IOC Report

loading gif

Files

File Path
Type
Category
Malicious
CU-6431 report.xlsm
Microsoft Excel 2007+
initial sample
malicious
C:\Users\user\Desktop\~$CU-6431 report.xlsm
data
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNHC0JWC\U7NJK7LJ.htm
HTML document, UTF-8 Unicode text, with very long lines, with CRLF, LF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\17493318.png
PNG image data, 1714 x 241, 8-bit colormap, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Temp\709E.tmp
Composite Document File V2 Document, Cannot read section info
dropped
clean
C:\Users\user\AppData\Local\Temp\~DFB67210ABB967FABD.TMP
data
dropped
clean
C:\Users\user\besta.ocx
HTML document, UTF-8 Unicode text, with very long lines, with CRLF, LF line terminators
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /automation -Embedding
malicious
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWow64\rundll32.exe ..\besta.ocx,44532.4786822917
malicious

URLs

Name
IP
Malicious
http://standoutglobal.com/2/MWpqeVgZ/
162.240.9.126
malicious
https://vendes.marketing/agencia-de-marketing-digital/ecommerce/conversion-rate-optimization/
unknown
clean
https://vendes.marketing/wp-content/plugins/happy-elementor-addons/assets/fonts/style.min.css?ver=3.
unknown
clean
https://vendes.marketing/wp-content/uploads/2021/10/framer.svg
unknown
clean
https://vendes.marketing/wp-content/uploads/elementor/css/post-1522.css?ver=1638212153
unknown
clean
https://vendes.marketing/agencia-de-marketing-digital-en-cdmx/
unknown
clean
https://vendes.marketing/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.svg?5.10.0#eico
unknown
clean
https://vendes.marketing/wp-content/plugins/elementor/assets/js/frontend-modules.min.js?ver=3.4.8
unknown
clean
https://vendes.marketing/agencia-de-marketing-digital/e-commerce-efectivo/conversion-rate-optimizati
unknown
clean
http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl0
unknown
clean
http://www.diginotar.nl/cps/pkioverheid0
unknown
clean
https://vendes.marketing/wp-content/uploads/2021/11/logo-VNDSmkt-final-300x102.png
unknown
clean
https://vendes.marketing/agencia-de-marketing-digital/servicios-creativos/diseno-web-ux/
unknown
clean
https://vendes.marketing/agencia-de-marketing-digital/servicios-de-marketing-digital/creacion-de-con
unknown
clean
https://vendes.marketing/wp-content/uploads/2021/10/anuncios-300x270.png
unknown
clean
http://schemas.open
unknown
clean
https://vendes.marketing/agencia-de-marketing-digital/servicios-de-marketing-digital/estrategias-en-
unknown
clean
https://vendes.marketing/wp-content/plugins/elementor/assets/lib/font-awesome/css/solid.min.css?ver=
unknown
clean
https://vendes.marketing/agencia-de-marketing-digital/e-commerce-efectivo/pagos-online/
unknown
clean
https://vendes.marketing/agencia-de-marketing-digital/servicios-creativos/branding/
unknown
clean
https://vendes.marketing/wp-content/uploads/images/comentario1.jpg
unknown
clean
https://vendes.marketing/
107.180.46.229
clean
https://vendes.marketing/agencia-de-marketing-digital/servicios-creativos/fotografia-y-edicion/
unknown
clean
https://connect.facebook.net/en_US/fbevents.js
unknown
clean
https://vendes.marketing/wp-content/plugins/elementor/assets/lib/eicons/css/elementor-icons.min.css?
