Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
sin t#U00edtulo_0212.xlsm
|
Microsoft Excel 2007+
|
initial sample
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\Z8LJs4fFM8[1].dll
|
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
|
downloaded
|
||
C:\Users\user\Desktop\~$sin t#U00edtulo_0212.xlsm
|
data
|
dropped
|
||
C:\Users\user\besta.ocx
|
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\30817388.png
|
PNG image data, 1714 x 241, 8-bit colormap, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\CC15.tmp
|
Composite Document File V2 Document, Cannot read section info
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\~DF20EA52A1DD92E798.TMP
|
data
|
dropped
|
||
C:\Windows\SysWOW64\Nrenernv\nnave.jwm (copy)
|
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|
"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /automation -Embedding
|
||
C:\Windows\SysWOW64\rundll32.exe
|
C:\Windows\SysWow64\rundll32.exe ..\besta.ocx,44532.8898178241
|
||
C:\Windows\SysWOW64\rundll32.exe
|
C:\Windows\SysWOW64\rundll32.exe "C:\Users\user\besta.ocx",DllRegisterServer
|
||
C:\Windows\SysWOW64\rundll32.exe
|
C:\Windows\SysWOW64\rundll32.exe "C:\Windows\SysWOW64\Nrenernv\nnave.jwm",ILDADvMws
|
||
C:\Windows\System32\svchost.exe
|
C:\Windows\System32\svchost.exe -k WerSvcGroup
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://www.duoyuhudong.cn/wp-content/we8xi/ooC:
|
unknown
|
||
http://www.duoyuhudong.cn/wp-content/we8xi/T
|
unknown
|
||
http://www.duoyuhudong.cn/wp-content/we8xi/R
|
unknown
|
||
http://www.duoyuhudong.cn/wp-content/we8xi/
|
47.96.4.95
|
||
http://www.windows.com/pctv.
|
unknown
|
||
http://investor.msn.com
|
unknown
|
||
http://www.msnbc.com/news/ticker.txt
|
unknown
|
||
http://schemas.openformatrg/drawml/2006/spreadsheetD
|
unknown
|
||
http://sadabahar.com.np/wp-includes/pUM)http://sadabahar.com.np/wp-includes/pUMqI
|
unknown
|
||
http://schemas.openformatrg/package/2006/content-t
|
unknown
|
||
http://sadabahar.com.np/wp-inclu
|
unknown
|
||
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
|
unknown
|
||
http://www.hotmail.com/oe
|
unknown
|
||
http://sadabahar.com.np/wp-i
|
unknown
|
||
http://schemas.open
|
unknown
|
||
http://sadabahar.com.n
|
unknown
|
||
http://sadabahar.c
|
unknown
|
||
http://sadabahar.com
|
unknown
|
||
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
|
unknown
|
||
http://sadabahar.co
|
unknown
|
||
http://www.icra.org/vocabulary/.
|
unknown
|
||
http://sadabahar.com.np/wp-includes/pUMqITC-http://sadabahar.com.np/wp-includes/pUMqITCt8/http://sad
|
unknown
|
||
http://schemas.openformatrg/package/2006/r
|
unknown
|
||
http://investor.msn.com/
|
unknown
|
||
http://sadabahar.com.np/wp-includes/pUMqITCt83a/
|
194.233.67.242
|
||
http://sadabahar.com.np/w
|
unknown
|
||
http://sadabahar.com.np/wp-inc
|
unknown
|
||
http://sadabahar.com.np/wp-include%http://sadabahar.com.np/wp-includes/p
|
unknown
|
There are 18 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
www.duoyuhudong.cn
|
47.96.4.95
|
||
sadabahar.com.np
|
194.233.67.242
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
47.96.4.95
|
www.duoyuhudong.cn
|
China
|
||
194.233.67.242
|
sadabahar.com.np
|
Germany
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
|
+%-
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
|
MTTT
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
|
ReviewToken
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\2DD64
|
2DD64
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
|
VBAFiles
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
|
/3-
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
|
LastPurgeTime
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
|
Max Display
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Max Display
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 1
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 2
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 3
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 4
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 5
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 6
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 7
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 8
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 9
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 10
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 11
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 12
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 13
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 14
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 15
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 16
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 17
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 18
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 19
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 20
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\3D5A7
|
3D5A7
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
|
Max Display
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Max Display
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 1
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 2
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 3
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 4
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 5
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 6
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 7
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 8
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 9
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 10
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 11
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 12
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 13
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 14
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 15
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 16
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 17
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 18
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 19
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
|
Item 20
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\3E070
|
3E070
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
|
1033
|
||
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
|
1033
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
|
EXCELFiles
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
|
ProductFiles
|
||
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
|
SavedLegacySettings
|
There are 48 hidden registries, click here to show them.
