Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
Invoice.xlsm
|
Microsoft Excel 2007+
|
initial sample
|
||
C:\Users\user\Desktop\~$Invoice.xlsm
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\suspendedpage[1].htm
|
HTML document, ASCII text, with very long lines
|
downloaded
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\5EEDDA76.png
|
PNG image data, 1714 x 241, 8-bit colormap, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\3F61.tmp
|
Composite Document File V2 Document, Cannot read section info
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\~DFF5ECB97273E842F1.TMP
|
data
|
dropped
|
||
C:\Users\user\besta.ocx
|
HTML document, ASCII text, with very long lines
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /automation -Embedding
|
||
C:\Windows\SysWOW64\rundll32.exe
|
C:\Windows\SysWow64\rundll32.exe ..\besta.ocx,44532.2932256944
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://crackedshop.org/9/q080U0ARYYL/
|
94.102.59.39
|
||
https://ascarya.digital/wp-content/ZH4rirU
|
unknown
|
||
https://ascarya.digital/wp-content/ZH4rirU/
|
unknown
|
||
http://www.windows.com/pctv.
|
unknown
|
||
http://investor.msn.com
|
unknown
|
||
http://www.msnbc.com/news/ticker.txt
|
unknown
|
||
http://crackedshop.org/cgi-sys/suspendedpage.cgi
|
94.102.59.39
|
||
http://purl.or
|
unknown
|
||
http://crackedshop.org/cgi-sys/suspendedpage.cgi5
|
unknown
|
||
https://ascarya.digital/wp-con
|
unknown
|
||
https://ascarya.digit
|
unknown
|
||
https://ascarya.digital/wp-conte
|
unknown
|
||
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
|
unknown
|
||
http://www.hotmail.com/oe
|
unknown
|
||
http://schemas.open
|
unknown
|
||
https://ascarya.digital/wp-content%https://ascarya.digital/wp-content/ZH&https://ascarya.digital/wp-
|
unknown
|
||
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
|
unknown
|
||
http://www.icra.org/vocabulary/.
|
unknown
|
||
http://schemas.openformatrg/package/2006/r
|
unknown
|
||
https://ascarya.digital/w
|
unknown
|
||
http://investor.msn.com/
|
unknown
|
||
https://ascarya.digital
|
unknown
|
||
https://ascarya.digital/
|
unknown
|
||
https://ascarya.dig
|
unknown
|
||
https://ascarya.digital/wp-c
|
unknown
|
There are 15 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
crackedshop.org
|
94.102.59.39
|
||
ascarya.digital
|
67.207.81.73
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
94.102.59.39
|
crackedshop.org
|
Netherlands
|
||
67.207.81.73
|
ascarya.digital
|
United States
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
|
/|%
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
|
MTTT
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
|
ReviewToken
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\2CAFC
|
2CAFC
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
|
VBAFiles
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
|
}e%
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
|
LastPurgeTime
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
|
Max Display
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Max Display
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 1
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 2
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 3
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 4
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 5
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 6
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 7
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 8
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 9
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 10
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 11
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 12
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 13
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 14
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 15
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 16
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 17
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 18
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 19
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 20
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\7472E
|
7472E
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
|
Max Display
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Max Display
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 1
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 2
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 3
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 4
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 5
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 6
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 7
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 8
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 9
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 10
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 11
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 12
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 13
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 14
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 15
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 16
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 17
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 18
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 19
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 20
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\74E6E
|
74E6E
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common
|
QMSessionCount
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\General
|
LastAutoSavePurgeTime
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
|
1033
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
|
1033
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
|
EXCELFiles
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
|
ProductFiles
|
||
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
|
SavedLegacySettings
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
|
ProductFiles
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
|
ProductFiles
|
There are 52 hidden registries, click here to show them.
