IOC Report

loading gif

Files

File Path
Type
Category
Malicious
payment8642156.xlsb
Microsoft Excel 2007+
initial sample
malicious
C:\ProgramData\XgQXeAWeoOU.rtf
HTML document, ASCII text, with very long lines, with CRLF line terminators
dropped
malicious
C:\Users\user\Desktop\~$payment8642156.xlsb
data
dropped
malicious
C:\ProgramData\pXJSNz.txt
ASCII text, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\89313E5E-CC0C-4CD1-B945-313065E02B9E
XML 1.0 document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\274B0EB1.png
PNG image data, 288 x 44, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\55F344FE.png
PNG image data, 237 x 336, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\7A5B4E7.tmp
Microsoft Excel 2007+
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\Q2W5VWUFL5VCMQ7JQPETG3CCTYX72Z4R25PDG[1].txt
ASCII text, with no line terminators
dropped
clean
\Device\ConDrv
ASCII text, with CRLF, CR line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\Q2W5VWUFL5VCMQ7JQPETG3CCTYX72Z4R25PDG[1].txt
ASCII text, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\32440B49.png
PNG image data, 288 x 44, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\C414A8B6.png
PNG image data, 237 x 336, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Temp\5E36.tmp
Microsoft Excel 2007+
dropped
clean
There are 4 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
"C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE" /automation -Embedding
malicious
C:\Windows\SysWOW64\wbem\WMIC.exe
wmic process call create "mshta C:\ProgramData\XgQXeAWeoOU.rtf"
malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /automation -Embedding
malicious
C:\Windows\System32\wbem\WMIC.exe
wmic process call create "mshta C:\ProgramData\XgQXeAWeoOU.rtf"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
clean
C:\Windows\System32\mshta.exe
mshta C:\ProgramData\XgQXeAWeoOU.rtf
clean

URLs

Name
IP
Malicious
https://api.diagnosticssdf.office.com
unknown
clean
https://login.microsoftonline.com/
unknown
clean
https://shell.suite.office.com:1443
unknown
clean
https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize
unknown
clean
https://autodiscover-s.outlook.com/
unknown
clean
https://roaming.edog.
unknown
clean
https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr
unknown
clean
https://cdn.entity.
unknown
clean
https://api.addins.omex.office.net/appinfo/query
unknown
clean
https://clients.config.office.net/user/v1.0/tenantassociationkey
unknown
clean
https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/
unknown
clean
https://powerlift.acompli.net
unknown
clean
https://rpsticket.partnerservices.getmicrosoftkey.com
unknown
clean
https://lookup.onenote.com/lookup/geolocation/v1
unknown
clean
https://cortana.ai
unknown
clean
https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
unknown
clean
https://cloudfiles.onenote.com/upload.aspx
unknown
clean
https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
unknown
clean
https://entitlement.diagnosticssdf.office.com
unknown
clean
https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy
unknown
clean
https://api.aadrm.com/
unknown
clean
https://ofcrecsvcapi-int.azurewebsites.net/
unknown
clean
https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies
unknown
clean
https://api.microsoftstream.com/api/
unknown
clean
https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive
unknown
clean
https://cr.office.com
unknown
clean
https://augloop.office.com;https://augloop-int.officeppe.com;https://augloop-dogfood.officeppe.com;h
unknown
clean
https://portal.office.com/account/?ref=ClientMeControl
unknown
clean
https://graph.ppe.windows.net
unknown
clean
https://res.getmicrosoftkey.com/api/redemptionevents
unknown
clean
https://powerlift-frontdesk.acompli.net
unknown
clean
https://tasks.office.com
unknown
clean
https://officeci.azurewebsites.net/api/
unknown
clean
https://sr.outlook.office.net/ws/speech/recognize/assistant/work
unknown
clean
https://store.office.cn/addinstemplate
unknown
clean
https://api.aadrm.com
unknown
clean
https://outlook.office.com/autosuggest/api/v1/init?cvid=
unknown
clean
https://globaldisco.crm.dynamics.com
unknown
clean
https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
unknown
clean
https://dev0-api.acompli.net/autodetect
unknown
clean
https://www.odwebp.svc.ms
unknown
clean
https://api.powerbi.com/v1.0/myorg/groups
unknown
clean
https://web.microsoftstream.com/video/
unknown
clean
https://api.addins.store.officeppe.com/addinstemplate
unknown
clean
https://graph.windows.net
unknown
clean
https://dataservice.o365filtering.com/
unknown
clean
https://officesetup.getmicrosoftkey.com
unknown
clean
https://analysis.windows.net/powerbi/api
unknown
clean
https://prod-global-autodetect.acompli.net/autodetect
unknown
clean
https://outlook.office365.com/autodiscover/autodiscover.json
unknown
clean
https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios
unknown
clean
https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
unknown
clean
https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json
unknown
clean
https://ncus.contentsync.
