IOC Report

loading gif

Files

File Path
Type
Category
Malicious
E0QkjJowwG.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\33a62d2d2e6f6fc30153b1b0408eca36.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\Yandex.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
\Device\ConDrv
ASCII text, with CRLF line terminators
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\E0QkjJowwG.exe
'C:\Users\user\Desktop\E0QkjJowwG.exe'
malicious
C:\Users\user\Yandex.exe
'C:\Users\user\Yandex.exe'
malicious
C:\Windows\SysWOW64\netsh.exe
netsh firewall add allowedprogram 'C:\Users\user\Yandex.exe' 'Yandex.exe' ENABLE
malicious
C:\Users\user\Yandex.exe
'C:\Users\user\Yandex.exe' ..
malicious
C:\Users\user\Yandex.exe
'C:\Users\user\Yandex.exe' ..
malicious
C:\Users\user\Yandex.exe
'C:\Users\user\Yandex.exe' ..
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
clean

URLs

Name
IP
Malicious
http://pki-crl.symauth.com/offlineca/TheInstituteofElectricalandElectronicsEngineersIncIEEERootCA.cr
unknown
clean
http://www.enigmaprotector.com/
unknown
clean
http://pki-ocsp.symauth.com0
unknown
clean
http://pki-crl.symauth.com/ca_732b6ec148d290c0a071efd1dac8e288/LatestCRL.crl07
unknown
clean
http://www.enigmaprotector.com/openU
unknown
clean

Domains

Name
IP
Malicious
8.tcp.ngrok.io
3.19.130.43
clean

IPs

IP
Domain
Country
Malicious
3.142.129.56
unknown
United States
malicious
3.142.81.166
unknown
United States
malicious
3.142.167.4
unknown
United States
malicious
13.58.157.220
unknown
United States
malicious
3.142.167.54
unknown
United States
malicious
3.19.130.43
8.tcp.ngrok.io
United States
clean

Registry

Path
Value
Malicious
HKEY_CURRENT_USER
di
malicious
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
33a62d2d2e6f6fc30153b1b0408eca36
malicious
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
Hidden
malicious
HKEY_CURRENT_USER\Software\33a62d2d2e6f6fc30153b1b0408eca36
hp
clean
HKEY_CURRENT_USER\Software\33a62d2d2e6f6fc30153b1b0408eca36
i
clean
HKEY_CURRENT_USER\Environment
SEE_MASK_NOZONECHECKS
clean
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run
33a62d2d2e6f6fc30153b1b0408eca36
clean
HKEY_CURRENT_USER\Software\33a62d2d2e6f6fc30153b1b0408eca36
kl
clean
HKEY_CURRENT_USER\Software\33a62d2d2e6f6fc30153b1b0408eca36
kl
clean
HKEY_CURRENT_USER_Classes\Local Settings\MuiCache\f0\52C64B7E
@C:\Windows\SysWOW64\FirewallControlPanel.dll,-12122
clean

Memdumps

Base Address
Regiontype
Protect
Malicious
72000
unkown image
page execute and read and write
malicious
F22000
unkown image
page execute and read and write
malicious
3CCE000
unkown
page read and write
malicious
72000
unkown image
page execute and read and write
malicious
72000
unkown image
page execute and read and write
malicious
72000
unkown image
page execute and read and write
malicious
510000
unkown
page read and write
clean
13EA000
heap default
page read and write
clean
6501000
unkown
page read and write
clean
31DE000
unkown
page read and write
clean
A50000
unkown image
page readonly
clean
3175000
unkown
page read and write
clean
648E000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
2BF0000
heap private
page read and write
clean
9B0000
unkown
page read and write
clean
3690000
heap private
page read and write
clean
BB8000
heap default
page read and write
clean
2FC0000
unkown
page execute and read and write
clean
A0000
unkown image
page execute and write copy
clean
F3A000
unkown image
page execute and read and write
clean
70000
unkown image
page readonly
clean
5A4000
unkown
page read and write
clean
3722000
unkown
page execute and read and write
clean
4C0000
unkown image
page readonly
clean
3D70000
heap private
page execute and read and write
clean
5A4000
unkown
page read and write
clean
23691135000
heap private
page read and write
clean
5A4000
unkown
page read and write
clean
E4E000
unkown
page read and write
clean
2DE0000
unkown
page execute and read and write
clean
7F490000
unkown image
page readonly
clean
5A4000
unkown
page read and write
clean
1F7000
unkown image
page execute and read and write
clean
5E0000
unkown
page read and write
clean
2EA4000
unkown
page execute and read and write
clean
33C0000
unkown
page execute and read and write
clean
D28000
heap default
page read and write
clean
5A4000
unkown
page read and write
clean
1491000
unkown
page read and write
clean
23691AF0000
unkown
page read and write
clean
8E000
unkown image
page execute and write copy
clean
332000
unkown image
page execute and read and write
clean
5A4000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
36D0000
heap private
page execute and read and write
clean
6500000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
7FF5E66E7000
unkown image
page readonly
clean
2FEE000
unkown
page read and write
clean
1F60000
unkown image
page readonly
clean
2DD4000
unkown
page execute and read and write
clean
B44000
unkown
page read and write
clean
367E000
unkown
page read and write
clean
3404000
unkown
page execute and read and write
clean
B10000
unkown
page read and write
clean
41FE000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
2B6C000
unkown
page execute and read and write
clean
7F4A0000
unkown image
page readonly
clean
5A4000
unkown
page read and write
clean
332000
unkown image
page execute and write copy
clean
7F492000
unkown image
page readonly
clean
7FC12000
unkown image
page readonly
clean
30B0000
heap private
page execute and read and write
clean
5A4000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
5EBE000
unkown
page read and write
clean
34C0000
unkown
page read and write
clean
6C30000
unkown
page read and write
clean
60BE000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