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
7EFC0000
|
unkown image
|
page readonly
|
||
3888000
|
unkown
|
page read and write
|
||
4AE2000
|
stack
|
page read and write
|
||
38B0000
|
unkown
|
page read and write
|
||
6C28000
|
unkown
|
page read and write
|
||
5AA9000
|
unkown
|
page read and write
|
||
35D0000
|
unkown
|
page read and write
|
||
6E854000
|
unkown image
|
page read and write
|
||
58B0000
|
stack
|
page read and write
|
||
31E0000
|
unkown
|
page read and write
|
||
377000
|
unkown
|
page read and write
|
||
537000
|
heap default
|
page read and write
|
||
346000
|
unkown
|
page read and write
|
||
6C44000
|
unkown
|
page read and write
|
||
6E80000
|
heap private
|
page read and write
|
||
44FF000
|
unkown
|
page read and write
|
||
7FFFFFD0000
|
unkown image
|
page readonly
|
||
5A45000
|
unkown
|
page read and write
|
||
C0000
|
unkown image
|
page readonly
|
||
58A6000
|
unkown
|
page read and write
|
||
584A000
|
unkown
|
page read and write
|
||
3160000
|
unkown
|
page read and write
|
||
718C000
|
unkown
|
page read and write
|
||
5510000
|
unkown
|
page read and write
|
||
7502000
|
unkown
|
page read and write
|
||
7110000
|
unkown
|
page read and write
|
||
5850000
|
unkown
|
page read and write
|
||
1C56000
|
unkown
|
page read and write
|
||
3210000
|
unkown image
|
page read and write
|
||
3810000
|
unkown
|
page read and write
|
||
1D43000
|
unkown
|
page read and write
|
||
4DF0000
|
stack
|
page read and write
|
||
30000
|
unkown image
|
page read and write
|
||
54C8000
|
unkown
|
page read and write
|
||
4AE2000
|
stack
|
page read and write
|
||
1D3E000
|
unkown
|
page read and write
|
||
5AD1000
|
unkown
|
page read and write
|
||
22A000
|
unkown
|
page read and write
|
||
4E20000
|
stack
|
page read and write
|
||
59B0000
|
unkown
|
page read and write
|
||
5A7F000
|
unkown
|
page read and write
|
||
4F66000
|
unkown
|
page read and write
|
||
5530000
|
unkown
|
page read and write
|
||
23B0000
|
heap private
|
page read and write
|
||
5510000
|
unkown
|
page read and write
|
||
5A9D000
|
unkown
|
page read and write
|
||
259B000
|
heap private
|
page read and write
|
||
1D74000
|
unkown
|
page read and write
|
||
7110000
|
unkown
|
page read and write
|
||
7FFFFFD0000
|
unkown image
|
page readonly
|
||
155000
|
unkown
|
page read and write
|
||
7800000
|
heap private
|
page read and write
|
||
1D65000
|
unkown
|
page read and write
|
||
31F0000
|
unkown
|
page read and write
|
||
5510000
|
unkown
|
page read and write
|
||
38C0000
|
unkown
|
page read and write
|
||
530000
|
heap default
|
page read and write
|
||
2DB000
|
heap default
|
page read and write
|
||
38D0000
|
unkown
|
page read and write
|
||
90000
|
unkown
|
page read and write
|
||
860000
|
unkown
|
page read and write
|
||
16E0000
|
unkown image
|
page readonly
|
||
2E0000
|
unkown
|
page read and write
|
||
5864000
|
unkown
|
page read and write
|
||
710000
|
unkown image
|
page readonly
|
||
7110000
|
unkown
|
page read and write
|
||
1DE000
|
heap default
|
page read and write
|
||
1DAE000
|
unkown
|
page read and write
|
||
3AD0000
|
unkown
|
page read and write
|
||
554000
|
heap default
|
page read and write
|
||
4E70000
|
unkown
|
page read and write
|
||
5AC2000
|
unkown
|
page read and write
|
||
D0000
|
heap private
|
page read and write
|
||
EC0000
|
unkown
|
page read and write
|
||
5510000
|
unkown
|
page read and write
|
||
13C000
|
unkown
|
page read and write
|
||
5BB0000
|
unkown
|
page read and write
|
||
3260000
|
unkown
|
page read and write
|
||
7FFFFFC2000
