IOC Report

loading gif

Files

File Path
Type
Category
Malicious
Complaint details 143595.xlsb
Microsoft Excel 2007+
initial sample
malicious
C:\ProgramData\KBjfhfmoGRoN.rtf
HTML document, ASCII text, with very long lines, with CRLF line terminators
dropped
malicious
C:\Users\user\Desktop\~$Complaint details 143595.xlsb
data
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\E2AB5816.png
PNG image data, 960 x 510, 8-bit/color RGBA, non-interlaced
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /automation -Embedding
malicious
C:\Windows\System32\wbem\WMIC.exe
wmic process call create "mshta C:\ProgramData\KBjfhfmoGRoN.rtf"
malicious
C:\Windows\System32\mshta.exe
mshta C:\ProgramData\KBjfhfmoGRoN.rtf
clean

URLs

Name
IP
Malicious
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://www.%s.comPA
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://servername/isapibackend.dll
unknown
clean
http://investor.msn.com/
unknown
clean
There are 1 hidden URLs, click here to show them.

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
)i(
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
MTTT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\2F0D4
2F0D4
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
r(
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
EXCELFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
There are 3 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
77F4000
unkown
page read and write
clean
2DA7000
unkown
page read and write
clean
6E84F000
unkown image
page readonly
clean
32CF000
stack
page read and write
clean
4875000
unkown
page read and write
clean
228C000
unkown
page read and write
clean
5760000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
37CD000
stack
page read and write
clean
3B39000
heap private
page read and write
clean
7360000
unkown
page read and write
clean
1CE0000
unkown
page read and write
clean
3570000
unkown
page read and write
clean
3120000
unkown
page read and write
clean
7B40000
unkown
page read and write
clean
2130000
unkown image
page readonly
clean
2DA3000
unkown
page read and write
clean
45B0000
heap private
page read and write
clean
376000
unkown
page read and write
clean
35B000
heap private
page read and write
clean
1F7C000
unkown
page read and write
clean
F0000
unkown
page read and write
clean
36F000
heap private
page read and write
clean
7B51000
unkown
page read and write
clean
3190000
unkown
page read and write
clean
3BE000
heap default
page read and write
clean
20000
unkown image
page readonly
clean
42C000
heap default
page read and write
clean
5710000
unkown
page read and write
clean
3335000
heap private
page read and write
clean
266000
unkown
page read and write
clean
70BF000
stack
page read and write
clean
7D0000
unkown image
page readonly
clean
6E521000
unkown image
page execute read
clean
3870000
unkown
page read and write
clean
3155000
unkown
page read and write
clean
36C0000
unkown
page read and write
clean
4DB0000
unkown
page read and write
clean
2DA6000
unkown
page read and write
clean
5640000
unkown
page read and write
clean
41D0000
unkown
page read and write
clean
5940000
unkown
page read and write
clean
1F70000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
3340000
unkown
page read and write
clean
2280000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
3550000
unkown
page read and write
clean
42F2000
unkown
page read and write
clean
2250000
unkown
page read and write
clean
1CD0000
unkown
page read and write
clean
31A4000
heap private
page read and write
clean
788B000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7A51000
unkown
page read and write
clean
485F000
unkown
page read and write
clean
37F2000
unkown
page read and write
clean
4879000
unkown
page read and write
clean
438000
unkown
page read and write
clean
5025000
unkown
page read and write
clean
2020000
unkown
page read and write
clean
87000
heap default
page read and write
clean
474000
unkown
page read and write
clean
3B0000
heap private
page read and write
clean
2DAC000
unkown
page read and write
clean
28CF000
stack
page read and write
clean
E0000
unkown image
page read and write
clean
42B000
unkown
page read and write
clean
36B9000
unkown
page read and write
clean
56F0000
unkown
page read and write
clean
270F000
stack
page read and write
clean
3318000
unkown
page read and write
clean
22B0000
heap private
page read and write
clean
40E000
heap default
page read and write
clean
22B5000
heap private
page read and write
clean
44A0000
unkown image
page readonly
clean
4A27000
unkown
page read and write
clean
2600000
unkown
page read and write
clean
1F00000
unkown image
page read and write
clean
54C0000
unkown
page read and write