7F390000
unkown image
page readonly
clean
2CE4000
unkown
page execute and read and write
clean
5A4000
unkown
page read and write
clean
335000
unkown image
page execute and write copy
clean
6524000
unkown
page read and write
clean
2ECA000
unkown
page execute and read and write
clean
18FE000
unkown
page read and write
clean
2EB0000
unkown
page read and write
clean
34C4000
unkown
page execute and read and write
clean
3404000
unkown
page execute and read and write
clean
D40000
heap default
page read and write
clean
332000
unkown image
page execute and write copy
clean
A0000
unkown image
page execute and write copy
clean
3400000
unkown
page execute and read and write
clean
529F000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
B20000
unkown
page execute and read and write
clean
D00000
unkown image
page read and write
clean
F3E000
unkown image
page execute and write copy
clean
12B0000
unkown
page read and write
clean
3E4E000
unkown
page read and write
clean
34B3000
unkown
page execute and read and write
clean
23691D70000
unkown
page read and write
clean
A7E000
unkown
page read and write
clean
2CE4000
unkown
page execute and read and write
clean
72000
unkown image
page execute and write copy
clean
62BE000
unkown
page read and write
clean
7FF5D27E1000
unkown image
page readonly
clean
3C49000
unkown
page read and write
clean
11E5000
unkown image
page execute and write copy
clean
142E000
heap default
page read and write
clean
73F82FF000
unkown
page read and write
clean
111E000
unkown
page read and write
clean
8E000
unkown image
page execute and write copy
clean
335000
unkown image
page execute and read and write
clean
370C000
unkown
page execute and read and write
clean
2FC0000
unkown
page read and write
clean
2FB0000
unkown
page read and write
clean
747E000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
A3E000
unkown
page read and write
clean
424E000
unkown
page read and write
clean
2ED2000
unkown
page execute and read and write
clean
13BE000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
31FD000
unkown
page read and write
clean
7F390000
unkown image
page readonly
clean
2BA2000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
6520000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
3743000
heap private
page read and write
clean
2B9A000
unkown
page execute and read and write
clean
DB0000
unkown image
page readonly
clean
2BA0000
unkown
page read and write
clean
1491000
unkown
page read and write
clean
5F0000
heap private
page read and write
clean
70000
unkown image
page readonly
clean
A20000
unkown
page execute and read and write
clean
5A4000
unkown
page read and write
clean
3FD0000
unkown
page read and write
clean
33F4000
unkown
page execute and read and write
clean
5A4000
unkown
page read and write
clean
2EA4000
unkown
page execute and read and write
clean
5A0000
heap default
page read and write
clean
13AF000
unkown
page read and write
clean
8E000
unkown image
page execute and write copy
clean
5A4000
unkown
page read and write
clean
2E94000
unkown
page execute and read and write
clean
3223000
heap private
page read and write
clean
A0000
unkown image
page execute and read and write
clean
4CE7000
unkown
page read and write
clean
4B0000
unkown image
page readonly
clean
3113000
heap private
page read and write
clean
C18000
heap default
page read and write
clean
3090000
unkown
page read and write
clean
2BF0000
unkown
page execute and read and write
clean
3220000
heap private
page read and write
clean
7FA50000
unkown image
page readonly
clean
23690F06000
heap default
page read and write
clean
23690EEE000
unkown
page read and write
clean
3ED0000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
E4B000
unkown
page read and write
clean
7FC00000
unkown image
page readonly
clean
10AC000
unkown image
page execute and read and write
clean
3F7E000
unkown
page read and write
clean
F22000
unkown image
page execute and write copy
clean
151F000
unkown
page read and write
clean
70000
unkown image
page readonly
clean
1F7000
unkown image
page execute and read and write
clean
67EE000
unkown
page read and write
clean
3702000
unkown
page execute and read and write
clean
2EBC000
unkown
page execute and read and write
clean
5A4000
unkown
page read and write
clean
7D1000
unkown
page read and write
clean
103C000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
628E000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
3C8E000
unkown
page read and write
clean
B4B000
unkown
page read and write
clean
3100000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
23691D50000
unkown
page readonly
clean
E51000
unkown
page read and write
clean
7DA000
unkown
page read and write
clean
5F0000
unkown image
page readonly
clean
1EB000
unkown image
page execute and read and write
clean
2F23000
heap private
page read and write
clean
7F362000
unkown image
page readonly
clean
BFA000
heap default
page read and write
clean
7FF5E67E3000
unkown image
page readonly
clean
E42000
unkown
page read and write
clean
3550000
unkown image
page read and write
clean
36F0000
unkown
page read and write
clean
36CE000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
7DF5F4550000
unkown image
page readonly
clean
D47000
unkown
page read and write
clean
3750000
unkown image
page readonly
clean
5A4000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
1BE0000
unkown image
page readonly
clean
B43000
heap default
page read and write
clean
3880000
heap private
page read and write
clean
10C8000
unkown image
page execute and read and write
clean
426B000
unkown
page read and write
clean
14E0000
unkown image
page readonly
clean