|
unkown image
|
page readonly
|
||
43D1000
|
stack
|
page read and write
|
||
4F0000
|
heap private
|
page read and write
|
||
3200000
|
unkown image
|
page readonly
|
||
2064000
|
unkown
|
page read and write
|
||
360000
|
unkown
|
page read and write
|
||
6E50000
|
heap private
|
page read and write
|
||
7410000
|
heap private
|
page read and write
|
||
59B8000
|
unkown
|
page read and write
|
||
7FB0000
|
unkown
|
page read and write
|
||
7130000
|
unkown
|
page read and write
|
||
554F000
|
unkown
|
page read and write
|
||
A9F000
|
stack
|
page read and write
|
||
7175000
|
unkown
|
page read and write
|
||
A0000
|
unkown image
|
page read and write
|
||
4EE000
|
stack
|
page read and write
|
||
7110000
|
unkown
|
page read and write
|
||
3870000
|
unkown
|
page read and write
|
||
6E84B000
|
unkown image
|
page read and write
|
||
2560000
|
unkown
|
page read and write
|
||
3880000
|
unkown
|
page read and write
|
||
43AC000
|
stack
|
page read and write
|
||
6BB0000
|
unkown
|
page read and write
|
||
6F90000
|
unkown
|
page read and write
|
||
4BD0000
|
stack
|
page read and write
|
||
5A7F000
|
unkown
|
page read and write
|
||
556A000
|
unkown
|
page read and write
|
||
31B0000
|
unkown
|
page read and write
|
||
6C70000
|
unkown image
|
page read and write
|
||
5510000
|
unkown
|
page read and write
|
||
7FFFFFC0000
|
unkown image
|
page readonly
|
||
BBF000
|
stack
|
page read and write
|
||
3850000
|
unkown
|
page read and write
|
||
20CB000
|
heap private
|
page read and write
|
||
90000
|
unkown image
|
page readonly
|
||
5BB0000
|
unkown
|
page read and write
|
||
370000
|
heap default
|
page read and write
|
||
90F000
|
stack
|
page read and write
|
||
2110000
|
unkown image
|
page readonly
|
||
80000
|
unkown
|
page read and write
|
||
7FFFFFD0000
|
unkown image
|
page readonly
|
||
490000
|
unkown image
|
page readonly
|
||
7175000
|
unkown
|
page read and write
|
||
2040000
|
unkown
|
page read and write
|
||
4B90000
|
stack
|
page read and write
|
||
46DE000
|
stack
|
page read and write
|
||
31C0000
|
unkown
|
page read and write
|
||
10000
|
unkown image
|
page read and write
|
||
4E46000
|
stack
|
page read and write
|
||
410000
|
unkown
|
page read and write
|
||
7FFFFFD0000
|
unkown image
|
page readonly
|
||
B37000
|
unkown image
|
page readonly
|
||
3243000
|
unkown
|
page read and write
|
||
36E000
|
heap default
|
page read and write
|
||
B4000
|
heap private
|
page read and write
|
||
75C0000
|
heap private
|
page read and write
|
||
7FFFFFC2000
|
unkown image
|
page readonly
|
||
2095000
|
heap private
|
page read and write
|
||
6C00000
|
unkown
|
page read and write
|
||
364000
|
unkown
|
page read and write
|
||
583E000
|
stack
|
page read and write
|
||
30C2000
|
heap private
|
page read and write
|
||
7F62000
|
unkown
|
page read and write
|
||
5070000
|
unkown image
|
page readonly
|
||
C0000
|
unkown image
|
page readonly
|
||
43B0000
|
stack
|
page read and write
|
||
5A9D000
|
unkown
|
page read and write
|
||
2598000
|
heap private
|
page read and write
|
||
4F4000
|
heap private
|
page read and write
|
||
2595000
|
heap private
|
page read and write
|
||
7FFFFFC0000
|
unkown image
|
page readonly
|
||
6CAE000
|
heap private
|
page read and write
|
||
7FFFFFC2000
|
unkown image
|
page readonly
|
||
45D0000
|
unkown
|
page read and write
|
||
7EFE0000
|
unkown image
|
page readonly
|
||
30000
|
unkown image
|
page readonly
|
||
290000
|
heap default
|
page read and write
|
||
2F0000
|
heap default
|
page read and write
|
||
2044000
|
unkown
|
page read and write