clean
45F000
unkown
page read and write
clean
54F0000
unkown
page read and write
clean
320000
heap private
page read and write
clean
1CC3000
unkown
page read and write
clean
1D00000
unkown
page read and write
clean
31B0000
unkown
page read and write
clean
36BD000
unkown
page read and write
clean
325000
heap private
page read and write
clean
5BA2000
unkown
page read and write
clean
3350000
unkown
page read and write
clean
6E844000
unkown image
page read and write
clean
32A5000
heap private
page read and write
clean
4D3D000
stack
page read and write
clean
5B2B000
unkown
page read and write
clean
3460000
unkown
page read and write
clean
2004000
unkown
page read and write
clean
5035000
unkown
page read and write
clean
37F7000
unkown
page read and write
clean
2DA9000
unkown
page read and write
clean
32E8000
unkown
page read and write
clean
5025000
unkown
page read and write
clean
1DB6000
unkown
page read and write
clean
38B000
heap private
page read and write
clean
4D90000
unkown
page read and write
clean
79D2000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
32F0000
unkown
page read and write
clean
2014000
unkown
page read and write
clean
3560000
unkown
page read and write
clean
335000
unkown
page read and write
clean
3CB000
unkown
page read and write
clean
3300000
unkown
page read and write
clean
1D70000
heap private
page read and write
clean
5CDF000
unkown
page read and write
clean
3496000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
6E84C000
unkown image
page read and write
clean
26E000
unkown
page read and write
clean
51A000
heap private
page read and write
clean
3890000
heap private
page read and write
clean
5037000
unkown
page read and write
clean
37FA000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
31C0000
unkown
page read and write
clean
1D80000
unkown
page read and write
clean
4C30000
unkown
page read and write
clean
2770000
heap private
page read and write
clean
45D000
unkown
page read and write
clean
20D0000
unkown image
page readonly
clean
5930000
unkown
page read and write
clean
1FDC000
unkown
page read and write
clean
1D03000
unkown
page read and write
clean
32A0000
heap private
page read and write
clean
3B2000
unkown
page read and write
clean
336B000
heap private
page read and write
clean
100000
unkown image
page readonly
clean
2C0000
unkown
page read and write
clean
5025000
unkown
page read and write
clean
37D0000
unkown
page read and write
clean
5B90000
unkown
page read and write
clean
133000
unkown
page read and write
clean
45A000
unkown
page read and write
clean
1FEC000
unkown
page read and write
clean
5940000
unkown
page read and write
clean
5018000
unkown
page read and write
clean
2230000
unkown image
page readonly
clean
54FC000
unkown
page read and write
clean
710000
unkown image
page readonly
clean
7A40000
unkown
page read and write
clean
2A0000
unkown
page read and write
clean
59A5000
heap private
page read and write
clean
20C0000
heap private
page read and write
clean
BE000
heap default
page read and write
clean
4710000
heap private
page read and write
clean
40000
unkown image
page readonly
clean
5510000
unkown
page read and write
clean
42EF000
stack
page read and write
clean
1BF0000
unkown image
page readonly
clean
2010000
unkown
page read and write
clean
1E0000
unkown
page read and write
clean
49D0000
unkown
page read and write
clean
1FB4000
unkown
page read and write
clean
32D0000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
5BE3000
unkown
page read and write
clean
7AA7000
unkown
page read and write
clean
3800000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
3D0000
heap default
page read and write
clean
5640000
unkown
page read and write
clean
5730000
unkown
page read and write
clean
2000000
unkown
page read and write
clean
7A6B000
unkown
page read and write
clean
580000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
22C0000
heap private
page read and write
clean
438000
unkown
page read and write
clean
28F0000
heap private
page read and write
clean
2ABE000
stack
page read and write
clean
78AA000
unkown
page read and write
clean
290000
unkown image
page readonly
clean
5B52000
unkown
page read and write
clean
5D23000
unkown image
page read and write
clean
4870000
unkown
page read and write
clean
4D80000
unkown
page read and write
clean
431000
heap default
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
6E7F1000
unkown image
page readonly
clean
3B2000
unkown
page read and write
clean
36BB000
unkown
page read and write
clean
2B0000
unkown
page read and write
clean
51D000
heap private
page read and write
clean
1FFC000
unkown
page read and write
clean
1CF0000
unkown
page read and write
clean
7FEFF1A0000
unkown
page execute read