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
210000
|
heap default
|
page read and write
|
||
7425000
|
unkown
|
page read and write
|
||
7EFD0000
|
unkown image
|
page readonly
|
||
7FFFFFB2000
|
unkown image
|
page readonly
|
||
143000
|
unkown
|
page read and write
|
||
1DA0000
|
unkown
|
page read and write
|
||
CC000
|
unkown
|
page read and write
|
||
7EFD0000
|
unkown image
|
page readonly
|
||
7EFC2000
|
unkown image
|
page readonly
|
||
50000
|
unkown image
|
page readonly
|
||
598A000
|
unkown
|
page read and write
|
||
5372000
|
unkown
|
page read and write
|
||
41C0000
|
unkown
|
page read and write
|
||
72B0000
|
unkown
|
page read and write
|
||
460000
|
unkown
|
page read and write
|
||
5500000
|
unkown
|
page read and write
|
||
59D9000
|
unkown
|
page read and write
|
||
7720000
|
unkown
|
page read and write
|
||
7EFC2000
|
unkown image
|
page readonly
|
||
3B0000
|
unkown
|
page read and write
|
||
7290000
|
unkown
|
page read and write
|
||
4F90000
|
unkown image
|
page readonly
|
||
7B78000
|
stack
|
page read and write
|
||
342B000
|
unkown
|
page read and write
|
||
7EFDF000
|
unkown
|
page read and write
|
||
7EFB0000
|
unkown image
|
page readonly
|
||
7EFB0000
|
unkown image
|
page readonly
|
||
7EFB2000
|
unkown image
|
page readonly
|
||
598F000
|
unkown
|
page read and write
|
||
41FA000
|
unkown
|
page read and write
|
||
204D000
|
unkown
|
page read and write
|
||
7B30000
|
stack
|
page read and write
|
||
6C22000
|
unkown
|
page read and write
|
||
7EFB0000
|
unkown image
|
page readonly
|
||
54F0000
|
unkown
|
page read and write
|
||
59B6000
|
unkown
|
page read and write
|
||
7EFC2000
|
unkown image
|
page readonly
|
||
7EFD0000
|
unkown image
|
page readonly
|
||
4E78000
|
unkown
|
page read and write
|
||
200000
|
heap private
|
page read and write
|
||
51E000
|
stack
|
page read and write
|
||
7290000
|
unkown
|
page read and write
|
||
5AC0000
|
unkown image
|
page read and write
|
||
6E441000
|
unkown image
|
page execute read
|
||
7570000
|
unkown image
|
page readonly
|
||
76D0000
|
unkown
|
page read and write
|
||
72F0000
|
unkown
|
page read and write
|
||
7710000
|
unkown
|
page read and write
|
||
7EFC0000
|
unkown image
|
page readonly
|
||
3020000
|
unkown image
|
page readonly
|
||
7FFFFFB0000
|
unkown image
|
page readonly
|
||
20000
|
unkown image
|
page readonly
|
||
4EDF000
|
unkown
|
page read and write
|
||
72A0000
|
unkown
|
page read and write
|
||
7EFB0000
|
unkown image
|
page readonly
|
||
33F0000
|
unkown image
|
page readonly
|
||
7EFC2000
|
unkown image
|
page readonly
|
||
6E48E000
|
unkown image
|
page readonly
|
||
54F0000
|
unkown
|
page read and write
|
||
7EFC0000
|
unkown image
|
page readonly
|
||
7B30000
|
stack
|
page read and write
|
||
410000
|
heap private
|
page read and write
|
||
7B78000
|
stack
|
page read and write
|
||
7FFFFFB2000
|
unkown image
|
page readonly
|
||
2600000
|
heap private
|
page read and write
|
||
590F000
|
unkown
|
page read and write
|
||
73F3000
|
unkown
|
page read and write
|
||
3F70000
|
unkown
|
page read and write
|
||
6E48E000
|
unkown image
|
page readonly
|
||
6AD000
|
heap default
|
page read and write