unknown
clean
https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false
unknown
clean
https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/
unknown
clean
http://weather.service.msn.com/data.aspx
unknown
clean
https://apis.live.net/v5.0/
unknown
clean
http://132.148.135.183:8080/Q2W5VWUFL5VCMQ7JQPETG3CCTYX72Z4R25PDG
132.148.135.183
clean
https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks
unknown
clean
https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios
unknown
clean
https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml
unknown
clean
https://management.azure.com
unknown
clean
https://outlook.office365.com
unknown
clean
https://wus2.contentsync.
unknown
clean
https://incidents.diagnostics.office.com
unknown
clean
https://clients.config.office.net/user/v1.0/ios
unknown
clean
https://insertmedia.bing.office.net/odc/insertmedia
unknown
clean
https://o365auditrealtimeingestion.manage.office.com
unknown
clean
https://outlook.office365.com/api/v1.0/me/Activities
unknown
clean
https://api.office.net
unknown
clean
https://incidents.diagnosticssdf.office.com
unknown
clean
https://asgsmsproxyapi.azurewebsites.net/
unknown
clean
https://clients.config.office.net/user/v1.0/android/policies
unknown
clean
https://entitlement.diagnostics.office.com
unknown
clean
https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json
unknown
clean
https://substrate.office.com/search/api/v2/init
unknown
clean
https://outlook.office.com/
unknown
clean
https://storage.live.com/clientlogs/uploadlocation
unknown
clean
https://outlook.office365.com/
unknown
clean
https://webshell.suite.office.com
unknown
clean
https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive
unknown
clean
https://substrate.office.com/search/api/v1/SearchHistory
unknown
clean
https://management.azure.com/
unknown
clean
https://login.windows.net/common/oauth2/authorize
unknown
clean
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile
unknown
clean
https://graph.windows.net/
unknown
clean
https://api.powerbi.com/beta/myorg/imports
unknown
clean
https://devnull.onenote.com
unknown
clean
https://ncus.pagecontentsync.
unknown
clean
https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json
unknown
clean
https://messaging.office.com/
unknown
clean
https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
unknown
clean
https://augloop.office.com/v2
unknown
clean
https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing
unknown
clean
https://skyapi.live.net/Activity/
unknown
clean
https://clients.config.office.net/user/v1.0/mac
unknown
clean
https://dataservice.o365filtering.com
unknown
clean
https://api.cortana.ai
unknown
clean
https://onedrive.live.com
unknown
clean
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://www.%s.comPA
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://servername/isapibackend.dll
unknown
clean
http://investor.msn.com/
unknown
clean
There are 101 hidden URLs, click here to show them.

IPs

IP
Domain
Country
Malicious
132.148.135.183
unknown
United States
clean

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\StartupItems
2c6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\StartupItems
3c6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\internet\WebServiceCache
RemoteClearDate
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--lcid=1033&syslcid=1033&uilcid=1033&build=16.0.4954&crev=3
Last
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\IOAV
LastBootTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--lcid=1033&syslcid=1033&uilcid=1033&build=16.0.4954&crev=3\0
FilePath
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--lcid=1033&syslcid=1033&uilcid=1033&build=16.0.4954&crev=3\0
StartDate
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--lcid=1033&syslcid=1033&uilcid=1033&build=16.0.4954&crev=3\0
EndDate
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--lcid=1033&syslcid=1033&uilcid=1033&build=16.0.4954&crev=3\0
Properties
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--lcid=1033&syslcid=1033&uilcid=1033&build=16.0.4954&crev=3\0
Url
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\internet\WebServiceCache
LastClean
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity
DisableWinHttpCertAuth
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity
DisableIsOwnerRegex
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity
DisableSessionAwareHttpClose
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity
DisableADALForExtendedApps
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity
DisableADALSetSilentAuth
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity
msoridDisableGuestCredProvider
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity
msoridDisableOstringReplace
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\DocumentRecovery\4CFC1
4CFC1
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00006109110000000000000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ExdCache\Excel8.0
MSForms
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ExdCache\Excel8.0
MSComctlLib
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\StartupItems
<v6
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00006109E60090400000000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ReviewCycle
OriginalAttachmentPath
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ReviewCycle
TemporaryAttachmentName
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00006109A10090400000000000F01FEC\Usage
OutlookMAPI2Intl_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00006109110000000000000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
en-US
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
en-US
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00006109110000000000000000F01FEC\Usage
EXCELFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Roaming
RoamingConfigurableSettings
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Roaming
RoamingLastSyncTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Roaming
RoamingLastWriteTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\IOAV
LastBootTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00006109E60090400000000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
0 .
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
MTTT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\2FB4F
2FB4F
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
j(.