9AA000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
1300000
heap default
page read and write
clean
70000
unkown image
page readonly
clean
2CD4000
unkown
page execute and read and write
clean
383F000
unkown
page read and write
clean
510000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
218000
unkown image
page execute and read and write
clean
2DEC000
unkown
page execute and read and write
clean
F20000
unkown image
page readonly
clean
12D0000
heap private
page read and write
clean
7F380000
unkown image
page readonly
clean
30F0000
unkown
page execute and read and write
clean
36FA000
unkown
page execute and read and write
clean
5A4000
unkown
page read and write
clean
7F3B0000
unkown image
page readonly
clean
5A4000
unkown
page read and write
clean
8E000
unkown image
page execute and write copy
clean
23690E60000
unkown
page read and write
clean
30F5000
unkown
page read and write
clean
23690EEE000
unkown
page read and write
clean
7BC000
unkown
page read and write
clean
2B40000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
332000
unkown image
page execute and write copy
clean
7EB000
unkown
page read and write
clean
7FF5E6822000
unkown image
page readonly
clean
8E000
unkown image
page execute and write copy
clean
70000
unkown image
page readonly
clean
36FA000
unkown
page execute and read and write
clean
73F81F9000
unkown
page read and write
clean
3A00000
unkown image
page read and write
clean
2E93000
unkown
page execute and read and write
clean
5A4000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
C76000
unkown
page read and write
clean
2E60000
unkown
page execute and read and write
clean
7FA52000
unkown image
page readonly
clean
1500000
heap default
page read and write
clean
3170000
unkown
page read and write
clean
4CC1000
unkown
page read and write
clean
2EA2000
unkown
page execute and read and write
clean
684E000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
335000
unkown image
page execute and write copy
clean
617E000
unkown
page read and write
clean
7DF5F4550000
unkown image
page readonly
clean
5A4000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
5251000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
1FC000
unkown image
page execute and read and write
clean
2EE0000
heap private
page read and write
clean
2BA7000
unkown
page execute and read and write
clean
1518000
heap default
page read and write
clean
9AD000
unkown
page read and write
clean
657E000
unkown
page read and write
clean
13B0000
unkown image
page readonly
clean
2F6B000
unkown
page read and write
clean
1350000
unkown image
page readonly
clean
5A4000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
7FA50000
unkown image
page readonly
clean
5A4000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
23691B00000
unkown
page read and write
clean
3DB0000
unkown
page read and write
clean
2FB0000
unkown
page read and write
clean
6575000
unkown
page read and write
clean
E3E000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
450000
unkown image
page readonly
clean
B70000
unkown image
page readonly
clean
156C000
heap default
page read and write
clean
67AE000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
7FF5E6159000
unkown image
page readonly
clean
10A7000
unkown image
page execute and read and write
clean
5A4000
unkown
page read and write
clean
17DE000
unkown
page read and write
clean
3763000
heap private
page read and write
clean
373B000
unkown
page execute and read and write
clean
3FC0000
unkown
page execute and read and write
clean
69B1000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
7FB00000
unkown image
page readonly
clean
9FA000
unkown
page read and write
clean
D20000
heap default
page read and write
clean
650B000
unkown
page read and write
clean
321C000
unkown
page read and write
clean
7FF5E66E2000
unkown image
page readonly
clean
3ECE000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
340C000
unkown
page execute and read and write
clean
362E000
unkown
page read and write
clean
2B62000
unkown
page execute and read and write
clean
A7E000
unkown
page read and write
clean
450000
unkown image
page readonly
clean
7F3A0000
unkown image
page readonly
clean
70000
unkown image
page readonly
clean
5A4000
unkown
page read and write
clean
6525000
unkown
page read and write
clean
A0000
unkown image
page execute and read and write
clean
5A4000
unkown
page read and write
clean
8A000
unkown image
page execute and read and write
clean
EF0000
unkown
page read and write
clean
652E000
unkown
page read and write
clean
B43000
unkown
page read and write
clean
CF0000
unkown image
page readonly
clean
6520000
unkown
page read and write
clean
7FF5E614D000
unkown image
page readonly
clean
5A4000
unkown
page read and write
clean
13F0000
heap private
page read and write
clean
7E8000
unkown
page read and write
clean
7F950000
unkown image
page readonly
clean
5A4000
unkown
page read and write
clean
7FA52000
unkown image
page readonly
clean
1B00000
unkown image
page readonly
clean
6C30000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
69B1000
unkown
page read and write
clean
7DF5F4540000
unkown image
page readonly
clean
B00000
unkown image
page readonly
clean
36A0000
unkown
page read and write
clean
B3B000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
7FF5E68C1000
unkown image
page readonly
clean
5E3E000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
2CE0000
unkown
page execute and read and write
clean
5A4000
unkown
page read and write
clean
7FC12000
unkown image
page readonly
clean
2B70000
heap private
page read and write
clean
B48000
unkown
page read and write
clean
2EAA000
unkown
page execute and read and write
clean
450000
