IOC Report

loading gif

Files

File Path
Type
Category
Malicious
4310352755503838173672.xlsb
Microsoft Excel 2007+
initial sample
malicious
C:\ProgramData\lvDMlIDBF.rtf
HTML document, ASCII text, with very long lines, with CRLF line terminators
dropped
malicious
C:\Users\user\Desktop\~$4310352755503838173672.xlsb
data
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\9CBB1296.png
PNG image data, 800 x 400, 8-bit/color RGBA, non-interlaced
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /automation -Embedding
malicious
C:\Windows\System32\wbem\WMIC.exe
wmic process call create "mshta C:\ProgramData\lvDMlIDBF.rtf"
malicious
C:\Windows\System32\mshta.exe
mshta C:\ProgramData\lvDMlIDBF.rtf
clean

URLs

Name
IP
Malicious
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://www.%s.comPA
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://servername/isapibackend.dll
unknown
clean
http://investor.msn.com/
unknown
clean
There are 1 hidden URLs, click here to show them.

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
~y)
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
MTTT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\2D4CC
2D4CC
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
>!)
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
EXCELFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
There are 3 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
577D000
unkown
page read and write
clean
2B22000
unkown
page read and write
clean
4FD5000
unkown
page read and write
clean
217B000
heap private
page read and write
clean
34D000
unkown
page read and write
clean
6EE0000
unkown
page read and write
clean
2A30000
unkown
page read and write
clean
5C00000
unkown
page read and write
clean
270000
unkown
page read and write
clean
1F90000
heap private
page read and write
clean
5C17000
unkown
page read and write
clean
31A000
unkown
page read and write
clean
2124000
unkown
page read and write
clean
2B27000
unkown
page read and write
clean
6F80000
unkown
page read and write
clean
450000
unkown image
page readonly
clean
71C0000
heap private
page read and write
clean
2C0000
heap default
page read and write
clean
144000
unkown
page read and write
clean
4F80000
unkown
page read and write
clean
318000
unkown
page read and write
clean
7768000
unkown
page read and write
clean
3F3000
heap default
page read and write
clean
340C000
unkown
page read and write
clean
4BD000
unkown
page read and write
clean
14E000
unkown
page read and write
clean
3160000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
58D0000
unkown
page read and write
clean
42F7000
unkown
page read and write
clean
2960000
unkown image
page read and write
clean
25B0000
unkown
page read and write
clean
42D0000
unkown
page read and write
clean
2980000
unkown
page read and write
clean
30BF000
stack
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
54AD000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
3E27000
unkown image
page readonly
clean
6EF0000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
1D40000
heap private
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
430B000
unkown
page read and write
clean
4DB000
unkown
page read and write
clean
20000
unkown image
page read and write
clean
55E0000
unkown
page read and write
clean
31F0000
heap private
page read and write
clean
4300000
unkown
page read and write
clean
442D000
stack
page read and write
clean
328000
unkown
page read and write
clean
3FE0000
unkown
page read and write
clean
2B80000
unkown image
page readonly
clean
5560000
unkown
page read and write
clean
3440000
unkown
page read and write
clean
5770000
unkown
page read and write
clean
2040000
heap private
page read and write
clean
40000
unkown image
page readonly
clean
42FE000
unkown
page read and write
clean
3C40000
unkown image
page readonly
clean
300000
unkown
page read and write
clean
4FD5000
unkown
page read and write
clean
5BBF000
stack
page read and write
clean
4FC9000
unkown
page read and write
clean
34B0000
unkown
page read and write
clean
4028000
unkown
page read and write
clean
26E0000
heap private
page read and write
clean
2B20000
unkown
page read and write
clean
1C8F000
unkown
page read and write
clean
65300000
unkown image
page readonly
clean
2FB8000
unkown
page read and write
clean
34F000
unkown
page read and write
clean
58C0000
unkown
page read and write
clean
2FAF000
stack
page read and write
clean
4595000
heap private
page read and write
clean
6D77000
unkown image
page read and write
clean
430000
unkown
page read and write
clean
13B0000
unkown image
page readonly
clean
1CB0000
unkown
page read and write
clean
207000
heap default
page read and write
clean