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
OriginalAttachmentPath
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
TemporaryAttachmentName
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109A10090400100000000F01FEC\Usage
OutlookMAPI2Intl_1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
EXCELFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
There are 45 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
2308FC3C000
unkown
page read and write
clean
7DF5616B2000
unkown image
page readonly
clean
2308FC98000
unkown
page read and write
clean
6057F7B000
stack
page read and write
clean
3B2D000
unkown
page read and write
clean
3B29000
unkown
page read and write
clean
7FF54C53B000
unkown image
page readonly
clean
17A57302000
unkown
page read and write
clean
7FF5D82B1000
unkown image
page readonly
clean
2288DCC0000
unkown image
page readonly
clean
7F700000
unkown image
page readonly
clean
17A5724D000
unkown
page read and write
clean
7F802000
unkown image
page readonly
clean
1086000
unkown image
page readonly
clean
7FF5B27BA000
unkown image
page readonly
clean
7DF4EB200000
unkown image
page readonly
clean
14547460000
unkown image
page readonly
clean
7FF54C3CC000
unkown image
page readonly
clean
3FA0000
unkown image
page readonly
clean
7FF54C39A000
unkown image
page readonly
clean
7FF54C484000
unkown image
page readonly
clean
145472D0000
unkown image
page readonly
clean
2288DDA0000
unkown image
page readonly
clean
7FF5D7A55000
unkown image
page readonly
clean
20576650000
unkown image
page readonly
clean
7DF561520000
unkown image
page readonly
clean
7DF5ED340000
unkown image
page readonly
clean
7FF54C3F1000
unkown image
page readonly
clean
7FF54C42E000
unkown image
page readonly
clean
7FF5D808C000
unkown image
page readonly
clean
7FF54C2F3000
unkown image
page readonly
clean
23090A70000
heap private
page read and write
clean
2288DE77000
unkown
page read and write
clean
7FF54C3CF000
unkown image
page readonly
clean
7FF54BE50000
unkown image
page readonly
clean
7FF5D8152000
unkown image
page readonly
clean
7FF5D823D000
unkown image
page readonly
clean
7FF54C622000
unkown image
page readonly
clean
3B19000
heap private
page read and write
clean
7FF5D821E000
unkown image
page readonly
clean
7DF5ED340000
unkown image
page readonly
clean
2288F770000
heap private
page read and write
clean
17A57850000
unkown image
page readonly
clean
20576740000
unkown
page read and write
clean
7FF5D7F18000
unkown image
page readonly
clean
7FF54C40E000
unkown image
page readonly
clean
20576108000
unkown
page read and write
clean
7FF5D8239000
unkown image
page readonly
clean
307E000
unkown
page read and write
clean
2B79000
unkown image
page readonly
clean
7FF5B2861000
unkown image
page readonly
clean
8F310E000
stack
page read and write
clean
7FF5B27C4000
unkown image
page readonly
clean
7FF54C49C000
unkown image
page readonly
clean
A6C07FD000
stack
page read and write
clean
7FF54C59E000
unkown image
page readonly
clean
7DF5616A0000
unkown image
page readonly
clean
7FF5D7F1C000
unkown image
page readonly
clean
F10000
unkown image
page readonly
clean
2308FC64000
unkown
page read and write
clean
17A570F0000
unkown image
page read and write
clean
7DF5C78E2000
unkown image
page readonly
clean
3AAE000
stack
page read and write
clean
7DFEAF758000
unkown image
page readonly
clean
2308FC58000
unkown
page read and write
clean
35E0000
unkown image
page readonly
clean
2288DCA0000
unkown image
page read and write
clean
2308FC2C000
unkown
page read and write
clean
23090A77000
heap private
page read and write
clean
7FF5D8094000
unkown image
page readonly
clean
17A57110000
unkown image
page readonly
clean
14546D30000
unkown image
page readonly
clean
2288DE22000
unkown
page read and write
clean
348B000
unkown
page read and write
clean
7DF561512000
unkown image
page readonly
clean
7FF5D7F9F000
unkown image
page readonly
clean
14546F13000
unkown
page read and write
clean
2D73000
unkown image
page readonly
clean
2288F730000
heap private
page read and write
clean
2308FF70000
unkown
page read and write
clean
7F810000
unkown image
page readonly
clean
7FF54C3D7000
unkown image
page readonly
clean
2288DE7F000
heap default
page read and write
clean
2288DE92000
heap default
page read and write
clean
2308FC08000
unkown
page read and write
clean
543F000
stack
page read and write
clean
22D96FF000
stack
page read and write
clean
348D000
unkown
page read and write
clean
14546E00000
unkown
page read and write
clean
2CC5000
unkown image
page readonly
clean
7F820000