unkown image
page readonly
clean
5A4000
unkown
page read and write
clean
5B0000
unkown image
page readonly
clean
723E000
unkown
page read and write
clean
2C82000
unkown
page execute and read and write
clean
C80000
unkown image
page readonly
clean
23690E80000
unkown
page read and write
clean
218000
unkown image
page execute and read and write
clean
3CDA000
unkown
page read and write
clean
2EAC000
unkown
page execute and read and write
clean
5A4000
unkown
page read and write
clean
6528000
unkown
page read and write
clean
23691D60000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
30F0000
unkown
page read and write
clean
4C0000
unkown image
page readonly
clean
F50000
unkown image
page execute and write copy
clean
2B50000
unkown image
page readonly
clean
5A4000
unkown
page read and write
clean
1FC000
unkown image
page execute and read and write
clean
5A4000
unkown
page read and write
clean
2CD3000
unkown
page execute and read and write
clean
4AC000
unkown
page read and write
clean
A20000
unkown image
page readonly
clean
65AE000
unkown
page read and write
clean
2DD3000
unkown
page execute and read and write
clean
23690F09000
heap default
page read and write
clean
6B3000
unkown
page read and write
clean
3060000
unkown
page execute and read and write
clean
7FA70000
unkown image
page readonly
clean
5A4000
unkown
page read and write
clean
8A000
unkown image
page execute and read and write
clean
332000
unkown image
page execute and read and write
clean
1430000
heap private
page read and write
clean
5A4000
unkown
page read and write
clean
332000
unkown image
page execute and read and write
clean
3050000
heap private
page read and write
clean
3A60000
unkown
page read and write
clean
3404000
unkown
page execute and read and write
clean
5A4000
unkown
page read and write
clean
7FF5E612F000
unkown image
page readonly
clean
7F0000
unkown image
page read and write
clean
69EE000
unkown
page read and write
clean
2C30000
heap private
page read and write
clean
7FF5E68D1000
unkown image
page readonly
clean
2CE4000
unkown
page execute and read and write
clean
2F9E000
unkown
page read and write
clean
404E000
unkown
page read and write
clean
23690E30000
unkown image
page readonly
clean
2FAA000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
E60000
unkown
page read and write
clean
9B6000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
2C10000
heap private
page read and write
clean
2C7E000
unkown
page read and write
clean
727D000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
23691D20000
unkown image
page read and write
clean
301E000
unkown
page read and write
clean
34C4000
unkown
page execute and read and write
clean
7FF5E68BA000
unkown image
page readonly
clean
38CE000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
B60000
heap default
page read and write
clean
5A4000
unkown
page read and write
clean
2DE4000
unkown
page execute and read and write
clean
218000
unkown image
page execute and read and write
clean
637E000
unkown
page read and write
clean
B00000
heap private
page read and write
clean
5A4000
unkown
page read and write
clean
3850000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
3A3E000
unkown
page read and write
clean
2CA0000
unkown
page execute and read and write
clean
E54000
unkown
page read and write
clean
23690E10000
unkown image
page readonly
clean
1305000
heap default
page read and write
clean
7FA60000
unkown image
page readonly
clean
2CE4000
unkown
page execute and read and write
clean
5A4000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
335000
unkown image
page execute and read and write
clean
23690E00000
unkown
page read and write
clean
F20000
unkown image
page readonly
clean
123A000
unkown
page read and write
clean
F00000
unkown
page execute and read and write
clean
1EB000
unkown image
page execute and read and write
clean
2CE4000
unkown
page execute and read and write
clean
70000
unkown image
page readonly
clean
2CE4000
unkown
page execute and read and write
clean
60BE000
unkown
page read and write
clean
7DC000
unkown
page read and write
clean
8E000
unkown image
page execute and write copy
clean
64BE000
unkown
page read and write
clean
353E000
unkown
page read and write
clean
E9E000
unkown
page read and write
clean
326E000
unkown
page read and write
clean
30F0000
unkown
page read and write
clean
7FF5E681B000
unkown image
page readonly
clean
3404000
unkown
page execute and read and write
clean
B41000
unkown
page read and write
clean
B3C000
unkown
page read and write
clean
622E000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
2DEC000
unkown
page execute and read and write
clean
5A4000
unkown
page read and write
clean
7DD000
unkown
page read and write
clean
1236000
unkown
page read and write
clean
2C8A000
unkown
page execute and read and write
clean
703E000
unkown
page read and write
clean
23690E40000
unkown image
page readonly
clean
3737000
unkown
page execute and read and write
clean
7FC02000
unkown image
page readonly
clean
7FC00000
unkown image
page readonly
clean
7DF5F4532000
unkown image
page readonly
clean
5A4000
unkown
page read and write
clean
32AE000
unkown
page read and write
clean
68BE000
unkown
page read and write
clean
236910D0000
unkown
page read and write
clean
34C4000
unkown
page execute and read and write
clean
3B7E000
unkown
page read and write
clean
2CEC000
unkown
page execute and read and write
clean
2EF0000
heap private
page read and write
clean
1EB000
unkown image
page execute and read and write
clean
5A4000
unkown
page read and write
clean
2EA4000
unkown
page execute and read and write
clean
A0000
unkown image
page execute and write copy
clean
BA0000
unkown image