1DBE000
unkown
page read and write
clean
4D70000
unkown
page read and write
clean
34A0000
unkown
page read and write
clean
1F30000
unkown image
page read and write
clean
319000
unkown
page read and write
clean
2B26000
unkown
page read and write
clean
58E0000
unkown
page read and write
clean
5BDA000
unkown
page read and write
clean
328000
unkown
page read and write
clean
2B24000
unkown
page read and write
clean
4960000
unkown
page read and write
clean
42F5000
unkown
page read and write
clean
4DB000
unkown
page read and write
clean
14A000
unkown
page read and write
clean
3704000
heap private
page read and write
clean
34F000
unkown
page read and write
clean
2600000
heap private
page read and write
clean
3420000
unkown image
page read and write
clean
1550000
unkown image
page readonly
clean
3D1000
heap default
page read and write
clean
5520000
unkown
page read and write
clean
5520000
unkown
page read and write
clean
2110000
unkown
page read and write
clean
6FB4000
heap private
page read and write
clean
6FF0000
heap private
page read and write
clean
31F5000
heap private
page read and write
clean
42F000
heap default
page read and write
clean
4BB0000
unkown
page read and write
clean
2186000
heap private
page read and write
clean
32BF000
stack
page read and write
clean
4000000
unkown
page read and write
clean
2B2C000
unkown
page read and write
clean
1F1F000
stack
page read and write
clean
6D60000
unkown
page read and write
clean
4039000
unkown
page read and write
clean
545D000
unkown
page read and write
clean
4020000
unkown
page read and write
clean
3455000
unkown
page read and write
clean
2890000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
5520000
unkown
page read and write
clean
3FD0000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
4FD5000
unkown
page read and write
clean
440000
heap private
page read and write
clean
5D0000
unkown image
page readonly
clean
6E858000
unkown image
page write copy
clean
2A68000
unkown
page read and write
clean
29E0000
unkown
page read and write
clean
4140000
heap private
page execute and read and write
clean
4C3000
unkown
page read and write
clean
1D00000
unkown
page read and write
clean
37AE000
stack
page read and write
clean
5595000
heap private
page read and write
clean
3700000
heap private
page read and write
clean
2760000
unkown image
page readonly
clean
34D000
unkown
page read and write
clean
34A000
unkown
page read and write
clean
77E8000
unkown
page read and write
clean
35BF000
stack
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
4FDA000
unkown
page read and write
clean
4FE5000
unkown
page read and write
clean
3730000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
2A98000
unkown
page read and write
clean
6CC0000
unkown
page read and write
clean
3FC0000
unkown
page read and write
clean
32F0000
unkown
page read and write
clean
2AA0000
heap private
page read and write
clean
340A000
unkown
page read and write
clean
2B28000
unkown
page read and write
clean
6FA0000
unkown
page read and write
clean
2CB000
heap default
page read and write
clean
6D87000
unkown image
page read and write
clean
4D67000
unkown
page read and write
clean
2A70000
unkown
page read and write
clean
5910000
unkown
page read and write
clean
34D000
unkown
page read and write
clean
4310000
unkown
page read and write
clean
2A40000
unkown
page read and write
clean
6F79000
unkown
page read and write
clean
4C2000
unkown
page read and write
clean
5790000
unkown
page read and write
clean
36C0000
unkown
page read and write
clean
36B000
unkown
page read and write
clean
576E000
stack
page read and write
clean
7828000
unkown
page read and write
clean
34F000
unkown
page read and write
clean
4032000
unkown
page read and write
clean
29C8000
unkown
page read and write
clean
570000
unkown image
page readonly
clean
176000
unkown
page read and write
clean
5C2F000
unkown
page read and write
clean
4A6000
unkown
page read and write
clean
58C0000
unkown
page read and write
clean
330000
heap default
page read and write
clean
770000
unkown image
page readonly
clean
6FB0000
heap private
page read and write
clean
2B2A000
unkown
page read and write
clean
540000
unkown image
page readonly
clean
23E000
heap default
page read and write
clean
2A0C000
unkown
page read and write
clean
4C2000
unkown
page read and write
clean
4590000
heap private
page read and write
clean
2590000
heap private
page read and write
clean
5A34000
unkown
page read and write
clean
1D71000
unkown
page read and write
clean
1C85000
unkown
page read and write
clean
36B000
unkown
page read and write
clean
2640000
heap private
page read and write
clean
6E530000
unkown image
page readonly
clean
36F0000
unkown
page read and write