unknown
clean
http://standoutglobal.c
unknown
clean
https://vendes.marketing/blog/
unknown
clean
https://vendes.marketing/wp-content/uploads/2021/10/visual-Studio.svg
unknown
clean
https://vendes.marketing/agencia-de-marketing-digital/servicios-de-marketing-digital/publicidad-digi
unknown
clean
https://vendes.marketing/comments/feed/
unknown
clean
https://standoutglobal.com/
unknown
clean
https://vendes.marketing/wp-includes/js/wp-embed.min.js?ver=5.8.2
unknown
clean
http://vendes.marketing/transmigrant/Wplzr/
107.180.46.229
clean
https://s.w.org/images/core/emoji/13.1.0/svg/1f609.svg
unknown
clean
https://vendes.marketing/wp-content/plugins/elementor-pro/assets/lib/smartmenus/jquery.smartmenus.mi
unknown
clean
https://vendes.marketing/agencia-de-marketing-digital/e-commerce-efectivo/tienda-online-con-magento/
unknown
clean
https://vendes.marketing/agencia-de-marketing-digital/consultorias/marketing-para-el-sector-salud/
unknown
clean
https://vendes.marketing/wp-content/plugins/elementor/assets/lib/font-awesome/css/fontawesome.min.cs
unknown
clean
https://vendes.marketing/wp-content/uploads/2021/11/logo-VNDSmkt-final-1536x522.png
unknown
clean
http://www.windows.com/pctv.
unknown
clean
https://vendes.marketing/wp-includes/wlwmanifest.xml
unknown
clean
https://vendes.marketing/agencia-de-marketing-digital/servicios-de-desarrollo-web/automatizacion-de-
unknown
clean
http://schemas.openformatrg/drawml/2006/spreadsheetD
unknown
clean
https://vendes.marketing/wp-content/plugins/elementor/assets/js/frontend.min.js?ver=3.4.8
unknown
clean
https://vendes.marketing/wp-content/uploads/2021/10/figma.svg
unknown
clean
https://vendes.marketing/wp-content/uploads/2021/10/marketing-digital-con-instagram.png
unknown
clean
https://vendes.marketing/wp-content/plugins/elementor-pro/assets/css/frontend.min.css?ver=3.0.2
unknown
clean
https://vendes.marketing/agencia-de-marketing-digital-en-monterrey/
unknown
clean
https://schema.org
unknown
clean
https://vendes.marketing/agencia-de-marketing-digital/consultorias/consultoria-en-marketing-basado-e
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
https://vendes.marketing/agencia-de-marketing-digital/consultorias/auditorias-y-optimizacion-de-camp
unknown
clean
https://vendes.marketing/agencia-de-marketing-digital/servicios-de-desarrollo-web/desarrollo-de-mega
unknown
clean
https://vendes.marketing/wp-content/uploads/elementor/css/post-2157.css?ver=1638212282
unknown
clean
https://vendes.marketing/wp-content/themes/twentytwentyone/assets/js/responsive-embeds.js?ver=1.4
unknown
clean
http://standoutglobal.co
unknown
clean
https://connect.facebook.net/es_LA/sdk/xfbml.customerchat.js
unknown
clean
https://vendes.marketing/wp-content/plugins/elementor-pro/assets/lib/lottie/lottie.min.js?ver=5.6.6
unknown
clean
https://vendes.marketing/wp-includes/css/dist/block-library/style.min.css?ver=5.8.2
unknown
clean
http://schemas.openformatrg/package/2006/r
unknown
clean
https://vendes.marketing/wp-content/plugins/elementor/assets/lib/share-link/share-link.min.js?ver=3.