clean
3B2000
unkown
page read and write
clean
45A000
unkown
page read and write
clean
320000
unkown
page read and write
clean
52EF000
stack
page read and write
clean
2240000
unkown
page read and write
clean
387000
heap default
page read and write
clean
1F84000
unkown
page read and write
clean
2EBF000
stack
page read and write
clean
415D000
unkown
page read and write
clean
56F0000
unkown
page read and write
clean
514000
heap private
page read and write
clean
5650000
unkown
page read and write
clean
2760000
unkown image
page read and write
clean
650000
unkown image
page readonly
clean
3AF000
unkown
page read and write
clean
2D20000
heap private
page read and write
clean
45F000
unkown
page read and write
clean
950000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
45F000
unkown
page read and write
clean
3B4000
heap private
page read and write
clean
7A43000
unkown
page read and write
clean
37E0000
unkown
page read and write
clean
3320000
unkown
page read and write
clean
303000
unkown
page read and write
clean
4960000
heap private
page read and write
clean
4B10000
heap private
page read and write
clean
785B000
unkown
page read and write
clean
5670000
heap private
page read and write
clean
141000
unkown
page read and write
clean
4890000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
26CF000
stack
page read and write
clean
77F2000
unkown
page read and write
clean
7B00000
unkown
page read and write
clean
1DA000
unkown
page read and write
clean
420000
unkown
page read and write
clean
700000
unkown image
page readonly
clean
2210000
unkown
page read and write
clean
D0000
unkown image
page readonly
clean
5770000
unkown
page read and write
clean
7AA1000
unkown
page read and write
clean
370000
unkown
page read and write
clean
2008000
unkown
page read and write
clean
1CB0000
unkown image
page readonly
clean
510000
heap private
page read and write
clean
5B20000
unkown
page read and write
clean
5B1E000
stack
page read and write
clean
110000
unkown
page read and write
clean
1D75000
heap private
page read and write
clean
5035000
unkown
page read and write
clean
228A000
unkown
page read and write
clean
3B30000
heap private
page read and write
clean
587E000
stack
page read and write
clean
35A8000
unkown
page read and write
clean
3170000
unkown image
page readonly
clean
5B3B000
unkown
page read and write
clean
6DD0000
heap private
page read and write
clean
26E0000
heap private
page read and write
clean
3B3000
unkown
page read and write
clean
480000
unkown
page read and write
clean
7976000
unkown
page read and write
clean
660000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
2D0000
unkown
page read and write
clean
5019000
unkown
page read and write
clean
384000
heap private
page read and write
clean
3B2000
unkown
page read and write
clean
484000
unkown
page read and write
clean
2E0000
unkown
page read and write
clean
2740000
unkown
page read and write
clean
350000
heap private
page read and write
clean
1FE8000
unkown
page read and write
clean
1F80000
unkown
page read and write
clean
3860000
unkown
page read and write
clean
438000
unkown
page read and write
clean
5640000
unkown
page read and write
clean
80000
heap default
page read and write
clean
5520000
unkown
page read and write
clean
5037000
unkown
page read and write
clean
8A0000
unkown image
page readonly
clean
5650000
unkown
page read and write
clean
42E000
heap default
page read and write
clean
356000
unkown
page read and write
clean
22EB000
heap private
page read and write
clean
D0000
unkown image
page readonly
clean
4388000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
5660000
unkown
page read and write
clean
65300000
unkown image
page readonly
clean
36B0000
unkown
page read and write
clean
1EF0000
unkown image
page readonly
clean
3580000
unkown
page read and write
clean
45D000
unkown
page read and write
clean
310000
unkown
page read and write
clean
2260000
unkown
page read and write
clean
7ADD000
unkown
page read and write
clean
3CB000
unkown
page read and write
clean
3C8000
unkown
page read and write
clean
3170000
unkown
page read and write
clean
24F0000
heap private
page read and write
clean
7928000
unkown
page read and write
clean
F0000
unkown
page read and write
clean
487C000
unkown
page read and write
clean
2020000
heap private
page read and write
clean
6312000
unkown image
page read and write
clean
316000
unkown
page read and write
clean
7B60000
unkown
page read and write
clean
486B000
unkown
page read and write
clean
2750000
unkown image
page readonly
clean
50D0000
unkown image
page readonly
clean
2730000
unkown
page read and write
clean
5720000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