clean
1D30000
unkown
page read and write
clean
7640000
unkown
page read and write
clean
549F000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
1C8C000
unkown
page read and write
clean
58D0000
unkown
page read and write
clean
419000
heap default
page read and write
clean
5485000
unkown
page read and write
clean
29E4000
unkown
page read and write
clean
444000
heap private
page read and write
clean
2645000
heap private
page read and write
clean
26D000
heap private
page read and write
clean
58BE000
stack
page read and write
clean
5520000
unkown
page read and write
clean
2FE000
heap default
page read and write
clean
6F90000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
4FD5000
unkown
page read and write
clean
4C2000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
560000
heap private
page read and write
clean
4FD5000
unkown
page read and write
clean
21A0000
heap private
page read and write
clean
25E0000
unkown
page read and write
clean
2510000
unkown
page read and write
clean
6E801000
unkown image
page readonly
clean
4035000
unkown
page read and write
clean
5520000
unkown
page read and write
clean
5476000
unkown
page read and write
clean
42E0000
unkown
page read and write
clean
401E000
unkown
page read and write
clean
36D8000
unkown
page read and write
clean
2BA4000
heap private
page read and write
clean
35C0000
unkown
page read and write
clean
358D000
stack
page read and write
clean
1D60000
unkown
page read and write
clean
4FCB000
unkown
page read and write
clean
5520000
unkown
page read and write
clean
4FCC000
unkown
page read and write
clean
4D00000
unkown image
page readonly
clean
2A8C000
unkown
page read and write
clean
25F0000
unkown
page read and write
clean
5478000
unkown
page read and write
clean
2A38000
unkown
page read and write
clean
36B000
unkown
page read and write
clean
5A7E000
unkown
page read and write
clean
343F000
stack
page read and write
clean
336000
unkown
page read and write
clean
4DB000
unkown
page read and write
clean
340C000
unkown
page read and write
clean
2140000
heap private
page read and write
clean
2560000
unkown
page read and write
clean
4DB000
unkown
page read and write
clean
79BF000
stack
page read and write
clean
7EFE0000
unkown image
page readonly
clean
5A2C000
stack
page read and write
clean
484000
unkown
page read and write
clean
29E0000
heap private
page read and write
clean
5560000
heap private
page read and write
clean
413F000
stack
page read and write
clean
29D0000
unkown
page read and write
clean
340A000
unkown
page read and write
clean
2B2B000
unkown
page read and write
clean
31B000
unkown
page read and write
clean
2A88000
unkown
page read and write
clean
6F80000
unkown
page read and write
clean
1D53000
unkown
page read and write
clean
6FD2000
unkown image
page readonly
clean
33F0000
unkown
page read and write
clean
1E00000
unkown
page read and write
clean
5450000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7070000
unkown
page read and write
clean
377000
unkown
page read and write
clean
5920000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
42FA000
unkown
page read and write
clean
274000
heap default
page read and write
clean
1B00000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
4030000
unkown
page read and write
clean
337000
heap default
page read and write
clean
310000
unkown
page read and write
clean
32EF000
stack
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
5790000
unkown
page read and write
clean
1D50000
unkown
page read and write
clean
5BDA000
unkown
page read and write
clean
482000
unkown
page read and write
clean
3C0000
unkown image
page readonly
clean
2A19000
unkown
page read and write
clean
4560000
unkown image
page readonly
clean
58F0000
unkown
page read and write
clean
564000
heap private
page read and write
clean
2B21000
unkown
page read and write
clean
1CD0000
unkown
page read and write
clean
4010000
unkown
page read and write
clean
5E0000
unkown image
page readonly
clean
403B000
unkown
page read and write
clean
3480000
unkown
page read and write
clean
260000
unkown image
page read and write
clean
2A64000
unkown
page read and write
clean
21C0000
heap private
page read and write
clean
3720000
unkown
page read and write
clean
2B90000
unkown image
page readonly
clean
546D000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
3FB0000
unkown
page read and write
clean
1C9D000
unkown
page read and write
clean
218F000
heap private
page read and write
clean
328000
unkown
page read and write
clean
6F80000
unkown
page read and write
clean
4F70000
unkown
page read and write
clean
2C7000
heap default
page read and write
clean
10000
unkown image
page read and write
clean
311F000
stack