unknown
clean
https://vendes.marketing/agencia-de-marketing-digital/consultorias/digital-partner-incubadora-de-neg
unknown
clean
https://vendes.marketing/wp-content/plugins/elementor/assets/lib/animations/animations.min.css?ver=3
unknown
clean
https://vendes.marketing/wp-includes/js/imagesloaded.min.js?ver=4.1.4
unknown
clean
https://vendes.marketing/wp-json/oembed/1.0/embed?url=https%3A%2F%2Fvendes.marketing%2F
unknown
clean
https://standoutglobal.com/2/MWpqeVgZ/
162.240.9.126
clean
https://vendes.marketing/xmlrpc.php?rsd
unknown
clean
https://vendes.marketing/wp-content/uploads/2021/10/elementor.svg
unknown
clean
https://vendes.marketing/agencia-de-marketing-digital/servicios-de-marketing-digital/inbound-marketi
unknown
clean
https://vendes.marketing/wp-content/plugins/elementor/assets/js/preloaded-modules.min.js?ver=3.4.8
unknown
clean
https://vendes.marketing/wp-content/themes/twentytwentyone/assets/css/ie.css?ver=1.4
unknown
clean
https://vendes.marketing/wp-content/plugins/elementor/assets/lib/font-awesome/js/v4-shims.min.js?ver
unknown
clean
https://www.thinkwithgoogle.com/intl/es-419/futuro-del-marketing/transformacion-digital/tiendas-omni
unknown
clean
https://vendes.marketing/feed/
unknown
clean
https://vendes.marketing/wp-content/uploads/images/caso-exito1.png
unknown
clean
http://crl.entrust.net/2048ca.crl0
unknown
clean
https://vendes.marketing/agencia-de-marketing-digital/consultorias/consultoria-para-adsense/
unknown
clean
https://vendes.marketing/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.woff2?5.10.0)
unknown
clean
https://vendes.marketing/wp-content/uploads/2021/10/apple_android.svg
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
https://vendes.marketing/wp-content/plugins/elementor/assets/lib/font-awesome/css/all.min.css?ver=4.
unknown
clean
https://vendes.marketing/agencia-de-marketing-digital/ecommerce/emailing/
unknown
clean
https://vendes.marketing/agencia-de-marketing-digital/servicios-creativos/produccion-audiovisual/
unknown
clean
http://ocsp.entrust.net03
unknown
clean
http://schemas.openformatrg/package/2006/content-t
unknown
clean
https://vendes.marketing/8
unknown
clean
https://vendes.marketing/wp-content/uploads/2021/10/anuncios.png
unknown
clean
https://vendes.marketing/agencia-de-marketing-digital/e-commerce-efectivo/tiendas-en-facebook-e-inst
unknown
clean
https://vendes.marketing/agencia-de-marketing-digital/ecommerce/
unknown
clean
https://vendes.marketing/wp-content/uploads/2021/10/marketing-digital-con-facebook.png
unknown
clean
https://vendes.marketing/wp-content/plugins/elementor/assets/js/webpack.runtime.min.js?ver=3.4.8
unknown
clean
https://vendes.marketing/agencia-de-marketing-digital/ecommerce/pagos-online/
unknown
clean
https://vendes.marketing/wp-content/uploads/elementor/css/post-2017.css?ver=1638212282
unknown
clean
https://vendes.marketing/agencia-de-marketing-digital/servicios-de-desarrollo-web/
unknown
clean
https://vendes.marketing/wp-content/uploads/2021/10/marketing-digital-con-youtube.png
unknown
clean
https://vendes.marketing/wp-content/uploads/images/comentario5-m.jpg
unknown
clean
https://vendes.marketing/agencia-de-marketing-digital/e-commerce-efectivo/tienda-online-con-shopify/
unknown
clean
https://vendes.marketing/agencia-de-marketing-digital/consultorias/
unknown
clean
https://vendes.marketing/agencia-de-marketing-digital/consultorias/marketing-para-inmobiliarias-cons
unknown
clean
https://vendes.marketing/agencia-de-marketing-digital/servicios-creativos/diseno-grafico/
unknown
clean
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
standoutglobal.com
162.240.9.126
clean
vendes.marketing
107.180.46.229
clean

IPs

IP
Domain
Country
Malicious
162.240.9.126
standoutglobal.com
United States
clean
107.180.46.229
vendes.marketing
United States
clean

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
jd*
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
MTTT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\2D7A9
2D7A9
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
fo*
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@%SystemRoot%\system32\qagentrt.dll,-10
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@%SystemRoot%\System32\fveui.dll,-843