5760000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
1F98000
unkown
page read and write
clean
4861000
unkown
page read and write
clean
5640000
unkown
page read and write
clean
5039000
unkown
page read and write
clean
5025000
unkown
page read and write
clean
1FC9000
unkown
page read and write
clean
1F78000
unkown
page read and write
clean
2024000
unkown
page read and write
clean
5035000
unkown
page read and write
clean
35A0000
unkown
page read and write
clean
345F000
stack
page read and write
clean
20000
unkown image
page read and write
clean
3AD000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
4883000
unkown
page read and write
clean
148000
heap default
page read and write
clean
380000
heap private
page read and write
clean
7254000
heap private
page read and write
clean
7250000
heap private
page read and write
clean
2B7F000
stack
page read and write
clean
2220000
unkown image
page readonly
clean
7906000
unkown
page read and write
clean
2DA4000
unkown
page read and write
clean
563C000
stack
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
2570000
unkown image
page readonly
clean
4110000
unkown
page read and write
clean
1CC0000
unkown
page read and write
clean
1FB0000
unkown
page read and write
clean
4877000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
3650000
unkown image
page readonly
clean
228C000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
473000
unkown
page read and write
clean
3590000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
316F000
stack
page read and write
clean
45B5000
heap private
page read and write
clean
79D4000
unkown
page read and write
clean
2270000
unkown
page read and write
clean
1FE0000
unkown
page read and write
clean
2720000
unkown
page read and write
clean
1D50000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
32E0000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
4A20000
unkown
page read and write
clean
2DA0000
unkown
page read and write
clean
4ED0000
unkown
page read and write
clean
13E000
unkown
page read and write
clean
2DA1000
unkown
page read and write
clean
5640000
unkown
page read and write
clean
354000
heap private
page read and write
clean
228C000
unkown
page read and write
clean
271E000
stack
page read and write
clean
456000
heap default
page read and write
clean
78FD000
unkown
page read and write
clean
3D7000
heap default
page read and write
clean
438000
unkown
page read and write
clean
5640000
unkown
page read and write
clean
6EF0000
heap private
page read and write
clean
7EFE0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
359E000
unkown
page read and write
clean
45D000
unkown
page read and write
clean
1F90000
unkown
page read and write
clean
5938000
unkown
page read and write
clean
2290000
unkown
page read and write
clean
2710000
unkown
page read and write
clean
4188000
unkown
page read and write
clean
7863000
unkown
page read and write
clean
36B2000
unkown
page read and write
clean
1FAC000
unkown
page read and write
clean
300000
unkown image
page read and write
clean
2B30000
heap private
page read and write
clean
22FB000
heap private
page read and write
clean
3357000
unkown image
page readonly
clean
3AF000
unkown
page read and write
clean
228C000
unkown
page read and write
clean
31A0000
heap private
page read and write
clean
396000
unkown
page read and write
clean
5960000
unkown
page read and write
clean
372000
unkown
page read and write
clean
4FD0000
unkown
page read and write
clean
5CDF000
unkown
page read and write
clean
3140000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
300000
unkown
page read and write
clean
1FA4000
unkown
page read and write
clean
6E520000
unkown image
page readonly
clean
4890000
unkown
page read and write
clean
1FD0000
unkown
page read and write
clean
4FE0000
unkown
page read and write
clean
47D0000
heap private
page read and write
clean
7AE6000
unkown
page read and write
clean
4B6000
unkown
page read and write
clean
5950000
unkown
page read and write
clean
4863000
unkown
page read and write
clean
4850000
unkown
page read and write
clean
5740000
unkown
page read and write
clean
281E000
stack
page read and write
clean
6E83B000
unkown image
page read and write
clean
2718000
unkown
page read and write
clean
2210000
unkown image
page readonly
clean
367000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
216000
unkown
page read and write
clean
7B08000
unkown
page read and write
clean
5510000
unkown
page read and write
clean
1F68000
unkown
page read and write
clean
7A80000
unkown
page read and write
clean
1F8F000
stack
page read and write
clean
5D05000
unkown
page read and write
clean
E0000
unkown
page read and write
clean
313000
unkown
page read and write
clean
1CAE000
unkown
page read and write