|
||
7EFD0000
|
unkown image
|
page readonly
|
||
4B0000
|
unkown
|
page read and write
|
||
349F000
|
stack
|
page read and write
|
||
7FFFFFC0000
|
unkown image
|
page readonly
|
||
46E0000
|
unkown image
|
page readonly
|
||
4FD0000
|
unkown
|
page read and write
|
||
3890000
|
heap private
|
page read and write
|
||
3050000
|
unkown
|
page read and write
|
||
7F25000
|
unkown
|
page read and write
|
||
6BB0000
|
unkown
|
page read and write
|
||
551C000
|
unkown
|
page read and write
|
||
2590000
|
heap private
|
page read and write
|
||
480000
|
unkown
|
page read and write
|
||
3AE0000
|
unkown
|
page read and write
|
||
5A89000
|
unkown
|
page read and write
|
||
7FFFFFC0000
|
unkown image
|
page readonly
|
||
7EFB0000
|
unkown image
|
page readonly
|
||
2594000
|
heap private
|
page read and write
|
||
6BC0000
|
unkown
|
page read and write
|
||
D30000
|
unkown
|
page read and write
|
||
2020000
|
unkown
|
page read and write
|
||
250000
|
unkown
|
page read and write
|
||
176000
|
unkown
|
page read and write
|
||
58A0000
|
unkown
|
page read and write
|
||
7158000
|
unkown
|
page read and write
|
||
1D33000
|
unkown
|
page read and write
|
||
5539000
|
unkown
|
page read and write
|
||
7EFE0000
|
unkown image
|
page readonly
|
||
7F62000
|
unkown
|
page read and write
|
||
82C0000
|
unkown
|
page read and write
|
||
58ED000
|
stack
|
page read and write
|
||
31D0000
|
unkown
|
page read and write
|
||
580000
|
unkown image
|
page readonly
|
||
7EFD0000
|
unkown image
|
page readonly
|
||
5850000
|
unkown
|
page read and write
|
||
43BD000
|
stack
|
page read and write
|
||
34A0000
|
unkown
|
page read and write
|
||
2CD000
|
heap default
|
page read and write
|
||
7158000
|
unkown
|
page read and write
|
||
315E000
|
stack
|
page read and write
|
||
4BB0000
|
stack
|
page read and write
|
||
3B50000
|
heap private
|
page read and write
|
||
2599000
|
heap private
|
page read and write
|
||
5550000
|
unkown
|
page read and write
|
||
5886000
|
unkown
|
page read and write
|
||
34B0000
|
unkown
|
page read and write
|
||
7110000
|
unkown
|
page read and write
|
||
3B1000
|
heap default
|
page read and write
|
||
5A08000
|
unkown
|
page read and write
|
||
2060000
|
unkown
|
page read and write
|
||
5A00000
|
unkown
|
page read and write
|
||
65300000
|
unkown image
|
page readonly
|
||
23F000
|
heap default
|
page read and write
|
||
4AE0000
|
stack
|
page read and write
|
||
570000
|
unkown image
|
page readonly
|
||
80D0000
|
heap private
|
page read and write
|
||
AD000
|
unkown
|
page read and write
|
||
6F09000
|
unkown image
|
page readonly
|
||
3840000
|
unkown
|
page read and write
|
||
72C0000
|
unkown
|
page read and write
|
||
5540000
|
unkown
|
page read and write
|
||
460000
|
unkown
|
page read and write
|
||
630000
|
unkown image
|
page readonly
|
||
6BC7000
|
unkown
|
page read and write
|
||
2069000
|
unkown
|
page read and write
|
||
7DBA000
|
unkown
|
page read and write
|
||
3B7000
|
heap default
|
page read and write
|
||
7FFFFFB0000
|
unkown image
|
page readonly
|
||
5510000
|
unkown
|
page read and write
|
||
4C0000
|
unkown
|
page read and write
|
||
3170000
|
unkown
|
page read and write
|
||
3800000
|
unkown
|
page read and write
|
||
36F0000
|
unkown
|
page read and write
|
||
3F0000
|
unkown image
|
page readonly
|
||
5560000
|
unkown
|
page read and write
|
||
7FFFFFB2000
|
unkown image
|
page readonly
|
||
4F70000
|
unkown
|
page read and write
|
||
555B000
|
unkown
|
page read and write
|
||
5840000
|
unkown
|
page read and write
|
||
4B90000
|