|
||
7290000
|
unkown
|
page read and write
|
||
144000
|
unkown
|
page read and write
|
||
2D0000
|
unkown
|
page read and write
|
||
4EDD000
|
unkown
|
page read and write
|
||
360000
|
unkown
|
page read and write
|
||
7B95000
|
stack
|
page read and write
|
||
A50000
|
heap private
|
page read and write
|
||
7EFD0000
|
unkown image
|
page readonly
|
||
7EFB2000
|
unkown image
|
page readonly
|
||
33D0000
|
unkown
|
page read and write
|
||
6AF7000
|
unkown
|
page read and write
|
||
797D000
|
unkown
|
page read and write
|
||
60000
|
unkown image
|
page readonly
|
||
4C8E000
|
stack
|
page read and write
|
||
24E0000
|
unkown
|
page read and write
|
||
316000
|
unkown
|
page read and write
|
||
3427000
|
heap private
|
page read and write
|
||
3F00000
|
unkown
|
page read and write
|
||
7860000
|
unkown
|
page read and write
|
||
D0000
|
unkown image
|
page readonly
|
||
4B20000
|
unkown
|
page read and write
|
||
900000
|
unkown image
|
page readonly
|
||
670000
|
unkown image
|
page readonly
|
||
7FFFFFC0000
|
unkown image
|
page readonly
|
||
48F000
|
stack
|
page read and write
|
||
7410000
|
unkown
|
page read and write
|
||
7EFB0000
|
unkown image
|
page readonly
|
||
2120000
|
unkown image
|
page readonly
|
||
7B50000
|
stack
|
page read and write
|
||
54F0000
|
unkown
|
page read and write
|
||
7860000
|
unkown
|
page read and write
|
||
1CD6000
|
unkown
|
page read and write
|
||
7B78000
|
stack
|
page read and write
|
||
72A0000
|
unkown
|
page read and write
|
||
7FFFFFC2000
|
unkown image
|
page readonly
|
||
72A0000
|
unkown
|
page read and write
|
||
3FA0000
|
heap private
|
page read and write
|
||
7EFB0000
|
unkown image
|
page readonly
|
||
54F0000
|
unkown
|
page read and write
|
||
7B9F000
|
stack
|
page read and write
|
||
50000
|
unkown image
|
page readonly
|
||
40E0000
|
unkown
|
page read and write
|
||
3FA4000
|
heap private
|
page read and write
|
||
41FE000
|
unkown
|
page read and write
|
||
41E0000
|
unkown
|
page read and write
|
||
7EFC2000
|
unkown image
|
page readonly
|
||
7830000
|
unkown
|
page read and write
|
||
5918000
|
unkown
|
page read and write
|
||
7B30000
|
stack
|
page read and write
|
||
72E0000
|
unkown
|
page read and write
|
||
7B30000
|
stack
|
page read and write
|
||
7890000
|
unkown
|
page read and write
|
||
20000
|
unkown image
|
page readonly
|
||
7EFE0000
|
unkown image
|
page readonly
|
||
7EFC2000
|
unkown image
|
page readonly
|
||
30000
|
unkown image
|
page read and write
|
||
3F10000
|
unkown
|
page read and write
|
||
7304000
|
unkown
|
page read and write
|
||
7860000
|
unkown
|
page read and write
|
||
8280000
|
unkown
|
page read and write
|
||
700000
|
unkown image
|
page readonly
|
||
4847000
|
unkown
|
page read and write
|
||
6E550000
|
unkown image
|
page readonly
|
||
E0000
|
unkown
|
page read and write
|
||
166000
|
unkown
|
page read and write
|
||
7EFC0000
|
unkown image
|
page readonly
|
||
2064000
|
unkown
|
page read and write
|
||
2A0000
|
heap private
|
page read and write
|
||
7446000
|
unkown
|
page read and write
|
||
6E479000
|
unkown image
|
page readonly
|
||
32A0000
|
unkown
|
page read and write
|
||
1A3000
|
unkown
|