page read and write
clean
2970000
heap private
page read and write
clean
5A4000
unkown
page read and write
clean
4B0000
unkown image
page readonly
clean
335000
unkown image
page execute and read and write
clean
12E0000
heap private
page read and write
clean
2CCB000
unkown
page execute and read and write
clean
5A4000
unkown
page read and write
clean
B38000
unkown
page read and write
clean
323C000
unkown
page read and write
clean
12AE000
unkown
page read and write
clean
2EA0000
unkown
page execute and read and write
clean
AF0000
unkown image
page readonly
clean
73F8279000
unkown
page read and write
clean
4AC000
unkown
page read and write
clean
37AE000
unkown
page read and write
clean
2B52000
unkown
page execute and read and write
clean
2CEC000
unkown
page execute and read and write
clean
7FA70000
unkown image
page readonly
clean
7F480000
unkown image
page readonly
clean
7DF5F4540000
unkown image
page readonly
clean
390D000
unkown
page read and write
clean
3040000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
7F362000
unkown image
page readonly
clean
7F3A2000
unkown image
page readonly
clean
5A4000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
34C4000
unkown
page execute and read and write
clean
2C20000
unkown
page read and write
clean
B8E000
unkown
page read and write
clean
13E0000
heap default
page read and write
clean
6510000
unkown
page read and write
clean
2C90000
unkown
page read and write
clean
1AFF000
unkown
page read and write
clean
2F77000
unkown
page execute and read and write
clean
19DE000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
2EA4000
unkown
page execute and read and write
clean
3CC9000
unkown
page read and write
clean
1360000
heap private
page read and write
clean
23691D40000
unkown
page read and write
clean
7F480000
unkown image
page readonly
clean
3100000
heap private
page read and write
clean
2EA4000
unkown
page execute and read and write
clean
2BE0000
heap private
page read and write
clean
9F6000
unkown
page read and write
clean
B90000
unkown image
page readonly
clean
23690EA9000
heap default
page read and write
clean
DD0000
unkown image
page readonly
clean
5A4000
unkown
page read and write
clean
6510000
unkown
page read and write
clean
145F000
heap default
page read and write
clean
A0000
unkown image
page execute and read and write
clean
2DE4000
unkown
page execute and read and write
clean
2C3E000
unkown
page read and write
clean
34CC000
unkown
page execute and read and write
clean
5A4000
unkown
page read and write
clean
E5D000
unkown
page read and write
clean
23691070000
unkown image
page readonly
clean
3F81000
unkown
page read and write
clean
2FC0000
unkown
page read and write
clean
34C4000
unkown
page execute and read and write
clean
9FA000
unkown
page read and write
clean
34B4000
unkown
page execute and read and write
clean
372B000
unkown
page execute and read and write
clean
4AC000
unkown
page read and write
clean
BF4000
heap default
page read and write
clean
7DF5F4532000
unkown image
page readonly
clean
F3E000
unkown image
page execute and write copy
clean
A3E000
unkown
page read and write
clean
7FF5E67D6000
unkown image
page readonly
clean
3480000
unkown
page execute and read and write
clean
3560000
heap private
page read and write
clean
73F807C000
unkown
page read and write
clean
2DA0000
unkown
page execute and read and write
clean
7E5000
unkown
page read and write
clean
EE0000
unkown image
page readonly
clean
3C41000
unkown
page read and write
clean
36F2000
unkown
page execute and read and write
clean
5A4000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
7FC10000
unkown image
page readonly
clean
5A4000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
7FA62000
unkown image
page readonly
clean
E5E000
unkown
page read and write
clean
33B0000
heap private
page read and write
clean
5A4000
unkown
page read and write
clean
41F1000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
340C000
unkown
page execute and read and write
clean
2EAC000
unkown
page execute and read and write
clean
5A4000
unkown
page read and write
clean
236910C0000
unkown
page read and write
clean
7F370000
unkown image
page readonly
clean
2DDE000
unkown
page read and write
clean
23691350000
unkown image
page readonly
clean
B4B000
unkown
page read and write
clean
3740000
heap private
page read and write
clean
72000
unkown image
page execute and write copy
clean
7F482000
unkown image
page readonly
clean
5E7E000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
7FF5E68B4000
unkown image
page readonly
clean
2CA0000
unkown
page execute and read and write
clean
5A4000
unkown
page read and write
clean
332000
unkown image
page execute and write copy
clean
2E50000
heap private
page read and write
clean
7E2000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
D45000
heap default
page read and write
clean
DE0000
unkown image
page readonly
clean
5A4000
unkown
page read and write
clean
3C3E000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
2B8A000
unkown
page execute and read and write
clean
3A5E000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
525000
heap default
page read and write
clean
ADB000
heap default
page read and write
clean
5A4000
unkown
page read and write
clean
7F482000
unkown image
page readonly
clean
5A4000
unkown
page read and write
clean
7F4A0000
unkown image
page readonly
clean
5A4000
unkown
page read and write
clean
2B5A000
unkown
page execute and read and write
clean
64CD000
unkown
page read and write
clean
34CC000
unkown
page execute and read and write
clean
5A4000
unkown
page read and write
clean
7F360000
unkown image
page readonly
clean
335000
unkown image