page read and write
clean
5474000
unkown
page read and write
clean
1E0000
unkown
page read and write
clean
466000
unkown
page read and write
clean
2010000
unkown image
page readonly
clean
260000
heap private
page read and write
clean
2190000
unkown
page read and write
clean
5A59000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
1E20000
heap private
page read and write
clean
3236000
unkown
page read and write
clean
2C20000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
4599000
heap private
page read and write
clean
548D000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
5520000
unkown
page read and write
clean
3490000
unkown
page read and write
clean
3410000
unkown image
page readonly
clean
3400000
heap private
page read and write
clean
4FE7000
unkown
page read and write
clean
29F8000
unkown
page read and write
clean
36D0000
unkown
page read and write
clean
2BA000
heap default
page read and write
clean
4BF000
unkown
page read and write
clean
6E531000
unkown image
page execute read
clean
7FFFFFB2000
unkown image
page readonly
clean
44C0000
heap private
page read and write
clean
7240000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
7676000
unkown
page read and write
clean
2120000
unkown
page read and write
clean
362000
unkown
page read and write
clean
21C5000
heap private
page read and write
clean
6CB0000
unkown
page read and write
clean
1D80000
unkown
page read and write
clean
1CE0000
unkown
page read and write
clean
150000
unkown
page read and write
clean
29D8000
unkown
page read and write
clean
2103000
unkown
page read and write
clean
5150000
heap private
page read and write
clean
2A00000
unkown
page read and write
clean
2A48000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
6E854000
unkown image
page read and write
clean
1C70000
unkown
page read and write
clean
4FE5000
unkown
page read and write
clean
2605000
heap private
page read and write
clean
340C000
unkown
page read and write
clean
1230000
unkown image
page readonly
clean
340C000
unkown
page read and write
clean
1D33000
unkown
page read and write
clean
250000
unkown image
page readonly
clean
546F000
unkown
page read and write
clean
1B70000
unkown
page read and write
clean
1F0000
unkown
page read and write
clean
2B23000
unkown
page read and write
clean
42BD000
stack
page read and write
clean
2A4C000
unkown
page read and write
clean
1C93000
unkown
page read and write
clean
3453000
unkown
page read and write
clean
2570000
unkown image
page readonly
clean
20F0000
unkown image
page readonly
clean
7789000
unkown
page read and write
clean
4C2000
unkown
page read and write
clean
2B29000
unkown
page read and write
clean
31DF000
stack
page read and write
clean
146000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
1CC0000
unkown image
page readonly
clean
5900000
unkown
page read and write
clean
2145000
heap private
page read and write
clean
3C3F000
stack
page read and write
clean
545F000
unkown
page read and write
clean
314E000
stack
page read and write
clean
42F2000
unkown
page read and write
clean
4BF000
unkown
page read and write
clean
1BA6000
unkown
page read and write
clean
2A08000
unkown
page read and write
clean
30B000
unkown
page read and write
clean
4FC8000
unkown
page read and write
clean
5080000
unkown image
page readonly
clean
53D0000
heap private
page read and write
clean
416000
heap default
page read and write
clean
2580000
unkown image
page readonly
clean
5590000
heap private
page read and write
clean
6F70000
unkown
page read and write
clean
34A000
unkown
page read and write
clean
21AB000
heap private
page read and write
clean
4FD5000
unkown
page read and write
clean
6FC3000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
5520000
unkown
page read and write
clean
420000
unkown
page read and write
clean
26A000
heap private
page read and write
clean
29F0000
unkown
page read and write
clean
2A14000
unkown
page read and write
clean
1C96000
unkown
page read and write
clean
5520000
unkown
page read and write
clean
364000
unkown
page read and write
clean
3470000
unkown
page read and write
clean
1C88000
unkown
page read and write
clean
4020000
unkown image
page readonly
clean
7741000
unkown
page read and write
clean
6DA0000
heap private
page read and write
clean
31E0000
unkown
page read and write
clean
2950000
unkown image
page readonly
clean
399F000
stack
page read and write
clean
1DA8000
unkown
page read and write
clean
21A4000
heap private
page read and write
clean
1D97000
unkown
page read and write
clean
1CF0000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
6E85F000
unkown image
page readonly
clean
455E000
stack
page read and write
clean
5AAB000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
