IOC Report

loading gif

Files

File Path
Type
Category
Malicious
Packing List.xlsx
CDFV2 Encrypted
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\vbc[1].exe
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
downloaded
malicious
C:\Users\user\Desktop\~$Packing List.xlsx
data
dropped
malicious
C:\Users\Public\vbc.exe
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\251FF695.png
PNG image data, 550 x 360, 8-bit colormap, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\27DB9FE4.emf
Windows Enhanced Metafile (EMF) image data version 0x10000
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\5268BA6B.png
PNG image data, 838 x 469, 8-bit colormap, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\67EFF2A.png
PNG image data, 737 x 456, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\6EA2EAB1.png
PNG image data, 1295 x 471, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\731170FE.jpeg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 150x150, segment length 16, baseline, precision 8, 1275x1650, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\84D2F0C8.jpeg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 150x150, segment length 16, baseline, precision 8, 1275x1650, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\9950728D.png
PNG image data, 838 x 469, 8-bit colormap, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\C4C845BC.png
PNG image data, 458 x 211, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\D3B5F0E7.png
PNG image data, 550 x 360, 8-bit colormap, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\D937B123.png
PNG image data, 1295 x 471, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Temp\dobvw7pi71yxrkawv
data
dropped
clean
C:\Users\user\AppData\Local\Temp\nsn3BBA.tmp\oxtrp.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\Local\Temp\~DF3DF424E48F9DA5FE.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DF60529B904FCF6857.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DF63AE2933B69E3EF1.TMP
CDFV2 Encrypted
dropped
clean
C:\Users\user\AppData\Local\Temp\~DFB3F4E2B4E1F422B3.TMP
data
dropped
clean
There are 11 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
'C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE' -Embedding
malicious
C:\Users\Public\vbc.exe
'C:\Users\Public\vbc.exe'
malicious
C:\Users\Public\vbc.exe
'C:\Users\Public\vbc.exe'
malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
clean

URLs

Name
IP
Malicious
http://192.227.228.38/0078/vbc.exe
192.227.228.38
malicious
http://www.%s.comPA
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://nsis.sf.net/NSIS_Error
unknown
clean
http://nsis.sf.net/NSIS_ErrorError
unknown
clean