page execute and write copy
clean
9FA000
unkown
page read and write
clean
7FF5E67F0000
unkown image
page readonly
clean
3CC1000
unkown
page read and write
clean
41F9000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
A80000
heap default
page read and write
clean
2F00000
heap private
page read and write
clean
5A4000
unkown
page read and write
clean
70000
unkown image
page readonly
clean
23691140000
unkown
page read and write
clean
6A8E000
unkown
page read and write
clean
A8A000
heap default
page read and write
clean
5A4000
unkown
page read and write
clean
1507000
heap default
page read and write
clean
7FF5E684A000
unkown image
page readonly
clean
5A4000
unkown
page read and write
clean
2F7B000
unkown
page execute and read and write
clean
5A4000
unkown
page read and write
clean
7FF5E673C000
unkown image
page readonly
clean
5A4000
unkown
page read and write
clean
7FC02000
unkown image
page readonly
clean
B4E000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
D2E000
unkown
page read and write
clean
3712000
unkown
page execute and read and write
clean
11AF000
unkown
page read and write
clean
7FF5E614F000
unkown image
page readonly
clean
3404000
unkown
page execute and read and write
clean
7F372000
unkown image
page readonly
clean
2B80000
unkown
page read and write
clean
6C31000
unkown
page read and write
clean
4C41000
unkown
page read and write
clean
7FF5E67DF000
unkown image
page readonly
clean
5A4000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
72000
unkown image
page execute and write copy
clean
5A4000
unkown
page read and write
clean
7FF5E6128000
unkown image
page readonly
clean
2B6A000
unkown
page execute and read and write
clean
5A4000
unkown
page read and write
clean
2F20000
heap private
page read and write
clean
7FF5E615E000
unkown image
page readonly
clean
3AB0000
heap private
page execute and read and write
clean
72000
unkown image
page execute and write copy
clean
5A4000
unkown
page read and write
clean
7F492000
unkown image
page readonly
clean
2FBE000
unkown
page read and write
clean
23690EEE000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
7C8000
unkown
page read and write
clean
7FF5E68C5000
unkown image
page readonly
clean
12FE000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
ABE000
unkown
page read and write
clean
3190000
heap private
page read and write
clean
5A4000
unkown
page read and write
clean
7F392000
unkown image
page readonly
clean
2B87000
unkown
page execute and read and write
clean
70000
unkown image
page readonly
clean
371A000
unkown
page execute and read and write
clean
D30000
unkown image
page readonly
clean
7B8000
unkown
page read and write
clean
236916E0000
unkown image
page readonly
clean
7DF5F4530000
unkown image
page readonly
clean
3F90000
unkown image
page readonly
clean
4C0000
unkown image
page readonly
clean
5A4000
unkown
page read and write
clean
7FF5D27E1000
unkown image
page readonly
clean
3095000
unkown
page read and write
clean
3640000
heap private
page read and write
clean
5A4000
unkown
page read and write
clean
E5A000
unkown
page read and write
clean
2BAB000
unkown
page execute and read and write
clean
2BC0000
unkown image
page readonly
clean
7FF5E682E000
unkown image
page readonly
clean
7EE000
unkown
page read and write
clean
3FB0000
unkown
page read and write
clean
218000
unkown image
page execute and read and write
clean
B40000
unkown
page read and write
clean
3404000
unkown
page execute and read and write
clean
3540000
unkown image
page readonly
clean
DB0000
unkown image
page readonly
clean
450000
unkown image
page readonly
clean
B65000
heap default
page read and write
clean
2DE4000
unkown
page execute and read and write
clean
3070000
unkown
page read and write
clean
688E000
unkown
page read and write
clean
34C4000
unkown
page execute and read and write
clean
2EBE000
unkown
page read and write
clean
23690EA0000
heap default
page read and write
clean
156E000
heap default
page read and write
clean
450000
unkown image
page readonly
clean
5A4000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
34D0000
unkown
page execute and read and write
clean
33B0000
heap private
page read and write
clean
440000
unkown image
page read and write
clean
B48000
heap default
page read and write
clean
5A4000
unkown
page read and write
clean
3580000
unkown image
page readonly
clean
3FE0000
heap private
page execute and read and write
clean
109B000
unkown image
page execute and read and write
clean
3CBE000
unkown
page read and write
clean
394B000
unkown
page read and write
clean
607E000
unkown
page read and write
clean
332000
unkown image
page execute and read and write
clean
5A4000
unkown
page read and write
clean
E57000
unkown
page read and write
clean
2C90000
heap private
page read and write
clean
73F817E000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
2BD0000
unkown
page read and write
clean
7F490000
unkown image
page readonly
clean
9BC000
unkown
page read and write
clean
3404000
unkown
page execute and read and write
clean
5A4000
unkown
page read and write
clean
70000
unkown image
page readonly
clean
3727000
unkown
page execute and read and write
clean
7CE000
unkown
page read and write
clean
ABE000
unkown
page read and write
clean
23691DC0000
unkown
page read and write
clean
7F372000
unkown image
page readonly
clean
5A4000
unkown
page read and write
clean
7FF5E684D000
unkown image
page readonly
clean
2C80000
unkown
page read and write
clean
236916D0000
unkown image
page readonly
clean
7DF5F4542000
unkown image
page readonly
clean
11E2000
unkown image
page execute and write copy
clean
5A4000
unkown
page read and write
clean
23690F0D000
heap default
page read and write