stack
|
page read and write
|
||
4BD0000
|
stack
|
page read and write
|
||
1A7000
|
heap default
|
page read and write
|
||
44A0000
|
unkown
|
page read and write
|
||
1DCD000
|
heap private
|
page read and write
|
||
388000
|
unkown
|
page read and write
|
||
38C000
|
heap default
|
page read and write
|
||
7240000
|
heap private
|
page read and write
|
||
2D6000
|
heap default
|
page read and write
|
||
5AC2000
|
unkown
|
page read and write
|
||
38C4000
|
unkown
|
page read and write
|
||
20000
|
unkown image
|
page readonly
|
||
7FFFFFC2000
|
unkown image
|
page readonly
|
||
6C04000
|
unkown
|
page read and write
|
||
361000
|
heap default
|
page read and write
|
||
5888000
|
unkown
|
page read and write
|
||
5570000
|
unkown
|
page read and write
|
||
1D50000
|
unkown
|
page read and write
|
||
6E23000
|
unkown
|
page read and write
|
||
5AA9000
|
unkown
|
page read and write
|
||
5510000
|
unkown
|
page read and write
|
||
4B00000
|
stack
|
page read and write
|
||
4D40000
|
unkown
|
page read and write
|
||
396E000
|
unkown
|
page read and write
|
||
60000
|
unkown image
|
page readonly
|
||
370000
|
heap default
|
page read and write
|
||
6E530000
|
unkown image
|
page readonly
|
||
7FFFFFB2000
|
unkown image
|
page readonly
|
||
1DC0000
|
heap private
|
page read and write
|
||
5510000
|
unkown
|
page read and write
|
||
310000
|
unkown
|
page read and write
|
||
6E85C000
|
unkown image
|
page read and write
|
||
5BB0000
|
unkown
|
page read and write
|
||
718C000
|
unkown
|
page read and write
|
||
4AE0000
|
stack
|
page read and write
|
||
59D0000
|
unkown
|
page read and write
|
||
5901000
|
stack
|
page read and write
|
||
6BE0000
|
unkown
|
page read and write
|
||
524000
|
heap private
|
page read and write
|
||
5510000
|
unkown
|
page read and write
|
||
6E3D000
|
unkown
|
page read and write
|
||
4370000
|
unkown
|
page read and write
|
||
3B57000
|
heap private
|
page read and write
|
||
6F0F000
|
unkown image
|
page readonly
|
||
58DC000
|
stack
|
page read and write
|
||
7110000
|
unkown
|
page read and write
|
||
31A0000
|
unkown
|
page read and write
|
||
7110000
|
unkown
|
page read and write
|
||
6D56000
|
unkown
|
page read and write
|
||
44F0000
|
unkown
|
page read and write
|
||
7FFFFFB2000
|
unkown image
|
page readonly
|
||
7FFFFFC0000
|
unkown image
|
page readonly
|
||
5510000
|
unkown
|
page read and write
|
||
5AA1000
|
unkown
|
page read and write
|
||
7B0000
|
unkown image
|
page readonly
|
||
35C0000
|
unkown
|
page read and write
|
||
87CE000
|
stack
|
page read and write
|
||
6BB0000
|
unkown
|
page read and write
|
||
7110000
|
unkown
|
page read and write
|
||
7EFB2000
|
unkown image
|
page readonly
|
||
718C000
|
unkown
|
page read and write
|
||
4390000
|
unkown image
|
page readonly
|
||
4AD0000
|
unkown
|
page read and write
|
||
77AE000
|
stack
|
page read and write
|
||
1D87000
|
unkown
|
page read and write
|
||
6F4F000
|
heap private
|
page read and write
|
||
4D49000
|
unkown
|
page read and write
|
||
214000
|
heap default
|
page read and write
|
||
7EFE0000
|
unkown image
|
page readonly
|
||
3820000
|
unkown
|
page read and write
|
||
820000
|
unkown image
|
page readonly
|
||
5510000
|
unkown
|
page read and write
|
||
7175000
|
unkown
|
page read and write
|
||
7630000
|
heap private
|
page read and write
|
||
6FD0000
|
heap private
|
page read and write
|
||
7C0000
|
unkown image
|
page readonly
|
||
5840000
|
unkown
|
page read and write
|
||
4450000
|
stack
|
page read and write
|
||
2080000
|
heap private
|
page read and write
|
||