unkown image
page readonly
clean
2309078E000
unkown
page read and write
clean
7FF5B285A000
unkown image
page readonly
clean
7DF5C7900000
unkown image
page readonly
clean
22D927E000
stack
page read and write
clean
2308FC0C000
unkown
page read and write
clean
7FF54C48A000
unkown image
page readonly
clean
7FF54C3A0000
unkown image
page readonly
clean
2288DE28000
heap default
page read and write
clean
7FF5B2631000
unkown image
page readonly
clean
3E20000
unkown image
page readonly
clean
7FF5D8124000
unkown image
page readonly
clean
7FF5B275A000
unkown image
page readonly
clean
2288DD30000
unkown
page read and write
clean
7FF54C1F1000
unkown image
page readonly
clean
3AEF000
stack
page read and write
clean
2308FC38000
unkown
page read and write
clean
7F800000
unkown image
page readonly
clean
7FF54C584000
unkown image
page readonly
clean
308D000
unkown
page read and write
clean
7F820000
unkown image
page readonly
clean
348A000
unkown
page read and write
clean
2308FAFA000
unkown
page read and write
clean
7FF5D7F98000
unkown image
page readonly
clean
2288DCC0000
unkown image
page readonly
clean
2308FBEC000
unkown
page read and write
clean
60583FF000
stack
page read and write
clean
22D937C000
stack
page read and write
clean
7FF5D7F70000
unkown image
page readonly
clean
8F3777000
stack
page read and write
clean
23090A74000
heap private
page read and write
clean
2288DEA7000
heap default
page read and write
clean
7FF5D7954000
unkown image
page readonly
clean
7FF5B266E000
unkown image
page readonly
clean
2308FAE0000
unkown
page read and write
clean
2288DE96000
heap default
page read and write
clean
2308FBF0000
unkown
page read and write
clean
2308FC30000
unkown
page read and write
clean
7FF54C0F6000
unkown image
page readonly
clean
23090BD5000
unkown
page read and write
clean
20576802000
unkown
page read and write
clean
7FF54C39E000
unkown image
page readonly
clean
17A5723C000
unkown
page read and write
clean
54BF000
stack
page read and write
clean
7FF54C535000
unkown image
page readonly
clean
336E000
stack
page read and write
clean
14546D60000
heap default
page read and write
clean
7FF54C61A000
unkown image
page readonly
clean
7FF5B276A000
unkown image
page readonly
clean
7FF54C416000
unkown image
page readonly
clean
2B73000
unkown image
page readonly
clean
7DF45F570000
unkown image
page readonly
clean
22D947B000
stack
page read and write
clean
7FF54C281000
unkown image
page readonly
clean
7FF5B27ED000
unkown image
page readonly
clean
2308FC20000
unkown
page read and write
clean
2B6C000
unkown image
page readonly
clean
6057B0B000
unkown
page read and write
clean
20576052000
unkown
page read and write
clean
8F35FB000
stack
page read and write
clean
2288DCB0000
unkown image
page readonly
clean
3530000
unkown
page read and write
clean
230907B3000
unkown
page read and write
clean
2288DE9E000
heap default
page read and write
clean
7FF54C598000
unkown image
page readonly
clean
7FF54C51C000
unkown image
page readonly
clean
7FF54C55C000
unkown image
page readonly
clean
3B24000
unkown
page read and write
clean
7FF5D8214000
unkown image
page readonly
clean
2308FC60000
unkown
page read and write
clean
2288DE48000
unkown
page read and write
clean
23090BF2000
unkown
page read and write
clean
7FF5D7AC2000
unkown image
page readonly
clean
7FF5D80FA000
unkown image
page readonly
clean
7FF5B2330000
unkown image
page readonly
clean
7FF54C51A000
unkown image
page readonly
clean
2288E300000
unkown image
page readonly
clean
20576084000
unkown
page read and write
clean
7DF5C78F0000
unkown image
page readonly
clean
7FF5B275C000
unkown image
page readonly
clean
308A000
unkown
page read and write
clean
8F318E000
stack
page read and write
clean
7FF5D7E9D000
unkown image
page readonly
clean
7FF5D8253000
unkown image
page readonly
clean
2308FBE8000
unkown
page read and write
clean
7FF5B266B000
unkown image
page readonly
clean
22D8FBE000
stack
page read and write
clean
14546D90000
unkown
page read and write
clean
7FF54C3AB000
unkown image
page readonly
clean
14546E70000
unkown
page read and write
clean
2288DE51000
unkown
page read and write
clean
2308FC41000
unkown
page read and write
clean
2C53000
unkown image
page readonly
clean
7FF5D82A4000
unkown image
page readonly
clean
3430000
heap default
page read and write
clean
7FF5B2090000
unkown image
page readonly
clean
3B13000
heap private
page read and write
clean
8F397E000
stack
page read and write
clean
2288DD80000
unkown
page read and write
clean
7FF5D81BA000
unkown image
page readonly
clean
7FF54C494000
unkown image