5570000
unkown
page read and write
clean
6D90000
unkown image
page readonly
clean
29E8000
unkown
page read and write
clean
2A04000
unkown
page read and write
clean
4F66000
unkown
page read and write
clean
30C0000
unkown
page read and write
clean
186000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
4BF000
unkown
page read and write
clean
5783000
unkown
page read and write
clean
34A000
unkown
page read and write
clean
57A0000
unkown
page read and write
clean
6E85C000
unkown image
page read and write
clean
5290000
heap private
page read and write
clean
6C30000
heap private
page read and write
clean
410000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
4950000
unkown
page read and write
clean
2A3C000
unkown
page read and write
clean
545B000
unkown
page read and write
clean
264000
heap private
page read and write
clean
2BA0000
heap private
page read and write
clean
25C0000
unkown
page read and write
clean
21FB000
heap private
page read and write
clean
5471000
unkown
page read and write
clean
2A74000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
374000
unkown
page read and write
clean
7640000
unkown
page read and write
clean
4BD2000
unkown
page read and write
clean
35A0000
heap private
page read and write
clean
44C5000
heap private
page read and write
clean
5AEB000
unkown
page read and write
clean
3120000
unkown
page read and write
clean
1C9A000
unkown
page read and write
clean
2B25000
unkown
page read and write
clean
36E000
heap default
page read and write
clean
6CD0000
unkown
page read and write
clean
13C0000
unkown image
page readonly
clean
5467000
unkown
page read and write
clean
29DC000
unkown
page read and write
clean
54A7000
unkown
page read and write
clean
2100000
unkown
page read and write
clean
2140000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
4CEE000
stack
page read and write
clean
5A30000
unkown
page read and write
clean
3200000
unkown
page read and write
clean
3718000
unkown
page read and write
clean
2A29000
unkown
page read and write
clean
5C33000
unkown image
page read and write
clean
2AE5000
heap private
page read and write
clean
29F000
heap default
page read and write
clean
4FE7000
unkown
page read and write
clean
200000
heap default
page read and write
clean
1C81000
unkown
page read and write
clean
5267000
unkown image
page readonly
clean
4D10000
unkown
page read and write
clean
148000
unkown
page read and write
clean
4D8000
unkown
page read and write
clean
2FB0000
unkown
page read and write
clean
5640000
unkown
page read and write
clean
25D0000
unkown
page read and write
clean
54D8000
unkown
page read and write
clean
3FF0000
unkown
page read and write
clean
1D75000
unkown
page read and write
clean
42C0000
unkown
page read and write
clean
5C28000
unkown
page read and write
clean
5A42000
unkown
page read and write
clean
36E0000
unkown
page read and write
clean
7FEFF1A0000
unkown
page execute read
clean
328000
unkown
page read and write
clean
6BE2000
unkown image
page read and write
clean
4BE8000
unkown
page read and write
clean
5458000
unkown
page read and write
clean
4FF0000
heap private
page read and write
clean
7740000
unkown
page read and write
clean
3407000
heap private
page read and write
clean
4D69000
unkown
page read and write
clean
30D0000
unkown
page read and write
clean
479000
unkown
page read and write
clean
2609000
heap private
page read and write
clean
2130000
unkown
page read and write
clean
2A5C000
unkown
page read and write
clean
547F000
unkown
page read and write
clean
1DA0000
unkown
page read and write
clean
5460000
unkown
page read and write
clean
6CE0000
heap private
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
29F4000
unkown
page read and write
clean
3326000
unkown
page read and write
clean
267B000
heap private
page read and write
clean
6E84B000
unkown image
page read and write
clean
2A10000
unkown
page read and write
clean
403D000
unkown
page read and write
clean
4D60000
unkown
page read and write
clean
6D67000
unkown image
page read and write
clean
430000
unkown
page read and write
clean
2AE0000
heap private
page read and write
clean
400000
unkown image
page readonly
clean
2B1B000
heap private
page read and write
clean
2A60000
unkown
page read and write
clean
1DAE000
unkown
page read and write
clean
29EC000
unkown
page read and write
clean
25A0000
unkown
page read and write
clean
1D45000
heap private
page read and write
clean
4E80000
unkown
page read and write
clean
29CC000
unkown
page read and write
clean
30BE000
stack
page read and write
clean
5AB2000
unkown
page read and write
clean
5C2F000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
There are 535 hidden memdumps, click here to show them.