clean
7FF5E60E8000
unkown image
page readonly
clean
7DF5F4530000
unkown image
page readonly
clean
11E5000
unkown image
page execute and read and write
clean
30AD000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
F50000
unkown image
page execute and read and write
clean
2EB2000
unkown
page execute and read and write
clean
370A000
unkown
page execute and read and write
clean
36D0000
unkown
page read and write
clean
A7C000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
6580000
unkown
page read and write
clean
33F3000
unkown
page execute and read and write
clean
7F260000
unkown image
page readonly
clean
4251000
unkown
page read and write
clean
370A000
unkown
page execute and read and write
clean
7C9000
unkown
page read and write
clean
335000
unkown image
page execute and write copy
clean
BB0000
heap default
page read and write
clean
5A4000
unkown
page read and write
clean
23690EB1000
heap default
page read and write
clean
70000
unkown image
page readonly
clean
1BDF000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
32EE000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
2C9A000
unkown
page execute and read and write
clean
3170000
unkown
page read and write
clean
2CE0000
unkown
page execute and read and write
clean
440000
unkown image
page read and write
clean
7FC20000
unkown image
page readonly
clean
5A4000
unkown
page read and write
clean
23691130000
heap private
page read and write
clean
13D0000
unkown image
page readonly
clean
23691550000
unkown image
page readonly
clean
2CB2000
unkown
page execute and read and write
clean
62FE000
unkown
page read and write
clean
2B60000
unkown
page read and write
clean
A00000
unkown image
page readonly
clean
8E000
unkown image
page execute and write copy
clean
2E1E000
unkown
page read and write
clean
A60000
unkown image
page read and write
clean
12F0000
heap private
page read and write
clean
39F0000
unkown
page read and write
clean
520000
heap default
page read and write
clean
36FC000
unkown
page execute and read and write
clean
2FE0000
heap private
page read and write
clean
1FC000
unkown image
page execute and read and write
clean
6C2E000
unkown
page read and write
clean
4F81000
unkown
page read and write
clean
64FE000
unkown
page read and write
clean
62BE000
unkown
page read and write
clean
1DE0000
unkown image
page readonly
clean
A20000
unkown image
page readonly
clean
9A7000
unkown
page read and write
clean
B20000
unkown
page execute and read and write
clean
1440000
unkown image
page readonly
clean
D64000
heap default
page read and write
clean
1730000
unkown image
page readonly
clean
AB9000
heap default
page read and write
clean
2C7E000
unkown
page read and write
clean
7F360000
unkown image
page readonly
clean
7F3A0000
unkown image
page readonly
clean
34CC000
unkown
page execute and read and write
clean
397E000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
7D4000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
7FA62000
unkown image
page readonly
clean
36EA000
unkown
page execute and read and write
clean
B34000
unkown
page read and write
clean
36E0000
unkown
page read and write
clean
7FF5E612A000
unkown image
page readonly
clean
144E000
heap default
page read and write
clean
5A4000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
677E000
unkown
page read and write
clean
7DF5F4542000
unkown image
page readonly
clean
76BC000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
3870000
unkown
page read and write
clean
398C000
unkown
page read and write
clean
7FF5E68D1000
unkown image
page readonly
clean
5A4000
unkown
page read and write
clean
3380000
unkown
page execute and read and write
clean
5A4000
unkown
page read and write
clean
7FF5E68CA000
unkown image
page readonly
clean
5A4000
unkown
page read and write
clean
450000
unkown image
page readonly
clean
3700000
unkown
page read and write
clean
1520000
unkown image
page readonly
clean
5A4000
unkown
page read and write
clean
2B92000
unkown
page execute and read and write
clean
1D00000
unkown image
page readonly
clean
8A000
unkown image
page execute and read and write
clean
4270000
unkown
page read and write
clean
2CC7000
unkown
page execute and read and write
clean
2DE4000
unkown
page execute and read and write
clean
4B0000
unkown image
page readonly
clean
9F6000
unkown
page read and write
clean
440000
unkown image
page read and write
clean
1EB000
unkown image
page execute and read and write
clean
3090000
unkown
page read and write
clean
2EA4000
unkown
page execute and read and write
clean
2C9C000
unkown
page execute and read and write
clean
41EE000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
2A80000
unkown image
page readonly
clean
70000
unkown image
page readonly
clean
5A4000
unkown
page read and write
clean
2EA4000
unkown
page execute and read and write
clean
5A4000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
7DF4F2400000
unkown image
page readonly
clean
5A4000
unkown
page read and write
clean
13E0000
unkown image
page readonly
clean
A10000
unkown
page read and write
clean
C90000
unkown image
page readonly
clean
7F380000
unkown image
page readonly
clean
7FF5E6123000
unkown image
page readonly
clean
2CAA000
unkown
page execute and read and write
clean
5A4000
unkown
page read and write
clean
36E2000
unkown
page execute and read and write
clean
296E000
unkown
page read and write
clean
23690DF0000
unkown image
page read and write
clean
2C30000
heap private
page read and write
clean
1150000
unkown image
page readonly
clean
7FF5E67E6000
unkown image
page readonly
clean
5A4000
unkown
page read and write
clean
8A000
unkown image
page execute and read and write
clean
5A4000
unkown