6F19000
|
heap private
|
page read and write
|
||
394000
|
heap default
|
page read and write
|
||
5890000
|
unkown
|
page read and write
|
||
6E858000
|
unkown image
|
page write copy
|
||
7FFFFFD0000
|
unkown image
|
page readonly
|
||
7EFB2000
|
unkown image
|
page readonly
|
||
6F10000
|
heap private
|
page read and write
|
||
3970000
|
unkown
|
page read and write
|
||
7110000
|
unkown
|
page read and write
|
||
297000
|
heap default
|
page read and write
|
||
3980000
|
unkown
|
page read and write
|
||
4378000
|
unkown
|
page read and write
|
||
31B8000
|
unkown
|
page read and write
|
||
1DC5000
|
heap private
|
page read and write
|
||
387D000
|
unkown
|
page read and write
|
||
397F000
|
unkown
|
page read and write
|
||
6C90000
|
unkown image
|
page read and write
|
||
557E000
|
unkown
|
page read and write
|
||
4FB7000
|
unkown
|
page read and write
|
||
5257000
|
unkown image
|
page readonly
|
||
3894000
|
heap private
|
page read and write
|
||
5450000
|
unkown
|
page read and write
|
||
6E54000
|
heap private
|
page read and write
|
||
5BB0000
|
unkown
|
page read and write
|
||
186000
|
unkown
|
page read and write
|
||
5543000
|
unkown
|
page read and write
|
||
36EF000
|
stack
|
page read and write
|
||
70000
|
unkown
|
page read and write
|
||
35C8000
|
unkown
|
page read and write
|
||
567000
|
heap default
|
page read and write
|
||
6E30000
|
unkown
|
page read and write
|
||
6CA0000
|
heap private
|
page read and write
|
||
44F000
|
stack
|
page read and write
|
||
7FFFFFB2000
|
unkown image
|
page readonly
|
||
6E801000
|
unkown image
|
page readonly
|
||
72C0000
|
unkown
|
page read and write
|
||
2F50000
|
unkown
|
page read and write
|
||
56D000
|
heap default
|
page read and write
|
||
391000
|
unkown
|
page read and write
|
||
420000
|
unkown
|
page read and write
|
||
5840000
|
unkown
|
page read and write
|
||
1DB0000
|
unkown image
|
page readonly
|
||
37F8000
|
unkown
|
page read and write
|
||
10000
|
unkown image
|
page read and write
|
||
58A0000
|
unkown
|
page read and write
|
||
7110000
|
unkown
|
page read and write
|
||
4D60000
|
unkown
|
page read and write
|
||
10000
|
unkown image
|
page read and write
|
||
32D000
|
heap default
|
page read and write
|
||
3830000
|
unkown
|
page read and write
|
||
7FFFFFB0000
|
unkown image
|
page readonly
|
||
150000
|
unkown
|
page read and write
|
||
5567000
|
unkown
|
page read and write
|
||
2500000
|
unkown
|
page read and write
|
||
591C000
|
unkown
|
page read and write
|
||
7EFC2000
|
unkown image
|
page readonly
|
||
59F5000
|
unkown
|
page read and write
|
||
388000
|
unkown
|
page read and write
|
||
7EFC2000
|
unkown image
|
page readonly
|
||
5BB0000
|
unkown image
|
page read and write
|
||
520000
|
heap private
|
page read and write
|
||
3967000
|
unkown
|
page read and write
|
||
20000
|
unkown image
|
page readonly
|
||
5905000
|
unkown
|
page read and write
|
||
6BB0000
|
unkown
|
page read and write
|
||
7FFFFFC2000
|
unkown image
|
page readonly
|
||
396000
|
unkown
|
page read and write
|
||
4E20000
|
stack
|
page read and write
|
||
6C34000
|
unkown
|
page read and write
|
||
35E0000
|
unkown
|
page read and write
|
||
4E40000
|
stack
|
page read and write
|
||
5562000
|
unkown
|
page read and write
|
||
7EFE0000
|
unkown image
|
page readonly
|
||
6F90000
|
unkown
|
page read and write
|
||
3962000
|
unkown
|
page read and write
|
||
5510000
|
unkown
|
page read and write
|
||
5840000
|
unkown
|
page read and write
|
||
1D9E000
|
unkown
|
page read and write
|
||
6C80000
|
unkown image
|