page execute and read and write
|
||
50000
|
unkown image
|
page readonly
|
||
2069000
|
unkown
|
page read and write
|
||
76D0000
|
unkown
|
page read and write
|
||
480000
|
heap default
|
page read and write
|
||
59A5000
|
unkown
|
page read and write
|
||
7EFC2000
|
unkown image
|
page readonly
|
||
7EFB2000
|
unkown image
|
page readonly
|
||
6CC6000
|
unkown
|
page read and write
|
||
1E0000
|
heap default
|
page read and write
|
||
7B30000
|
stack
|
page read and write
|
||
433000
|
unkown
|
page read and write
|
||
770000
|
unkown image
|
page readonly
|
||
7554000
|
unkown image
|
page readonly
|
||
59A5000
|
unkown
|
page read and write
|
||
42E000
|
unkown
|
page read and write
|
||
23E0000
|
heap private
|
page read and write
|
||
7830000
|
unkown
|
page read and write
|
||
60000
|
unkown image
|
page readonly
|
||
4EDA000
|
unkown
|
page read and write
|
||
7EFD0000
|
unkown image
|
page readonly
|
||
3DD5000
|
unkown
|
page read and write
|
||
4EF0000
|
unkown
|
page read and write
|
||
3FC0000
|
unkown
|
page read and write
|
||
7840000
|
unkown
|
page read and write
|
||
4EF1000
|
unkown
|
page read and write
|
||
2FB0000
|
unkown
|
page read and write
|
||
170000
|
unkown image
|
page readonly
|
||
40F0000
|
unkown
|
page read and write
|
||
2060000
|
unkown
|
page read and write
|
||
7360000
|
unkown
|
page read and write
|
||
400000
|
heap default
|
page read and write
|
||
154000
|
unkown
|
page read and write
|
||
74B0000
|
unkown
|
page read and write
|
||
10000
|
unkown image
|
page read and write
|
||
6CC8000
|
unkown
|
page read and write
|
||
7EFE0000
|
unkown image
|
page readonly
|
||
3F60000
|
unkown
|
page read and write
|
||
7EFD0000
|
unkown image
|
page readonly
|
||
660000
|
unkown image
|
page readonly
|
||
7B30000
|
stack
|
page read and write
|
||
116000
|
unkown
|
page read and write
|
||
7EFB2000
|
unkown image
|
page readonly
|
||
78C0000
|
heap private
|
page read and write
|
||
751D000
|
unkown
|
page read and write
|
||
6E87F000
|
unkown image
|
page readonly
|
||
90000
|
unkown
|
page read and write
|
||
7FFFFFC0000
|
unkown image
|
page readonly
|
||
50000
|
unkown image
|
page readonly
|
||
79E0000
|
unkown
|
page read and write
|
||
797C000
|
unkown
|
page read and write
|
||
5380000
|
unkown
|
page read and write
|
||
595D000
|
unkown
|
page read and write
|
||
4B10000
|
unkown
|
page read and write
|
||
4BE000
|
heap default
|
page read and write
|
||
548E000
|
stack
|
page read and write
|
||
73C4000
|
unkown
|
page read and write
|
||
420F000
|
unkown
|
page read and write
|
||
2500000
|
heap private
|
page read and write
|
||
7EFD0000
|
unkown image
|
page readonly
|
||
3010000
|
unkown
|
page read and write
|
||
7720000
|
unkown
|
page read and write
|
||
1EA0000
|
unkown image
|
page readonly
|
||
7370000
|
unkown
|
page read and write
|
||
419E000
|
unkown
|
page read and write
|
||
1CA0000
|
unkown
|
page read and write
|
||
3F40000
|
unkown
|
page read and write
|
||
2030000
|
unkown
|
page read and write
|
||
54F0000
|
unkown
|
page read and write
|
||
7850000
|
unkown
|
page read and write
|
||
72B0000
|
unkown
|
page read and write
|
||
7EFB0000
|
unkown image
|
page readonly