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@%SystemRoot%\System32\fveui.dll,-844
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@%SystemRoot%\System32\wuaueng.dll,-400
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\37899
37899
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\37F9B
37F9B
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
EXCELFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\12891DF7B048CD69D0196C8AD7A754C8A812A08C
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\12891DF7B048CD69D0196C8AD7A754C8A812A08C
Blob
clean
There are 59 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
357000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
2170000
unkown image
page readonly
clean
2610000
unkown
page read and write
clean
162000
unkown
page read and write
clean
5AB4000
unkown
page read and write
clean
A4F000
stack
page read and write
clean
7430000
heap private
page read and write
clean
7AAF000
heap private
page read and write
clean
55E0000
unkown
page read and write
clean
6FF4000
unkown image
page readonly
clean
7390000
unkown
page read and write
clean
7100000
unkown
page read and write
clean
6EC0000
heap private
page read and write
clean
C60000
heap private
page read and write
clean
169000
unkown
page read and write
clean
5B20000
unkown
page read and write
clean
310000
heap private
page read and write
clean
82E2000
unkown
page read and write
clean
1D16000
unkown
page read and write
clean
157000
unkown
page read and write
clean
5627000
unkown
page read and write
clean
7FEFF1A0000
unkown
page execute read
clean
72B2000
unkown
page read and write
clean
204D000
unkown
page read and write
clean
70E6000
unkown
page read and write
clean
20F0000
heap private
page read and write
clean
3354000
heap private
page read and write
clean
3665000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
55E0000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
7100000
unkown
page read and write
clean
24F000
stack
page read and write
clean
1CE0000
unkown
page read and write
clean
41D0000
unkown
page read and write
clean
71C0000
heap private
page read and write
clean
43E1000
unkown
page read and write
clean
7A79000
heap private
page read and write
clean
55E0000
unkown
page read and write
clean
55F0000
unkown
page read and write
clean
7E80000
unkown
page read and write
clean
5147000
unkown
page read and write
clean
737C000
stack
page read and write
clean
50000
unkown image
page readonly
clean
49E000
unkown
page read and write
clean
5724000
stack
page read and write
clean
20000
unkown image
page readonly
clean
3100000
unkown
page read and write
clean
3640000
unkown
page read and write
clean
55E0000
unkown
page read and write
clean
7020000
unkown
page read and write
clean
55E0000
unkown
page read and write
clean
5609000
unkown
page read and write
clean
7EE5000
unkown
page read and write
clean
43B0000
unkown
page read and write
clean
30E0000
unkown
page read and write
clean
7C8C000
stack
page read and write
clean
37A0000
unkown
page read and write
clean
6BD0000
unkown
page read and write
clean
6F70000
heap private
page read and write
clean
46FE000
stack
page read and write
clean
6CF4000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
433000
unkown
page read and write
clean
5A9A000
unkown
page read and write
clean
7300000
unkown
page read and write
clean
5100000
unkown
page read and write
clean
42DF000
stack
page read and write
clean
2069000
unkown
page read and write
clean
406000
unkown
page read and write
clean
3610000
unkown
page read and write
clean
6BE0000
unkown
page read and write
clean
5B40000
unkown
page read and write
clean
430000
unkown
page read and write
clean
7EFC000
unkown
page read and write
clean
2560000
unkown
page read and write
clean
562A000
unkown
page read and write
clean
367000
unkown
page read and write
clean
41B0000
unkown
page read and write
clean
34C0000
unkown
page read and write
clean
21AB000
heap private
page read and write
clean
7930000
heap private
page read and write
clean
214000
heap private
page read and write
clean
70F0000
unkown
page read and write
clean
38A0000
unkown
page read and write
clean
7130000
heap private
page read and write
clean
65300000
unkown image
page readonly
clean
20B0000