page read and write
|
||
2030000
|
unkown
|
page read and write
|
||
6F00000
|
unkown image
|
page readonly
|
||
74C5000
|
unkown
|
page read and write
|
||
7EFC0000
|
unkown image
|
page readonly
|
||
6C10000
|
unkown image
|
page readonly
|
||
190000
|
unkown image
|
page readonly
|
||
3230000
|
unkown
|
page read and write
|
||
7110000
|
unkown
|
page read and write
|
||
3245000
|
unkown
|
page read and write
|
||
1C20000
|
unkown
|
page read and write
|
||
6BB0000
|
unkown
|
page read and write
|
||
5A85000
|
unkown
|
page read and write
|
||
7090000
|
heap private
|
page read and write
|
||
6F04000
|
unkown image
|
page readonly
|
||
4BC0000
|
stack
|
page read and write
|
||
690000
|
unkown image
|
page readonly
|
||
2570000
|
unkown image
|
page readonly
|
||
3380000
|
unkown
|
page read and write
|
||
6E531000
|
unkown image
|
page execute read
|
||
72C0000
|
unkown
|
page read and write
|
||
4E02000
|
stack
|
page read and write
|
||
680000
|
unkown image
|
page readonly
|
||
4500000
|
unkown
|
page read and write
|
||
6BB0000
|
unkown
|
page read and write
|
||
4D0000
|
unkown
|
page read and write
|
||
336F000
|
stack
|
page read and write
|
||
3965000
|
unkown
|
page read and write
|
||
2580000
|
unkown image
|
page readonly
|
||
7FFFFFB2000
|
unkown image
|
page readonly
|
||
5880000
|
unkown
|
page read and write
|
||
B0000
|
heap private
|
page read and write
|
||
549D000
|
unkown
|
page read and write
|
||
7130000
|
unkown
|
page read and write
|
||
204D000
|
unkown
|
page read and write
|
||
2B0000
|
unkown
|
page read and write
|
||
4DF0000
|
stack
|
page read and write
|
||
12D000
|
unkown
|
page read and write
|
||
4E50000
|
stack
|
page read and write
|
||
4550000
|
heap private
|
page execute and read and write
|
||
3B30000
|
unkown
|
page read and write
|
||
6D20000
|
unkown
|
page read and write
|
||
3190000
|
unkown
|
page read and write
|
||
B0000
|
unkown image
|
page readonly
|
||
802F000
|
unkown
|
page read and write
|
||
7FFFFFD0000
|
unkown image
|
page readonly
|
||
1DC7000
|
heap private
|
page read and write
|
||
3370000
|
unkown
|
page read and write
|
||
388000
|
unkown
|
page read and write
|
||
5510000
|
unkown
|
page read and write
|
||
1D70000
|
unkown
|
page read and write
|
||
5520000
|
unkown
|
page read and write
|
||
4AE0000
|
stack
|
page read and write
|
||
12D0000
|
unkown
|
page read and write
|
||
38A0000
|
unkown
|
page read and write
|
||
140000
|
unkown
|
page read and write
|
||
4F55000
|
unkown
|
page read and write
|
||
4E50000
|
stack
|
page read and write
|
||
38E0000
|
heap private
|
page read and write
|
||
A6D000
|
stack
|
page read and write
|
||
5A7F000
|
unkown
|
page read and write
|
||
4BC6000
|
stack
|
page read and write
|
||
5840000
|
unkown
|
page read and write
|
||
2050000
|
unkown
|
page read and write
|
||
5A42000
|
unkown
|
page read and write
|
||
6CA5000
|
heap private
|
page read and write
|
||
30A0000
|
heap private
|
page read and write
|
||
17B000
|
unkown
|
page read and write
|
||
2090000
|
heap private
|
page read and write
|
||
7550000
|
unkown
|
page read and write
|
||
377000
|
unkown
|
page read and write
|
||
4A0000
|
unkown
|
page read and write
|
||
2023000
|
unkown
|
page read and write
|
||
35BF000
|
stack
|
page read and write
|
||
5A9D000
|
unkown
|
page read and write
|
||
1D60000
|
unkown
|
page read and write
|
||
5510000
|
unkown
|
page read and write
|
||
82D0000
|
unkown
|
page read and write
|
||
3F0000
|
unkown image
|
page readonly
|
||
40000
|
unkown image
|
page readonly
|
||
1D30000
|
unkown
|