|
||
50000
|
unkown image
|
page readonly
|
||
55B5000
|
heap private
|
page read and write
|
||
7EFB0000
|
unkown image
|
page readonly
|
||
7590000
|
unkown image
|
page read and write
|
||
5388000
|
unkown
|
page read and write
|
||
41F2000
|
unkown
|
page read and write
|
||
5510000
|
heap private
|
page read and write
|
||
21D000
|
heap default
|
page read and write
|
||
7991000
|
unkown
|
page read and write
|
||
430000
|
unkown
|
page read and write
|
||
1CD000
|
unkown
|
page read and write
|
||
7310000
|
unkown
|
page read and write
|
||
40C4000
|
stack
|
page read and write
|
||
7700000
|
unkown
|
page read and write
|
||
7EFB2000
|
unkown image
|
page readonly
|
||
20A5000
|
heap private
|
page read and write
|
||
4E90000
|
unkown
|
page read and write
|
||
6E878000
|
unkown image
|
page write copy
|
||
2010000
|
unkown image
|
page readonly
|
||
60000
|
unkown image
|
page readonly
|
||
30000
|
unkown image
|
page readonly
|
||
3030000
|
unkown image
|
page readonly
|
||
487000
|
heap default
|
page read and write
|
||
6C1B000
|
unkown
|
page read and write
|
||
7945000
|
unkown
|
page read and write
|
||
7510000
|
unkown
|
page read and write
|
||
595D000
|
unkown
|
page read and write
|
||
7860000
|
unkown
|
page read and write
|
||
7846000
|
unkown
|
page read and write
|
||
7890000
|
unkown
|
page read and write
|
||
4B70000
|
unkown
|
page read and write
|
||
54B0000
|
unkown
|
page read and write
|
||
7EFC0000
|
unkown image
|
page readonly
|
||
4100000
|
unkown
|
page read and write
|
||
22B000
|
heap default
|
page read and write
|
||
5904000
|
unkown
|
page read and write
|
||
6E10000
|
heap private
|
page read and write
|
||
7EFB2000
|
unkown image
|
page readonly
|
||
7EFC0000
|
unkown image
|
page readonly
|
||
1DA8000
|
unkown
|
page read and write
|
||
59CF000
|
unkown
|
page read and write
|
||
7B30000
|
stack
|
page read and write
|
||
54F0000
|
unkown
|
page read and write
|
||
1E0000
|
unkown
|
page read and write
|
||
598F000
|
unkown
|
page read and write
|
||
2023000
|
unkown
|
page read and write
|
||
AA0000
|
unkown image
|
page readonly
|
||
423000
|
unkown
|
page read and write
|
||
32B8000
|
unkown
|
page read and write
|
||
6AFC000
|
unkown
|
page read and write
|
||
7462000
|
unkown
|
page read and write
|
||
7290000
|
unkown
|
page read and write
|
||
24000
|
heap private
|
page read and write
|
||
7B30000
|
stack
|
page read and write
|
||
73A8000
|
unkown
|
page read and write
|
||
694000
|
heap default
|
page read and write
|
||
6E440000
|
unkown image
|
page readonly
|
||
390000
|
unkown
|
page read and write
|
||
180000
|
unkown
|
page execute and read and write
|
||
7B30000
|
stack
|
page read and write
|
||
404000
|
heap default
|
page read and write
|
||
33E0000
|
unkown
|
page read and write
|
||
226000
|
heap default
|
page read and write
|
||
7F15000
|
unkown
|
page read and write
|
||
7B30000
|
stack
|
page read and write
|
||
41F5000
|
unkown
|
page read and write
|
||
7EFC0000
|
unkown image
|
page readonly
|
||
7B95000
|
stack
|
page read and write
|
||
3EED000
|
stack
|
page read and write
|
||
72A0000
|
unkown
|
page read and write
|
||
4800000
|
unkown
|
page read and write