unkown
page read and write
clean
5AD9000
unkown
page read and write
clean
4C70000
unkown
page read and write
clean
2625000
heap private
page read and write
clean
73B0000
unkown
page read and write
clean
7E80000
unkown
page read and write
clean
4C7000
heap default
page read and write
clean
20000
heap private
page read and write
clean
16D000
unkown
page read and write
clean
453E000
stack
page read and write
clean
420000
unkown image
page readonly
clean
7E80000
unkown
page read and write
clean
42E000
unkown
page read and write
clean
3D0000
unkown
page read and write
clean
488000
unkown
page read and write
clean
2580000
unkown image
page readonly
clean
2064000
unkown
page read and write
clean
740000
unkown image
page readonly
clean
2F0000
unkown
page read and write
clean
6D23000
unkown
page read and write
clean
4FF0000
unkown
page read and write
clean
5748000
unkown
page read and write
clean
2290000
heap private
page read and write
clean
3618000
unkown
page read and write
clean
3680000
unkown
page read and write
clean
7020000
unkown
page read and write
clean
7020000
unkown
page read and write
clean
1A0000
unkown image
page readonly
clean
154000
unkown
page read and write
clean
927000
unkown image
page readonly
clean
7256000
unkown
page read and write
clean
574A000
unkown
page read and write
clean
6D3E000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
7022000
unkown
page read and write
clean
8730000
unkown
page read and write
clean
166000
unkown
page read and write
clean
3000000
unkown image
page readonly
clean
30D000
heap default
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
35F0000
unkown
page read and write
clean
7275000
unkown
page read and write
clean
59CC000
stack
page read and write
clean
71B0000
unkown
page read and write
clean
7380000
unkown
page read and write
clean
357000
heap default
page read and write
clean
740000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
2050000
unkown
page read and write
clean
562000
heap default
page read and write
clean
10000
unkown image
page read and write
clean
150000
unkown
page read and write
clean
7020000
unkown
page read and write
clean
F0000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
3662000
unkown
page read and write
clean
6E88B000
unkown image
page read and write
clean
5BD0000
unkown
page read and write
clean
3977000
heap private
page read and write
clean
6C50000
heap private
page read and write
clean
74B0000
unkown
page read and write
clean
5C0000
unkown image
page readonly
clean
4FE0000
unkown
page read and write
clean
15B000
unkown
page read and write
clean
5A61000
unkown
page read and write
clean
5860000
unkown
page read and write
clean
6DB0000
unkown
page read and write
clean
6BD0000
unkown
page read and write
clean
7CB1000
stack
page read and write
clean
5ACA000
unkown
page read and write
clean
55FA000
unkown
page read and write
clean
25A0000
unkown
page read and write
clean
130000
heap private
page read and write
clean
25D0000
unkown
page read and write
clean
55E0000
unkown
page read and write
clean
324E000
stack
page read and write
clean
6BD0000
unkown
page read and write
clean
6C01000
unkown
page read and write
clean
2B6000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
6E898000
unkown image
page write copy
clean
2FE0000
unkown
page read and write
clean
3670000
unkown
page read and write
clean
5B0000
unkown image
page readonly
clean
347F000
stack
page read and write
clean
320000
heap default
page read and write
clean
6BD0000
unkown
page read and write
clean
34E0000
unkown
page read and write
clean
8E0000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
31B000
heap default
page read and write
clean
6BFE000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
160000
heap default
page read and write
clean
6EBB000
unkown
page read and write
clean
53E7000
unkown image
page readonly
clean
7C8C000
stack
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
3120000
unkown
page read and write
clean
73E4000
heap private
page read and write
clean
3488000
unkown
page read and write
clean
7C2F000
unkown
page read and write
clean
6DE6000
unkown
page read and write
clean
3918000
unkown
page read and write
clean
360E000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