page read and write
clean
6570000
unkown
page read and write
clean
FAF000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
32A0000
unkown
page execute and read and write
clean
3E8E000
unkown
page read and write
clean
13C0000
heap private
page read and write
clean
664E000
unkown
page read and write
clean
2DE4000
unkown
page execute and read and write
clean
5A4000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
642E000
unkown
page read and write
clean
3FA0000
heap private
page read and write
clean
AC0000
unkown image
page readonly
clean
CE0000
unkown
page read and write
clean
F20000
unkown image
page readonly
clean
7FF5E68A2000
unkown image
page readonly
clean
7D7000
unkown
page read and write
clean
1F7000
unkown image
page execute and read and write
clean
34C4000
unkown
page execute and read and write
clean
7FA60000
unkown image
page readonly
clean
7CD000
unkown
page read and write
clean
6B7000
unkown
page read and write
clean
C32000
heap default
page read and write
clean
3B81000
unkown
page read and write
clean
3110000
heap private
page read and write
clean
2EBA000
unkown
page execute and read and write
clean
73F83FF000
unkown
page read and write
clean
997000
unkown
page read and write
clean
1F7000
unkown image
page execute and read and write
clean
7FC20000
unkown image
page readonly
clean
2980000
unkown
page execute and read and write
clean
3B80000
unkown
page read and write
clean
6CCE000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
335000
unkown image
page execute and read and write
clean
656C000
unkown
page read and write
clean
3F89000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
7FF5E67F3000
unkown image
page readonly
clean
3070000
unkown
page read and write
clean
7F370000
unkown image
page readonly
clean
B50000
unkown image
page readonly
clean
5A4000
unkown
page read and write
clean
3030000
unkown image
page readonly
clean
99B000
unkown
page read and write
clean
2CD0000
heap private
page read and write
clean
2B30000
unkown image
page readonly
clean
306E000
unkown
page read and write
clean
B10000
unkown
page read and write
clean
2E20000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
292E000
unkown
page read and write
clean
30F0000
unkown
page read and write
clean
8E000
unkown image
page execute and write copy
clean
5A4000
unkown
page read and write
clean
73F80FD000
unkown
page read and write
clean
B4E000
heap default
page read and write
clean
2FF0000
heap private
page read and write
clean
74BE000
unkown
page read and write
clean
2DE4000
unkown
page execute and read and write
clean
2C20000
heap private
page read and write
clean
2FA0000
unkown image
page readonly
clean
5A4000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
51F1000
unkown
page read and write
clean
23690E10000
unkown image
page readonly
clean
69B0000
unkown
page read and write
clean
2CE4000
unkown
page execute and read and write
clean
7FF5E67DD000
unkown image
page readonly
clean
1FC000
unkown image
page execute and read and write
clean
302E000
unkown
page read and write
clean
2DE4000
unkown
page execute and read and write
clean
5A4000
unkown
page read and write
clean
7FC10000
unkown image
page readonly
clean
372A000
unkown
page execute and read and write
clean
5A4000
unkown
page read and write
clean
34C0000
unkown
page execute and read and write
clean
DA0000
unkown image
page read and write
clean
5A4000
unkown
page read and write
clean
3760000
heap private
page read and write
clean
2FD0000
heap private
page read and write
clean
9B9000
unkown
page read and write
clean
66BD000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
3580000
heap private
page read and write
clean
23691139000
heap private
page read and write
clean
9F5000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
7FF5E666A000
unkown image
page readonly
clean
7FF5E68A9000
unkown image
page readonly
clean
11E2000
unkown image
page execute and read and write
clean
36F2000
unkown
page execute and read and write
clean
23690EE6000
unkown
page read and write
clean
1E80000
unkown image
page readonly
clean
33A0000
unkown image
page readonly
clean
7F392000
unkown image
page readonly
clean
5A4000
unkown
page read and write
clean
A0000
unkown image
page execute and read and write
clean
5258000
unkown
page read and write
clean
3570000
heap private
page read and write
clean
14D0000
unkown image
page readonly
clean
30EB000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
7F290000
unkown image
page readonly
clean
5A4000
unkown
page read and write
clean
D92000
heap default
page read and write
clean
5A4000
unkown
page read and write
clean
131F000
unkown
page read and write
clean
3860000
unkown
page execute and read and write
clean
ED0000
heap private
page read and write
clean
5A4000
unkown
page read and write
clean
A0000
unkown image
page execute and write copy
clean
5A4000
unkown
page read and write
clean
6A2E000
unkown
page read and write
clean
2C92000
unkown
page execute and read and write
clean
7DF000
unkown
page read and write
clean
2C00000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
3730000
unkown
page read and write
clean
7F380000
unkown image
page readonly
clean
9B3000
unkown
page read and write
clean
15B0000
unkown image
page readonly
clean
6ACE000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
5A4000
unkown
page read and write
clean
3270000
heap private
page read and write
clean
1543000
heap default
page read and write
clean
73F8379000
unkown
page read and write
clean
7F3A2000
unkown image
page readonly
clean
7F3B0000
unkown image
page readonly
clean
3680000
unkown image
page read and write
clean
There are 998 hidden memdumps, click here to show them.