|
||
6E440000
|
unkown image
|
page readonly
|
||
6CB0000
|
unkown
|
page read and write
|
||
7384000
|
unkown
|
page read and write
|
||
8090000
|
heap private
|
page read and write
|
||
6C10000
|
unkown
|
page read and write
|
||
7290000
|
unkown
|
page read and write
|
||
55BE000
|
heap private
|
page read and write
|
||
2040000
|
unkown
|
page read and write
|
||
4EF5000
|
unkown
|
page read and write
|
||
7842000
|
unkown
|
page read and write
|
||
7290000
|
unkown
|
page read and write
|
||
7EFB0000
|
unkown image
|
page readonly
|
||
20C000
|
unkown
|
page read and write
|
||
6E821000
|
unkown image
|
page readonly
|
||
594F000
|
unkown
|
page read and write
|
||
2509000
|
heap private
|
page read and write
|
||
60000
|
unkown image
|
page readonly
|
||
20DB000
|
heap private
|
page read and write
|
||
2505000
|
heap private
|
page read and write
|
||
54F0000
|
unkown
|
page read and write
|
||
7EFC0000
|
unkown image
|
page readonly
|
||
4E87000
|
unkown
|
page read and write
|
||
417000
|
heap default
|
page read and write
|
||
550F000
|
unkown
|
page read and write
|
||
4EE0000
|
unkown
|
page read and write
|
||
4F4000
|
heap default
|
page read and write
|
||
7EFD0000
|
unkown image
|
page readonly
|
||
33CF000
|
stack
|
page read and write
|
||
6E440000
|
unkown image
|
page readonly
|
||
6AC0000
|
unkown
|
page read and write
|
||
95F000
|
stack
|
page read and write
|
||
C0000
|
unkown image
|
page readonly
|
||
7EFB2000
|
unkown image
|
page readonly
|
||
6E551000
|
unkown image
|
page execute read
|
||
50000
|
unkown image
|
page readonly
|
||
7330000
|
unkown
|
page read and write
|
||
440000
|
unkown
|
page read and write
|
||
4D90000
|
unkown
|
page read and write
|
||
3540000
|
unkown
|
page read and write
|
||
7EFC2000
|
unkown image
|
page readonly
|
||
41D0000
|
unkown
|
page read and write
|
||
3F50000
|
unkown
|
page read and write
|
||
316F000
|
stack
|
page read and write
|
||
2087000
|
unkown image
|
page readonly
|
||
153000
|
unkown
|
page read and write
|
||
7EFC0000
|
unkown image
|
page readonly
|
||
484B000
|
unkown
|
page read and write
|
||
7EFB0000
|
unkown image
|
page readonly
|
||
6E86B000
|
unkown image
|
page read and write
|
||
7FFFFFD0000
|
unkown image
|
page readonly
|
||
7290000
|
unkown
|
page read and write
|
||
59B9000
|
unkown
|
page read and write
|
||
7F2C000
|
unkown
|
page read and write
|
||
41BB000
|
unkown
|
page read and write
|
||
160000
|
unkown image
|
page readonly
|
||
1EA0000
|
unkown image
|
page readonly
|
||
4190000
|
unkown
|
page read and write
|
||
450000
|
unkown
|
page read and write
|
||
7B30000
|
stack
|
page read and write
|
||
7FFFFFC2000
|
unkown image
|
page readonly
|
||
7EF8000
|
unkown
|
page read and write
|
||
3C0000
|
unkown
|
page read and write
|
||
7EAA000
|
stack
|
page read and write
|
||
134000
|
unkown
|
page read and write
|
||
7EFD0000
|
unkown image
|
page readonly
|
||
4ED7000
|
unkown
|
page read and write
|
||
670000
|
heap default
|
page read and write
|
||
2B4000
|
unkown
|
page read and write
|
||
7EFDF000
|
unkown
|
page read and write
|
||
3EF0000
|
unkown
|
page read and write
|
||
60000
|
unkown image
|