IPs

IP
Domain
Country
Malicious
192.227.228.38
unknown
United States
malicious

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
w))
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
MTTT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\2F289
2F289
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
=2)
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\33E19
33E19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\354F3
354F3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 21
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
EXCELFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Name
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\33E19
33E19
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
EquationEditorFilesIntl_1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
There are 32 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
30BA000
unkown
page read and write
malicious
7FFFFFB0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
42D000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
409000
unkown image
page write copy
clean
7FFFFFC2000
unkown image
page readonly
clean
3190000
heap private
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
190000
unkown image
page readonly
clean
190000
unkown image
page readonly
clean
407000
unkown image
page readonly
clean
1A0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
F400000
unkown
page read and write
clean
401000
unkown image
page execute read
clean
F300000
unkown
page read and write
clean
F3E0000
unkown
page read and write
clean
820000
unkown image
page readonly
clean
2E0000
unkown
page read and write
clean
F3F7000
unkown
page read and write
clean
409000
unkown image
page write copy
clean
28A0000
unkown
page read and write
clean
401000
unkown image
page execute read
clean
407000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
6DE000
stack
page read and write
clean
F460000
unkown
page read and write
clean
160000
unkown image
page read and write
clean
1D8000
unkown
page execute and read and write
clean
9C0000
unkown image
page readonly
clean
407000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
190000
unkown image
page readonly
clean
F460000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
190000
unkown image
page readonly
clean
F3E0000
unkown
page read and write
clean
F400000
unkown
page read and write
clean
1C0000
unkown
page execute and read and write
clean
3260000
unkown
page read and write
clean
F2F0000
unkown
page read and write
clean
1A0000
unkown image
page readonly
clean
42A000
unkown image
page read and write
clean
494000
heap default
page read and write
clean
67A000
stack
page read and write
clean
407000
unkown image
page readonly
clean
150000
unkown image
page readonly
clean
400000
unkown image
page readonly
clean
215000
unkown
page read and write
clean
F3F4000
unkown
page read and write
clean
407000
unkown image
page readonly
clean
333D000
unkown
page read and write
clean
1A0000
unkown image
page readonly
clean
880000
unkown image
page readonly
clean
73230000
unkown image
page readonly
clean
F3F7000
unkown
page read and write
clean
F3F4000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
F3F1000
unkown
page read and write
clean
1C0000
unkown
page execute and read and write
clean
2A0000
unkown image
page readonly
clean
6F6000
heap private
page read and write
clean
401000
unkown image
page execute read
clean
F300000
unkown
page read and write
clean
400000
unkown image
page readonly
clean
830000
unkown image
page readonly
clean
21C2000
heap private
page read and write
clean
407000
unkown image
page readonly
clean
190000
unkown image
page readonly
clean
407000
unkown image
page readonly
clean
190000
unkown image
page readonly
clean
401000
unkown image
page execute read
clean
190000
unkown image
page readonly
clean
48E000
stack
page read and write
clean
1C0000
unkown
page execute and read and write
clean
3260000
unkown
page read and write
clean
3260000
unkown
page read and write
clean
F3E0000
unkown
page read and write
clean
407000
unkown image
page readonly
clean
42D000
unkown image
page readonly
clean
F3F1000
unkown
page read and write
clean
F2F0000
unkown
page read and write
clean
5C0000
unkown image
page readonly
clean
F3E0000
unkown
page read and write
clean
21E0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
333A000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
F3F7000
unkown
page read and write
clean
42D000
unkown image
page readonly
clean
F2F0000
unkown
page read and write
clean
3260000
unkown
page read and write
clean
400000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
2130000
heap private
page read and write
clean
401000
unkown image
page execute read
clean
7EFC2000
unkown image
page readonly
clean
1C0000
unkown
page execute and read and write
clean
7EFB0000
unkown image
page readonly
clean
470000
heap default
page read and write
clean
1FF0000
heap private
page read and write
clean
42D000
unkown image
page readonly
clean
F400000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
F400000
unkown
page read and write
clean
F300000
unkown
page read and write
clean
190000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
F460000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
F3E0000
unkown
page read and write
clean
1F40000
unkown
page read and write
clean
42D000
unkown image
page readonly
clean
1A0000
unkown image
page readonly
clean
407000
unkown image
page readonly
clean
407000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
401000
unkown image
page execute read
clean
7FFFFFC0000
unkown image
page readonly
clean
D30000
unkown image
page readonly
clean
409000
unkown image
page write copy
clean
190000
unkown image
page readonly
clean
1C9000
unkown
page execute and read and write
clean
400000
unkown image
page readonly
clean
212000
heap default
page read and write
clean
1D5000
unkown
page execute and read and write
clean
400000
unkown image
page readonly
clean
400000
unkown image
page readonly
clean
F300000
unkown
page read and write
clean
1A0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
417000
unkown image
page read and write
clean
409000
unkown image
page write copy
clean
333D000
unkown
page read and write
clean
F300000
unkown
page read and write
clean
42D000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