1F0000
unkown image
page readonly
clean
7E80000
unkown
page read and write
clean
58B0000
unkown
page read and write
clean
30C3000
unkown
page read and write
clean
3370000
unkown
page read and write
clean
34B0000
unkown
page read and write
clean
371000
unkown
page read and write
clean
25C0000
unkown
page read and write
clean
6E89C000
unkown image
page read and write
clean
3650000
unkown
page read and write
clean
7E80000
unkown
page read and write
clean
5AB0000
unkown
page read and write
clean
34A0000
unkown
page read and write
clean
362D000
unkown
page read and write
clean
5860000
unkown
page read and write
clean
1CD000
heap private
page read and write
clean
7E80000
unkown
page read and write
clean
5A9A000
unkown
page read and write
clean
7E80000
unkown
page read and write
clean
3F0000
unkown
page read and write
clean
7EE5000
unkown
page read and write
clean
443F000
unkown
page read and write
clean
1C5000
heap private
page read and write
clean
3630000
unkown
page read and write
clean
5860000
unkown
page read and write
clean
7EFC000
unkown
page read and write
clean
4A0000
unkown image
page readonly
clean
3010000
unkown image
page read and write
clean
5750000
unkown
page read and write
clean
6EB0000
unkown
page read and write
clean
366E000
unkown
page read and write
clean
43B8000
unkown
page read and write
clean
7EFC000
unkown
page read and write
clean
3040000
heap private
page read and write
clean
59EF000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
561E000
unkown
page read and write
clean
3620000
unkown
page read and write
clean
3250000
unkown
page read and write
clean
55E0000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
4C0000
heap default
page read and write
clean
232000
heap private
page read and write
clean
7A70000
heap private
page read and write
clean
7CB1000
stack
page read and write
clean
7E80000
unkown
page read and write
clean
6E570000
unkown image
page readonly
clean
7000000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
7060000
heap private
page read and write
clean
1D0000
unkown
page read and write
clean
8280000
unkown
page read and write
clean
464000
unkown
page read and write
clean
59D8000
unkown
page read and write
clean
7E80000
unkown
page read and write
clean
2570000
unkown image
page readonly
clean
58A0000
unkown
page read and write
clean
4430000
unkown
page read and write
clean
5615000
unkown
page read and write
clean
190000
unkown
page read and write
clean
2030000
unkown
page read and write
clean
70F0000
unkown
page read and write
clean
585A000
stack
page read and write
clean
5ACA000
unkown
page read and write
clean
7020000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
2FF0000
unkown
page read and write
clean
515D000
unkown
page read and write
clean
4B0000
unkown
page read and write
clean
420000
unkown
page read and write
clean
5160000
unkown
page read and write
clean
55E0000
unkown
page read and write
clean
7E80000
unkown
page read and write
clean
55E0000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
55E0000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
20F5000
heap private
page read and write
clean
7C9D000
stack
page read and write
clean
35EF000
stack
page read and write
clean
573F000
unkown
page read and write
clean
8280000
unkown
page read and write
clean
25F0000
unkown
page read and write
clean
7050000
unkown
page read and write
clean
7020000
unkown
page read and write
clean
8070000
heap private
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7E80000
unkown
page read and write
clean
376000
unkown
page read and write
clean
7E80000
unkown
page read and write
clean
86A5000
unkown
page read and write
clean
6CE000
stack
page read and write
clean
7E80000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
70F0000
unkown
page read and write
clean
5B4B000
unkown
page read and write
clean
7EFC0000
unkown image
page readonly
clean
5AB4000
unkown
page read and write
clean
20B0000
unkown image
page readonly
clean
6E841000
unkown image
page readonly
clean
5600000
unkown
page read and write
clean
6BD0000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
7E80000
unkown
page read and write
clean
2D0000
heap default
page read and write
clean
8270000
unkown
page read and write
clean