clean
41B000
unkown
page read and write
clean
2775000
heap private
page read and write
clean
2DA2000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
6E848000
unkown image
page write copy
clean
20A0000
unkown image
page readonly
clean
36B5000
unkown
page read and write
clean
5B77000
unkown
page read and write
clean
378000
unkown
page read and write
clean
48A0000
unkown
page read and write
clean
59A0000
heap private
page read and write
clean
45A000
unkown
page read and write
clean
366000
heap private
page read and write
clean
36AE000
stack
page read and write
clean
52B7000
unkown image
page readonly
clean
1FD8000
unkown
page read and write
clean
6702000
unkown image
page readonly
clean
44A000
heap default
page read and write
clean
4D0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
5038000
unkown
page read and write
clean
1CE4000
unkown
page read and write
clean
3AF000
unkown
page read and write
clean
340000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
5700000
unkown
page read and write
clean
37FE000
unkown
page read and write
clean
4A29000
unkown
page read and write
clean
22C5000
heap private
page read and write
clean
42A000
unkown
page read and write
clean
3B35000
heap private
page read and write
clean
1FA0000
heap private
page read and write
clean
3330000
heap private
page read and write
clean
3CB000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
120000
unkown
page read and write
clean
4858000
unkown
page read and write
clean
5025000
unkown
page read and write
clean
22A0000
unkown
page read and write
clean
1F88000
unkown
page read and write
clean
7A3B000
unkown
page read and write
clean
7A8A000
unkown
page read and write
clean
1F6C000
unkown
page read and write
clean
16D000
heap default
page read and write
clean
5640000
unkown
page read and write
clean
2DAA000
unkown
page read and write
clean
180000
unkown
page read and write
clean
5750000
unkown
page read and write
clean
3180000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
4873000
unkown
page read and write
clean
1FB9000
unkown
page read and write
clean
7100000
heap private
page read and write
clean
1F20000
unkown
page read and write
clean
3F4000
heap default
page read and write
clean
501B000
unkown
page read and write
clean
380B000
unkown
page read and write
clean
37E000
unkown
page read and write
clean
3330000
unkown
page read and write
clean
5640000
unkown
page read and write
clean
331000
unkown
page read and write
clean
4889000
unkown
page read and write
clean
488B000
unkown
page read and write
clean
264000
unkown
page read and write
clean
268000
unkown
page read and write
clean
72E0000
heap private
page read and write
clean
31D6000
unkown
page read and write
clean
429000
unkown
page read and write
clean
369000
unkown
page read and write
clean
960000
unkown image
page readonly
clean
2779000
heap private
page read and write
clean
160000
unkown
page read and write
clean
21B0000
unkown
page read and write
clean
20B4000
heap private
page read and write
clean
3AB0000
heap private
page read and write
clean
5502000
unkown
page read and write
clean
1FA8000
unkown
page read and write
clean
2287000
heap private
page read and write
clean
4D30000
heap private
page read and write
clean
380000
heap default
page read and write
clean
122000
heap default
page read and write
clean
29FD000
stack
page read and write
clean
5640000
unkown
page read and write
clean
2DAB000
unkown
page read and write
clean
2DA5000
unkown
page read and write
clean
78C7000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
1F8C000
unkown
page read and write
clean
2DA8000
unkown
page read and write
clean
5BA6000
unkown
page read and write
clean
5640000
unkown
page read and write
clean
1F94000
unkown
page read and write
clean
AF0000
unkown image
page readonly
clean
320000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
4300000
heap private
page execute and read and write
clean
3810000
unkown
page read and write
clean
428000
unkown
page read and write
clean
20B0000
heap private
page read and write
clean
7940000
unkown
page read and write
clean
49C0000
unkown image
page readonly
clean
487000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
5036000
unkown
page read and write
clean
1FA0000
unkown
page read and write
clean
5038000
unkown
page read and write
clean
31A0000
unkown
page read and write
clean
58B0000
heap private
page read and write
clean
3CB000
unkown
page read and write
clean
3153000
unkown
page read and write
clean
502D000
unkown
page read and write
clean
37F5000
unkown
page read and write
clean
449E000
stack
page read and write
clean
7B60000
unkown
page read and write
clean
There are 537 hidden memdumps, click here to show them.