F460000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
1C0000
unkown
page execute and read and write
clean
CD000
unkown
page read and write
clean
400000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
42D000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
409000
unkown image
page write copy
clean
7EFC0000
unkown image
page readonly
clean
409000
unkown image
page write copy
clean
360000
heap default
page read and write
clean
409000
unkown image
page write copy
clean
7EFB2000
unkown image
page readonly
clean
333A000
unkown
page read and write
clean
28A0000
unkown
page read and write
clean
1C0000
unkown
page execute and read and write
clean
700000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
F3F4000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
1C0000
unkown
page execute and read and write
clean
890000
unkown image
page readonly
clean
F460000
unkown
page read and write
clean
1D5000
unkown
page execute and read and write
clean
400000
unkown image
page readonly
clean
400000
unkown image
page readonly
clean
409000
unkown image
page read and write
clean
230000
unkown image
page readonly
clean
F3F1000
unkown
page read and write
clean
1A0000
unkown image
page readonly
clean
F3F4000
unkown
page read and write
clean
407000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
190000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
1360000
heap private
page read and write
clean
1DD000
heap default
page read and write
clean
190000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
407000
unkown image
page readonly
clean
F2F0000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
28A0000
unkown
page read and write
clean
401000
unkown image
page execute read
clean
42D000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
407000
unkown image
page readonly
clean
21B000
heap default
page read and write
clean
333D000
unkown
page read and write
clean
F400000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
F3F7000
unkown
page read and write
clean
190000
unkown image
page readonly
clean
F3E0000
unkown
page read and write
clean
522000
heap default
page read and write
clean
D20000
unkown image
page readonly
clean
F3F7000
unkown
page read and write
clean
1C0000
unkown
page execute and read and write
clean
1A0000
unkown image
page readonly
clean
F3F1000
unkown
page read and write
clean
333A000
unkown
page read and write
clean
400000
unkown image
page readonly
clean
20000
unkown
page read and write
clean
F3F4000
unkown
page read and write
clean
F2F0000
unkown
page read and write
clean
6A0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
409000
unkown image
page write copy
clean
333A000
unkown
page read and write
clean
400000
unkown image
page readonly
clean
F2F0000
unkown
page read and write
clean
1D8000
unkown
page readonly
clean
401000
unkown image
page execute read
clean
510000
heap default
page read and write
clean
401000
unkown image
page execute read
clean
477000
heap default
page read and write
clean
407000
unkown image
page readonly
clean
F460000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
333A000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
21D000
stack
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
F2F0000
unkown
page read and write
clean
1A0000
heap default
page read and write
clean
7EFC0000
unkown image
page readonly
clean
333D000
unkown
page read and write
clean
4C0000
heap default
page read and write
clean
409000
unkown image
page write copy
clean
7EFC0000
unkown image
page readonly
clean
20FF000
stack
page read and write
clean
F400000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
30B0000
unkown
page read and write
clean
73235000
unkown image
page execute and read and write
clean
20A000
unkown
page read and write
clean
333D000
unkown
page read and write
clean
51F000
stack
page read and write
clean
F300000
unkown
page read and write
clean
3B6000
unkown
page read and write
clean
3130000
heap private
page read and write
clean
1A0000
unkown image
page readonly
clean
F2F0000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7EFB0000
unkown image
page readonly
clean
F460000
unkown
page read and write
clean
1A0000
unkown image
page readonly
clean
409000
unkown image
page write copy
clean
F460000
unkown
page read and write
clean
409000
unkown image
page write copy
clean
1F1F000
stack
page read and write
clean
F3F7000
unkown
page read and write
clean
F3E0000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
333D000
unkown
page read and write
clean
3F0000
unkown image
page readonly
clean
F3E0000
unkown
page read and write
clean
401000
unkown image
page execute read
clean
1A0000
unkown image
page readonly
clean
3260000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
6F0000
heap private
page read and write
clean
333A000
unkown
page read and write
clean
333D000
unkown
page read and write
clean
4C7000
heap default
page read and write
clean
42D000
unkown image
page readonly
clean
422000
unkown image
page read and write
clean
73237000
unkown image
page readonly
clean
F300000
unkown
page read and write
clean
205000
unkown
page read and write
clean
400000
unkown image
page readonly
clean
400000
unkown image
page readonly
clean
3260000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
F300000
unkown
page read and write
clean
1D5000
unkown
page execute and read and write
clean
6E0000
unkown image
page readonly
clean
208000
heap default
page read and write
clean
BA0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
F300000
unkown
page read and write
clean
333D000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
3260000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
42D000
unkown image
page readonly
clean
42D000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
407000
unkown image
page readonly
clean
F3F1000
unkown
page read and write
clean
F400000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
190000
unkown image
page readonly
clean
42D000
unkown image
page readonly
clean
42D000
unkown image
page readonly
clean
F3F1000
unkown
page read and write
clean
401000
unkown image
page execute read
clean
42D000
unkown image
page readonly
clean
1A0000
unkown image
page readonly
clean
170000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
333A000
unkown
page read and write
clean
3260000
unkown
page read and write
clean
F3F4000
unkown
page read and write