page read and write
|
||
6F90000
|
unkown
|
page read and write
|
||
5AA9000
|
unkown
|
page read and write
|
||
6BFF000
|
unkown
|
page read and write
|
||
7FFFFFB0000
|
unkown image
|
page readonly
|
||
7FFFFFB0000
|
unkown image
|
page readonly
|
||
4FCD000
|
unkown
|
page read and write
|
||
7EFB0000
|
unkown image
|
page readonly
|
||
552A000
|
unkown
|
page read and write
|
||
7FFFFFC0000
|
unkown image
|
page readonly
|
||
376000
|
unkown
|
page read and write
|
||
396A000
|
unkown
|
page read and write
|
||
7FFFFFC2000
|
unkown image
|
page readonly
|
||
7110000
|
unkown
|
page read and write
|
||
82BA000
|
stack
|
page read and write
|
||
58B5000
|
stack
|
page read and write
|
||
4E50000
|
stack
|
page read and write
|
||
3860000
|
unkown
|
page read and write
|
||
7FB0000
|
unkown
|
page read and write
|
||
5850000
|
unkown
|
page read and write
|
||
7FFFFFB0000
|
unkown image
|
page readonly
|
||
7FFFFFB0000
|
unkown image
|
page readonly
|
||
588A000
|
unkown
|
page read and write
|
||
3ACD000
|
stack
|
page read and write
|
||
500000
|
unkown image
|
page readonly
|
||
4E20000
|
stack
|
page read and write
|
||
34F000
|
heap default
|
page read and write
|
||
7EFDF000
|
unkown
|
page read and write
|
||
2590000
|
heap private
|
page read and write
|
||
2F6000
|
heap default
|
page read and write
|
||
50000
|
unkown image
|
page readonly
|
||
58E8000
|
unkown
|
page read and write
|
||
60000
|
unkown image
|
page readonly
|
||
7130000
|
unkown
|
page read and write
|
||
7E70000
|
heap private
|
page read and write
|
||
1D98000
|
unkown
|
page read and write
|
||
6BD0000
|
unkown
|
page read and write
|
||
6BF0000
|
unkown
|
page read and write
|
||
5674000
|
stack
|
page read and write
|
||
6E85F000
|
unkown image
|
page readonly
|
||
7F25000
|
unkown
|
page read and write
|
||
4E00000
|
stack
|
page read and write
|
||
7FEFF1A0000
|
unkown
|
page execute read
|
||
24E0000
|
unkown
|
page read and write
|
||
5840000
|
unkown
|
page read and write
|
||
300000
|
heap private
|
page read and write
|
||
5AA9000
|
unkown
|
page read and write
|
||
1D90000
|
unkown
|
page read and write
|
||
58C0000
|
unkown
|
page read and write
|
||
3390000
|
unkown
|
page read and write
|
||
30A4000
|
heap private
|
page read and write
|
||
10000
|
unkown image
|
page read and write
|
||
43A0000
|
stack
|
page read and write
|
||
7880000
|
unkown
|
page read and write
|
||
4362000
|
unkown
|
page read and write
|
||
4E10000
|
stack
|
page read and write
|
||
377000
|
unkown
|
page read and write
|
||
4AE0000
|
stack
|
page read and write
|
||
4AE0000
|
stack
|
page read and write
|
||
4E06000
|
stack
|
page read and write
|
||
4AE0000
|
stack
|
page read and write
|
||
2F86000
|
unkown
|
page read and write
|
||
4E20000
|
stack
|
page read and write
|
||
7110000
|
unkown
|
page read and write
|
||
1AD0000
|
unkown
|
page read and write
|
||
3180000
|
unkown
|
page read and write
|
||
1A0000
|
heap default
|
page read and write
|
||
1D40000
|
unkown
|
page read and write
|
||
B0000
|
heap private
|
page read and write
|
||
4BCA000
|
stack
|
page read and write
|
||
7158000
|
unkown
|
page read and write
|
||
7110000
|
unkown
|
page read and write
|
||
950000
|
unkown image
|
page readonly
|
||
377000
|
unkown
|
page read and write
|
||
44FC000
|
unkown
|
page read and write
|
||
7FFFFFB2000
|
unkown image
|
page readonly
|
||
4BB0000
|
stack
|
page read and write
|
||
7110000
|
unkown
|
page read and write
|
||
4D20000
|
unkown
|
page read and write
|
There are 542 hidden memdumps, click here to show them.