page read and write
clean
4A5000
unkown
page read and write
clean
39D4000
unkown
page read and write
clean
6440000
unkown
page read and write
clean
4EE000
unkown
page read and write
clean
24A6000
heap private
page read and write
clean
490000
unkown
page read and write
clean
300000
unkown
page read and write
clean
490000
unkown
page read and write
clean
4DF0000
unkown image
page read and write
clean
4F0000
unkown
page execute and read and write
clean
300000
unkown
page read and write
clean
450000
unkown
page execute and read and write
clean
3A54000
unkown
page read and write
clean
308000
unkown
page read and write
clean
67CE000
unkown
page read and write
clean
2A0000
unkown
page read and write
clean
23C000
unkown
page execute and read and write
clean
3A74000
unkown
page read and write
clean
3AB4000
unkown
page read and write
clean
1A8000
unkown
page read and write
clean
39F3000
unkown
page read and write
clean
547000
heap default
page read and write
clean
3A13000
unkown
page read and write
clean
47C0000
unkown
page read and write
clean
6AD2000
heap private
page read and write
clean
232000
unkown
page execute and read and write
clean
20A000
unkown
page execute and read and write
clean
3A94000
unkown
page read and write
clean
3A94000
unkown
page read and write
clean
1A3000
heap default
page read and write
clean
630000
unkown
page read and write
clean
5A7000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
750000
unkown
page read and write
clean
764000
heap private
page read and write
clean
490000
unkown
page read and write
clean
4A1E000
unkown
page read and write
clean
490000
unkown
page read and write
clean
490000
unkown
page read and write
clean
56A2000
unkown
page read and write
clean
BA000
unkown
page read and write
clean
760000
heap private
page read and write
clean
39F3000
unkown
page read and write
clean
2F8000
unkown
page read and write
clean
22F0000
unkown
page read and write
clean
18D000
unkown
page read and write
clean
5A7000
unkown
page read and write
clean
17A000
unkown
page execute and read and write
clean
3AB4000
unkown
page read and write
clean
490000
unkown
page read and write
clean
47C0000
unkown
page read and write
clean
C20000
unkown image
page read and write
clean
D8E000
unkown
page read and write
clean
56A2000
unkown
page read and write
clean
5CB000
heap default
page read and write
clean
A10000
heap private
page read and write
clean
249E000
unkown
page read and write | page guard
clean
48ED000
unkown
page read and write
clean
3A74000
unkown
page read and write
clean
39D4000
unkown
page read and write
clean
4B7000
unkown
page read and write
clean
247000
unkown
page execute and read and write
clean
60A000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
544000
heap default
page read and write
clean
23A000
unkown
page execute and read and write
clean
5C9000
heap default
page read and write
clean
609000
unkown
page read and write
clean
635000
unkown
page read and write
clean
There are 724 hidden memdumps, click here to show them.