D0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
134000
heap private
page read and write
clean
3960000
unkown
page read and write
clean
357000
unkown
page read and write
clean
25E0000
unkown
page read and write
clean
3600000
unkown
page read and write
clean
8330000
unkown
page read and write
clean
3625000
unkown
page read and write
clean
340000
unkown
page read and write
clean
379E000
stack
page read and write
clean
7EFDF000
unkown
page read and write
clean
477000
unkown
page read and write
clean
7020000
unkown
page read and write
clean
5622000
unkown
page read and write
clean
7112000
unkown
page read and write
clean
316000
heap default
page read and write
clean
58C6000
unkown
page read and write
clean
7022000
unkown
page read and write
clean
5746000
unkown
page read and write
clean
7E80000
unkown
page read and write
clean
750000
unkown image
page readonly
clean
356000
unkown
page read and write
clean
17D000
unkown
page read and write
clean
4FD0000
unkown
page read and write
clean
5890000
unkown
page read and write
clean
3360000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
5860000
unkown
page read and write
clean
210000
heap private
page read and write
clean
2044000
unkown
page read and write
clean
6BD0000
unkown
page read and write
clean
443C000
unkown
page read and write
clean
7250000
unkown
page read and write
clean
6CD8000
unkown
page read and write
clean
7EA0000
unkown
page read and write
clean
3110000
unkown
page read and write
clean
366A000
unkown
page read and write
clean
826F000
stack
page read and write
clean
4E76000
unkown
page read and write
clean
7EC8000
unkown
page read and write
clean
21A0000
heap private
page read and write
clean
30F0000
unkown
page read and write
clean
270000
heap private
page read and write
clean
5730000
unkown
page read and write
clean
35D000
heap default
page read and write
clean
460000
unkown
page read and write
clean
4B3000
unkown
page read and write
clean
7EC8000
unkown
page read and write
clean
7050000
unkown
page read and write
clean
6C40000
unkown image
page read and write
clean
7116000
unkown
page read and write
clean
4FE000
heap default
page read and write
clean
58C0000
unkown
page read and write
clean
1B0000
unkown
page read and write
clean
82A5000
unkown
page read and write
clean
110000
unkown
page read and write
clean
4FFB000
unkown
page read and write
clean
344000
unkown
page read and write
clean
7030000
unkown
page read and write
clean
2629000
heap private
page read and write
clean
6C10000
unkown image
page readonly
clean
8271000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
7110000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
70EA000
unkown
page read and write
clean
2B4000
unkown
page read and write
clean
71B0000
unkown
page read and write
clean
5AB0000
unkown
page read and write
clean
30C5000
unkown
page read and write
clean
6D35000
heap private
page read and write
clean
7010000
unkown
page read and write
clean
86E2000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
43D0000
unkown image
page readonly
clean
8271000
unkown
page read and write
clean
362B000
unkown
page read and write
clean
28D000
unkown
page read and write
clean
5610000
unkown
page read and write
clean
5740000
unkown
page read and write
clean
2D7000
heap default
page read and write
clean
5BD0000
unkown
page read and write
clean
55E0000
unkown
page read and write
clean
BE0000
unkown
page read and write
clean
38ED000
unkown
page read and write
clean
1E0000
unkown
page read and write
clean
7120000
unkown
page read and write
clean
5AD9000
unkown
page read and write
clean
15F000
unkown
page read and write
clean
4C40000
unkown
page read and write
clean
7EA0000
unkown
page read and write
clean
5860000
unkown
page read and write
clean
7EFC000
unkown
page read and write
clean
4E65000
unkown
page read and write
clean
7EE5000
unkown
page read and write
clean
170000
unkown
page read and write
clean
43A2000
unkown
page read and write
clean
3350000
heap private
page read and write
clean
2060000
unkown
page read and write
clean
25B0000
unkown
page read and write
clean
5860000
unkown
page read and write
clean
5620000
unkown
page read and write
clean
7020000
unkown
page read and write
clean
34D0000
unkown
page read and write