page readonly
clean
20575FE0000
heap default
page read and write
clean
7F812000
unkown image
page readonly
clean
20576000000
unkown
page read and write
clean
2288DD9E000
heap private
page read and write
clean
7FF54C408000
unkown image
page readonly
clean
EB0000
unkown image
page readonly
clean
7DF5ED330000
unkown image
page readonly
clean
EA0000
unkown image
page read and write
clean
3618000
heap private
page read and write
clean
23090BDB000
unkown
page read and write
clean
7FF54C3FF000
unkown image
page readonly
clean
2288DDF9000
unkown
page read and write
clean
2308FC70000
unkown
page read and write
clean
3B26000
unkown
page read and write
clean
7FF5D80C3000
unkown image
page readonly
clean
20576063000
unkown
page read and write
clean
7FF54C117000
unkown image
page readonly
clean
14546CF0000
unkown image
page read and write
clean
7FF5D7A66000
unkown image
page readonly
clean
EB0000
unkown image
page readonly
clean
7FF54C38C000
unkown image
page readonly
clean
7FF5D815C000
unkown image
page readonly
clean
2288DE29000
unkown
page read and write
clean
22D8F3B000
unkown
page read and write
clean
7FF54C547000
unkown image
page readonly
clean
14547450000
unkown image
page readonly
clean
7DF5616C0000
unkown image
page readonly
clean
35DF000
stack
page read and write
clean
7FF54C048000
unkown image
page readonly
clean
7FF5D8160000
unkown image
page readonly
clean
3B10000
heap private
page read and write
clean
7FF5D8097000
unkown image
page readonly
clean
7FF54C419000
unkown image
page readonly
clean
7FF5D81D7000
unkown image
page readonly
clean
2CCF000
unkown image
page readonly
clean
2288DE87000
heap default
page read and write
clean
8F387E000
stack
page read and write
clean
2288DE48000
heap default
page read and write
clean
14546E0B000
unkown
page read and write
clean
2057604B000
unkown
page read and write
clean
A6BFBFF000
stack
page read and write
clean
7FF5B26BD000
unkown image
page readonly
clean
7DF5ED330000
unkown image
page readonly
clean
7FF5D8236000
unkown image
page readonly
clean
7DF5616A2000
unkown image
page readonly
clean
2057604E000
unkown
page read and write
clean
7F812000
unkown image
page readonly
clean
A6BFEF7000
unkown
page read and write
clean
7FF5D8228000
unkown image
page readonly
clean
7FF54C52A000
unkown image
page readonly
clean
7FF5D7D0D000
unkown image
page readonly
clean
7FF5D7CF6000
unkown image
page readonly
clean
3496000
unkown
page read and write
clean
7FF5D7F7B000
unkown image
page readonly
clean
2308FBF8000
unkown
page read and write
clean
7FF5D7B77000
unkown image
page readonly
clean
3B17000
heap private
page read and write
clean
7DF5616B2000
unkown image
page readonly
clean
14546E3C000
unkown
page read and write
clean
17A57224000
unkown
page read and write
clean
7FF54BB24000
unkown image
page readonly
clean
17A57255000
unkown
page read and write
clean
20575F70000
unkown image
page read and write
clean
7FF5D7F2C000
unkown image
page readonly
clean
7FF5D7E1A000
unkown image
page readonly
clean
3B12000
heap private
page read and write
clean
7F802000
unkown image
page readonly
clean
7FF54C492000
unkown image
page readonly
clean
230908D0000
unkown image
page read and write
clean
7FF5D7F86000
unkown image
page readonly
clean
34A2000
unkown
page read and write
clean
3A60000
heap private
page read and write
clean
20575FB0000
unkown image
page readonly
clean
7FF5D7974000
unkown image
page readonly
clean
32F0000
unkown
page read and write
clean
23090770000
unkown
page read and write
clean
7FF5D7F24000
unkown image
page readonly
clean
23090CD0000
unkown image
page readonly
clean
2308FC10000
unkown
page read and write
clean
53FE000
stack
page read and write
clean
605807B000
stack
page read and write
clean
14546E13000
unkown
page read and write
clean
7FF54C105000
unkown image
page readonly
clean
17A57300000
unkown
page read and write
clean
7FF5D822E000
unkown image
page readonly
clean
7FF5B2613000
unkown image
page readonly
clean
7FF54C3A5000
unkown image
page readonly
clean
7FF5B27E9000
unkown image
page readonly
clean
2288DE8E000
heap default
page read and write
clean
7FF54C41D000
unkown image
page readonly
clean
A6C06FF000
stack
page read and write
clean
2C95000
unkown image
page readonly
clean
7DF561510000
unkown image
page readonly
clean
2288DF80000
unkown image
page readonly
clean
7FF54C3E4000
unkown image
page readonly
clean
7DF561530000
unkown image
page readonly
clean
7FF5D80C8000
unkown image
page readonly
clean
7FF54C52E000
unkown image
page readonly
clean
2288DE22000
heap default