clean
F3F1000
unkown
page read and write
clean
31E000
stack
page read and write
clean
7EFD0000
unkown image
page readonly
clean
1A0000
unkown image
page readonly
clean
333A000
unkown
page read and write
clean
F3F7000
unkown
page read and write
clean
F3F1000
unkown
page read and write
clean
F3F4000
unkown
page read and write
clean
F3F1000
unkown
page read and write
clean
F2F0000
unkown
page read and write
clean
F3F4000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
401000
unkown image
page execute read
clean
400000
unkown image
page readonly
clean
401000
unkown image
page execute read
clean
7EFB2000
unkown image
page readonly
clean
3260000
unkown
page read and write
clean
409000
unkown image
page write copy
clean
400000
unkown image
page readonly
clean
F3E0000
unkown
page read and write
clean
1F0000
heap default
page read and write
clean
370000
heap private
page read and write
clean
73234000
unkown image
page readonly
clean
21A4000
heap private
page read and write
clean
3260000
unkown
page read and write
clean
1C0000
unkown
page execute and read and write
clean
380000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
1C0000
unkown
page execute and read and write
clean
401000
unkown image
page execute read
clean
F3F4000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
407000
unkown image
page readonly
clean
190000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
401000
unkown image
page execute read
clean
7EFB0000
unkown image
page readonly
clean
374000
heap private
page read and write
clean
400000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
F3F1000
unkown
page read and write
clean
28A0000
unkown
page read and write
clean
409000
unkown image
page write copy
clean
7EFC2000
unkown image
page readonly
clean
409000
unkown image
page write copy
clean
690000
heap private
page read and write
clean
F460000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
407000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
1D5000
unkown
page execute and read and write
clean
73231000
unkown image
page execute read
clean
409000
unkown image
page write copy
clean
7EFD0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
F3F7000
unkown
page read and write
clean
1A0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
190000
unkown image
page readonly
clean
400000
unkown image
page readonly
clean
F3F7000
unkown
page read and write
clean
F400000
unkown
page read and write
clean
1D8000
unkown
page execute and read and write
clean
400000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
333A000
unkown
page read and write
clean
1A0000
unkown image
page readonly
clean
409000
unkown image
page write copy
clean
1D5000
unkown
page execute and read and write
clean
F300000
unkown
page read and write
clean
B9E000
stack
page read and write
clean
333D000
unkown
page read and write
clean
F300000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
401000
unkown image
page execute read
clean
400000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
F460000
unkown
page read and write
clean
F400000
unkown
page read and write
clean
F3E0000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
409000
unkown image
page write copy
clean
1D8000
unkown
page execute and read and write
clean
7EFC2000
unkown image
page readonly
clean
401000
unkown image
page execute read
clean
F460000
unkown
page read and write
clean
F3F4000
unkown
page read and write
clean
4E4000
heap default
page read and write
clean
400000
unkown image
page readonly
clean
28A0000
unkown
page read and write
clean
F2F0000
unkown
page read and write
clean
F3F7000
unkown
page read and write
clean
1D5000
unkown
page execute and read and write
clean
F2F0000
unkown
page read and write
clean
1D8000
unkown
page execute and read and write
clean
7EFE0000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
1A0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
409000
unkown image
page write copy
clean
7EFD0000
unkown image
page readonly
clean
407000
unkown image
page readonly
clean
333D000
unkown
page read and write
clean
8B000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
42D000
unkown image
page readonly
clean
70F000
stack
page read and write
clean
7EFD0000
unkown image
page readonly
clean
28A0000
unkown
page read and write
clean
F3F1000
unkown
page read and write
clean
250000
heap default
page read and write
clean
21A0000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
333A000
unkown
page read and write
clean
1A0000
unkown image
page readonly
clean
20000
unkown
page read and write
clean
333D000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
401000
unkown image
page execute read
clean
400000
unkown image
page readonly
clean
42D000
unkown image
page readonly
clean
190000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
1E8000
heap default
page read and write
clean
F400000
unkown
page read and write
clean
1A0000
unkown image
page readonly
clean
73230000
unkown image
page readonly
clean
1E6000
heap default
page read and write
clean
401000
unkown image
page execute read
clean
1A7000
heap default
page read and write
clean
42D000
unkown image
page readonly
clean
42D000
unkown image
page readonly
clean
1C0000
unkown
page execute and read and write
clean
F3E0000
unkown
page read and write
clean
190000
unkown image
page readonly
clean
3260000
unkown
page read and write
clean
33F0000
heap private
page read and write
clean
EC0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
1C0000
unkown
page execute and read and write
clean
7EFD0000
unkown image
page readonly
clean
F3F4000
unkown
page read and write
clean
407000
unkown image
page readonly
clean
F400000
unkown
page read and write
clean
18B000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
F3F7000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
7EFC0000
unkown image
page readonly
clean
42D000
unkown image
page readonly
clean
3220000
heap private
page read and write
clean
1D5000
unkown
page execute and read and write
clean
7EFB0000
unkown image
page readonly
clean
333A000
unkown
page read and write
clean
1C1000
unkown
page execute read
clean
1D5000
unkown
page execute and read and write
clean
7EFB0000
unkown image
page readonly
clean
240000
unkown image
page read and write
clean
7EFC2000
unkown image
page readonly
clean
There are 478 hidden memdumps, click here to show them.