clean
5BD0000
unkown image
page read and write
clean
21A4000
heap private
page read and write
clean
480000
unkown
page read and write
clean
2FD0000
unkown
page read and write
clean
BA000
unkown
page read and write
clean
5A0000
unkown image
page readonly
clean
73C0000
unkown
page read and write
clean
5200000
unkown image
page readonly
clean
55E0000
unkown
page read and write
clean
212B000
heap private
page read and write
clean
4C50000
unkown
page read and write
clean
7260000
unkown
page read and write
clean
5B20000
unkown
page read and write
clean
4D6F000
stack
page read and write
clean
58A0000
unkown
page read and write
clean
3629000
unkown
page read and write
clean
5860000
unkown
page read and write
clean
4D80000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
55E0000
unkown
page read and write
clean
6E89F000
unkown image
page readonly
clean
7000000
unkown
page read and write
clean
5BD0000
unkown
page read and write
clean
140000
unkown image
page read and write
clean
1C0000
heap private
page read and write
clean
326000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7E80000
unkown
page read and write
clean
48E000
unkown
page read and write
clean
5874000
unkown
page read and write
clean
6BF0000
unkown
page read and write
clean
6FF0000
unkown image
page readonly
clean
8308000
unkown
page read and write
clean
450000
unkown
page read and write
clean
534000
heap default
page read and write
clean
70E0000
unkown
page read and write
clean
4BF0000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
79B0000
heap private
page read and write
clean
440000
unkown
page read and write
clean
4FD7000
unkown
page read and write
clean
5A28000
unkown
page read and write
clean
7E80000
unkown
page read and write
clean
59D0000
unkown
page read and write
clean
7EA0000
unkown
page read and write
clean
5A14000
unkown
page read and write
clean
423000
unkown
page read and write
clean
7EC8000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
3490000
unkown
page read and write
clean
3286000
unkown
page read and write
clean
6E894000
unkown image
page read and write
clean
7EE5000
unkown
page read and write
clean
327000
heap default
page read and write
clean
100000
unkown image
page readonly
clean
7C9D000
stack
page read and write
clean
2608000
unkown
page read and write
clean
3148000
unkown
page read and write
clean
55E0000
unkown
page read and write
clean
E0000
unkown
page read and write
clean
7386000
unkown
page read and write
clean
4700000
unkown image
page readonly
clean
455000
unkown
page read and write
clean
5860000
unkown
page read and write
clean
50FE000
stack
page read and write
clean
21A8000
heap private
page read and write
clean
42E0000
heap private
page execute and read and write
clean
3030000
unkown
page read and write
clean
6CE4000
unkown
page read and write
clean
2040000
unkown
page read and write
clean
2600000
unkown
page read and write
clean
7E80000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
575B000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
73E0000
heap private
page read and write
clean
6C30000
unkown image
page read and write
clean
7E80000
unkown
page read and write
clean
344000
heap default
page read and write
clean
70F0000
unkown
page read and write
clean
5B38000
unkown
page read and write
clean
140000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
3970000
heap private
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7E80000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
7260000
unkown
page read and write
clean
2620000
heap private
page read and write
clean
7E80000
unkown
page read and write
clean
3130000
unkown
page read and write
clean
2520000
unkown
page read and write
clean
274000
heap private
page read and write
clean
3667000
unkown
page read and write
clean
6C20000
unkown image
page read and write
clean
5A20000
unkown
page read and write
clean
6E571000
unkown image
page execute read
clean
5BD0000
unkown
page read and write
clean
7EC8000
unkown
page read and write
clean
7EA0000
unkown
page read and write
clean
3140000
unkown
page read and write
clean
3622000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
6D30000
heap private
page read and write
clean
There are 502 hidden memdumps, click here to show them.