page read and write
clean
2288DDEA000
unkown
page read and write
clean
60581F7000
stack
page read and write
clean
17A57130000
unkown image
page readonly
clean
22D95F7000
stack
page read and write
clean
17A57200000
unkown
page read and write
clean
20575FC0000
unkown image
page readonly
clean
14547602000
unkown
page read and write
clean
2288DE7F000
unkown
page read and write
clean
3490000
unkown
page read and write
clean
7FF5D81C0000
unkown image
page readonly
clean
7FF54C621000
unkown image
page readonly
clean
7DF5C78F2000
unkown image
page readonly
clean
2D45000
unkown image
page readonly
clean
17A57A02000
unkown
page read and write
clean
17A576D0000
unkown image
page readonly
clean
7FF54C0F0000
unkown image
page readonly
clean
14546F02000
unkown
page read and write
clean
7FF5D812C000
unkown image
page readonly
clean
17A57170000
unkown image
page readonly
clean
2288DEA9000
heap default
page read and write
clean
20576063000
unkown
page read and write
clean
7DF561510000
unkown image
page readonly
clean
2308FC14000
unkown
page read and write
clean
2288DE50000
heap default
page read and write
clean
F20000
unkown image
page readonly
clean
2309078D000
unkown
page read and write
clean
2288DE7B000
heap default
page read and write
clean
7FF5B2345000
unkown image
page readonly
clean
342E000
stack
page read and write
clean
2308FC8C000
unkown
page read and write
clean
2308FC1C000
unkown
page read and write
clean
2308FC04000
unkown
page read and write
clean
3610000
heap private
page read and write
clean
7FF5B26C3000
unkown image
page readonly
clean
7FF54C614000
unkown image
page readonly
clean
7FF5D79A1000
unkown image
page readonly
clean
7FF54C42B000
unkown image
page readonly
clean
2D54000
unkown image
page readonly
clean
2057604F000
unkown
page read and write
clean
2308FC6C000
unkown
page read and write
clean
7FF5D8057000
unkown image
page readonly
clean
14546D00000
heap private
page read and write
clean
2288DE3D000
heap default
page read and write
clean
7FF54BF75000
unkown image
page readonly
clean
7FF5B25C1000
unkown image
page readonly
clean
7FF54C29B000
unkown image
page readonly
clean
2308FE20000
unkown
page read and write
clean
60582FE000
stack
page read and write
clean
2308FC00000
unkown
page read and write
clean
3B2A000
unkown
page read and write
clean
2288E180000
unkown image
page readonly
clean
7FF5B2854000
unkown image
page readonly
clean
22D94FE000
stack
page read and write
clean
7FF54C55F000
unkown image
page readonly
clean
14546D10000
unkown image
page readonly
clean
2308FAE4000
unkown
page read and write
clean
20575FF0000
unkown image
page readonly
clean
2CCD000
unkown image
page readonly
clean
17A57140000
unkown image
page readonly
clean
2288DDB0000
heap default
page read and write
clean
7DF5ED332000
unkown image
page readonly
clean
7DF5C78F2000
unkown image
page readonly
clean
7FF5B27CF000
unkown image
page readonly
clean
7FF5B2787000
unkown image
page readonly
clean
6057E7D000
stack
page read and write
clean
7DF5C78E0000
unkown image
page readonly
clean
2CAB000
unkown image
page readonly
clean
2288DEAB000
heap default
page read and write
clean
7FF5D7E9A000
unkown image
page readonly
clean
2309078A000
unkown
page read and write
clean
2308FF20000
unkown image
page write copy
clean
7DF5616A2000
unkown image
page readonly
clean
7DF5616C0000
unkown image
page readonly
clean
7FF5B27DE000
unkown image
page readonly
clean
3B20000
unkown
page read and write
clean
7FF54C3EA000
unkown image
page readonly
clean
230907A2000
unkown
page read and write
clean
7FF5B27E6000
unkown image
page readonly
clean
17A57280000
unkown
page read and write
clean
7FF5D81AC000
unkown image
page readonly
clean
2288DD90000
heap private
page read and write
clean
7DF5C78F0000
unkown image
page readonly
clean
3550000
unkown
page read and write
clean
2CA3000
unkown image
page readonly
clean
2308FC34000
unkown
page read and write
clean
2C7C000
unkown image
page readonly
clean
20576100000
unkown
page read and write
clean
7DF5C7900000
unkown image
page readonly
clean
7FF5D794A000
unkown image
page readonly
clean
2CB0000
unkown image
page readonly
clean
2288DD10000
unkown
page read and write
clean
7FF5B279F000
unkown image
page readonly
clean
3090000
unkown
page read and write
clean
7DF5ED342000
unkown image
page readonly
clean
3C20000
unkown image
page readonly
clean
205764D0000
unkown image
page readonly
clean
14546E9F000
unkown
page read and write
clean
7FF54C47D000
unkown image
page readonly
clean
2288DEA5000
heap default
page read and write
clean
7FF54C5A9000
unkown image
page readonly
clean
7FF5D82B2000
unkown image
page readonly
clean
7FF5B276E000
unkown image
page readonly
clean
7FF5B2770000
unkown image
page readonly
clean
7FF5B277B000
unkown image
page readonly
clean
7FF54C3D3000
unkown image
page readonly
clean
7FF54BCB4000
unkown image
page readonly
clean
A6C05FE000
stack
page read and write
clean
2CD3000
unkown image
page readonly
clean
8F367E000
stack
page read and write
clean
2288F774000
heap private
page read and write
clean
2C5C000
unkown image
page readonly
clean
7FF5D7F2E000
unkown image
page readonly
clean
2309078E000
unkown
page read and write
clean
2CC7000
unkown image
page readonly
clean
7FF54C243000
unkown image
page readonly
clean
7FF5D81AA000
unkown image
page readonly
clean
7FF5B2862000
unkown image
page readonly
clean
7FF5D7980000
unkown image
page readonly
clean
7FF54C38A000
unkown image
page readonly
clean
2288DEA3000
heap default
page read and write
clean
A6C04FF000
stack
page read and write
clean
20575F80000
heap private
page read and write
clean
A6C08FF000
stack
page read and write
clean
A6C02FE000
stack
page read and write
clean
3437000
heap default
page read and write
clean
2C6C000
unkown image
page readonly
clean
7DF561530000
unkown image
page readonly
clean
7FF54BF66000
unkown image
page readonly
clean
2288F794000
heap private
page read and write
clean
7FF54C3F4000
unkown image
page readonly
clean
2057603C000
unkown
page read and write
clean
7DF5616B0000
unkown image
page readonly
clean
20576113000
unkown
page read and write
clean
7FF5B26D4000
unkown image
page readonly
clean
7DF5616A0000
unkown image
page readonly
clean
7DF561512000
unkown image
page readonly
clean
23090A7A000
heap private
page read and write
clean
7DF5616B0000
unkown image
page readonly
clean
2288DDB9000
heap default
page read and write
clean
7FF5D7DF3000
unkown image
page readonly
clean
7FF5B27B4000
unkown image
page readonly
clean
3487000
unkown
page read and write
clean
7DF561520000
unkown image
page readonly
clean
7FF54C3B7000
unkown image
page readonly
clean
23090779000
unkown
page read and write
clean
17A57308000
unkown
page read and write
clean
7FF5B2651000
unkown image
page readonly
clean
7FF5B26DC000
unkown image
page readonly
clean
20576070000
unkown
page read and write
clean
7FF54C567000
unkown image
page readonly
clean
14546E29000
unkown
page read and write
clean
3B17000
heap private
page read and write
clean
7FF5D8088000
unkown image
page readonly
clean
7FF54BF60000
unkown image
page readonly
clean
343F000
unkown
page read and write
clean
2308FC9C000
unkown
page read and write
clean
7FF54C574000
unkown image
page readonly
clean
17A57313000
unkown
page read and write
clean
20576096000
unkown
page read and write
clean
7FF54C5A6000
unkown image
page readonly
clean
7FF5D82AA000
unkown image
page readonly
clean
23090A80000
unkown
page read and write
clean
7FF5D7A1B000
unkown image
page readonly
clean
2288DD95000
heap private
page read and write
clean
17A57190000
unkown
page read and write
clean
2288DE50000
unkown
page read and write
clean
2308FC84000
unkown
page read and write
clean
2CDA000
unkown image
page readonly
clean
23090780000
unkown
page read and write
clean
7DF5ED342000
unkown image
page readonly
clean
2288F790000
heap private
page read and write
clean
17A57270000
unkown
page read and write
clean
2C8D000
unkown image
page readonly
clean
17A57213000
unkown
page read and write
clean
7FF5B27A7000
unkown image
page readonly
clean
17A57202000
unkown
page read and write
clean
7FF5D8113000
unkown image
page readonly
clean
2288DE87000
unkown
page read and write
clean
20576102000
unkown
page read and write
clean
14546D10000
unkown image
page readonly
clean
23090BD0000
unkown
page read and write
clean
17A57100000
heap private
page read and write
clean
547E000
stack
page read and write
clean
A6C03FE000
stack
page read and write
clean
2308FCE0000
unkown image
page readonly
clean
7FF5D7DEF000
unkown image
page readonly
clean
60580FE000
stack
page read and write
clean
33AF000
stack
page read and write
clean
2CF2000
unkown image
page readonly
clean
2D68000
unkown image
page readonly
clean
17A57249000
unkown
page read and write
clean
7FF5B2336000
unkown image
page readonly
clean
7FF5D8204000
unkown image
page readonly
clean
7FF54C381000
unkown image
page readonly
clean
2CB9000
unkown image
page readonly
clean
2308FC7C000
unkown
page read and write
clean
20575F90000
unkown image
page readonly
clean
2308FBFC000
unkown
page read and write
clean
34A4000
unkown
page read and write
clean
20575F90000
unkown image
page readonly
clean
2308FC18000
unkown
page read and write
clean
2D62000
unkown image
page readonly
clean
23090A40000
unkown
page read and write
clean
17A57110000
unkown image
page readonly
clean
7FF5D81EF000
unkown image
page readonly
clean
7FF5D810D000
unkown image
page readonly
clean
7FF54C30C000
unkown image
page readonly
clean
14546D40000
unkown image
page readonly
clean
2308FDB0000
unkown
page read and write
clean
230907CE000
unkown
page read and write
clean
14546D70000
unkown image
page readonly
clean
7FF5D8106000
unkown image
page readonly
clean
6057B8E000
stack
page read and write
clean
23090783000
unkown
page read and write
clean
7FF5D7E40000
unkown image
page readonly
clean
7F810000
unkown image
page readonly
clean
20576055000
unkown
page read and write
clean
307A000
unkown
page read and write
clean
7FF5B279C000
unkown image
page readonly
clean
2308FDD0000
unkown image
page readonly
clean
2D73000
unkown image
page readonly
clean
7FF54C411000
unkown image
page readonly
clean
2288E310000
unkown image
page readonly
clean
359E000
stack
page read and write
clean
2308FC28000
unkown
page read and write
clean
2C9C000
unkown image
page readonly
clean
20576046000
unkown
page read and write
clean
7FF5D8175000
unkown image
page readonly
clean
2308FC88000
unkown
page read and write
clean
2308FC50000
unkown
page read and write
clean
7FF54C58F000
unkown image
page readonly
clean
205762D0000
unkown image
page readonly
clean
3B2B000
unkown
page read and write
clean
20576013000
unkown
page read and write
clean
7FF5D8082000
unkown image
page readonly
clean
7FF54C2ED000
unkown image
page readonly
clean
7DF5ED350000
unkown image
page readonly
clean
2288F740000
unkown
page read and write
clean
7FF5D81EC000
unkown image
page readonly
clean
2057608F000
unkown
page read and write
clean
2288DCE0000
unkown image
page readonly
clean
F0C000
unkown
page read and write
clean
7DF561522000
unkown image
page readonly
clean
7FF54C530000
unkown image
page readonly
clean
347D000
unkown
page read and write
clean
7FF54C2A7000
unkown image
page readonly
clean
2FEB000
unkown
page read and write
clean
3320000
heap default
page read and write
clean
2057602A000
unkown
page read and write
clean
34A1000
unkown
page read and write
clean
17A5728B000
unkown
page read and write
clean
7FF5B24E7000
unkown image
page readonly
clean
3475000
unkown
page read and write
clean
23090A72000
heap private
page read and write
clean
7FF5B2775000
unkown image
page readonly
clean
3442000
heap default
page read and write
clean
7DF5C78E0000
unkown image
page readonly
clean
2BA2000
unkown image
page readonly
clean
2288F720000
unkown
page read and write
clean
145470D0000
unkown image
page readonly
clean
2288DCF0000
unkown image
page readonly
clean
2308FC80000
unkown
page read and write
clean
7DF5ED332000
unkown image
page readonly
clean
7DF45F3E0000
unkown image
page readonly
clean
3B1A000
heap private
page read and write
clean
2CDF000
unkown image
page readonly
clean
22D97FE000
stack
page read and write
clean
2308FDC0000
unkown image
page readonly
clean
14546E9A000
unkown
page read and write
clean
2D41000
unkown image
page readonly
clean
7FF5D81BE000
unkown image
page readonly
clean
7FF54C57A000
unkown image
page readonly
clean
7FF54C483000
unkown image
page readonly
clean
7DF4C57B0000
unkown image
page readonly
clean
7FF5D81F7000
unkown image
page readonly
clean
7F800000
unkown image
page readonly
clean
17A574D0000
unkown image
page readonly
clean
7FF5D8090000
unkown image
page readonly
clean
17A57250000
unkown
page read and write
clean
7FF54C5AD000
unkown image
page readonly
clean
7FF5D8183000
unkown image
page readonly
clean
2288DDC6000
heap default
page read and write
clean
7DF5ED350000
unkown image
page readonly
clean
17A57160000
heap default
page read and write
clean
7FF54C304000
unkown image
page readonly
clean
7DF5C78E2000
unkown image
page readonly
clean
33EE000
stack
page read and write
clean
7FF5D81CB000
unkown image
page readonly
clean
7FF5B27D8000
unkown image
page readonly
clean
2308FAFD000
unkown
page read and write
clean
7FF5D820A000
unkown image
page readonly
clean
2288F79D000
heap private
page read and write
clean
2288DE3D000
unkown
page read and write
clean
7FF54C491000
unkown image
page readonly
clean
8F308B000
unkown
page read and write
clean
2288DDE5000
heap default
page read and write
clean
7FF5D81C5000
unkown image
page readonly
clean
7DF561522000
unkown image
page readonly
clean
There are 578 hidden memdumps, click here to show them.