page readonly
|
||
76D0000
|
unkown
|
page read and write
|
||
6E48B000
|
unkown image
|
page read and write
|
||
7B95000
|
stack
|
page read and write
|
||
2020000
|
unkown
|
page read and write
|
||
7290000
|
unkown
|
page read and write
|
||
76D0000
|
unkown
|
page read and write
|
||
4EF8000
|
unkown
|
page read and write
|
||
59B9000
|
unkown
|
page read and write
|
||
6B80000
|
unkown
|
page read and write
|
||
3180000
|
unkown
|
page read and write
|
||
41D000
|
heap default
|
page read and write
|
||
7EFD0000
|
unkown image
|
page readonly
|
||
7290000
|
unkown
|
page read and write
|
||
320000
|
unkown
|
page read and write
|
||
3466000
|
unkown
|
page read and write
|
||
3F88000
|
unkown
|
page read and write
|
||
7B30000
|
stack
|
page read and write
|
||
7B30000
|
stack
|
page read and write
|
||
51C000
|
heap default
|
page read and write
|
||
4310000
|
unkown image
|
page readonly
|
||
72F9000
|
unkown
|
page read and write
|
||
55B0000
|
heap private
|
page read and write
|
||
3060000
|
unkown
|
page read and write
|
||
2B6000
|
unkown
|
page read and write
|
||
7300000
|
unkown
|
page read and write
|
||
75D0000
|
heap private
|
page read and write
|
||
2050000
|
unkown
|
page read and write
|
||
7EFC2000
|
unkown image
|
page readonly
|
||
144000
|
unkown
|
page read and write
|
||
50000
|
unkown image
|
page readonly
|
||
3430000
|
unkown
|
page read and write
|
||
328E000
|
stack
|
page read and write
|
||
3F58000
|
unkown
|
page read and write
|
||
58BA000
|
stack
|
page read and write
|
||
75A0000
|
unkown image
|
page read and write
|
||
79A1000
|
unkown
|
page read and write
|
||
7B30000
|
stack
|
page read and write
|
||
78B0000
|
unkown
|
page read and write
|
||
7380000
|
unkown
|
page read and write
|
||
81F5000
|
unkown
|
page read and write
|
||
72AB000
|
unkown
|
page read and write
|
||
798D000
|
unkown
|
page read and write
|
||
6CC0000
|
unkown
|
page read and write
|
||
7FFFFFD0000
|
unkown image
|
page readonly
|
||
800000
|
unkown
|
page read and write
|
||
10000
|
unkown image
|
page read and write
|
||
76E0000
|
unkown
|
page read and write
|
||
7EFB0000
|
unkown image
|
page readonly
|
||
3F20000
|
unkown
|
page read and write
|
||
72C4000
|
unkown
|
page read and write
|
||
41F7000
|
unkown
|
page read and write
|
||
755F000
|
unkown image
|
page readonly
|
||
6A7000
|
heap default
|
page read and write
|
||
7EFD0000
|
unkown image
|
page readonly
|
||
60000
|
unkown image
|
page readonly
|
||
796C000
|
unkown
|
page read and write
|
||
710000
|
unkown image
|
page readonly
|
||
6CD0000
|
heap private
|
page read and write
|
||
737F000
|
unkown
|
page read and write
|
||
7390000
|
unkown image
|
page readonly
|
||
7880000
|
unkown
|
page read and write
|
||
72A0000
|
unkown
|
page read and write
|
||
8F0000
|
unkown image
|
page readonly
|
||
5590000
|
unkown
|
page read and write
|
||
6C20000
|
unkown
|
page read and write
|
||
7FFFFFD0000
|
unkown image
|
page readonly
|
||
7FFFFFC2000
|
unkown image
|
page readonly
|
||
3FB0000
|
unkown
|
page read and write
|
||
3F30000
|
unkown
|
page read and write
|
||
2FAF000
|
stack
|
page read and write
|
||
6E48B000
|
unkown image
|
page read and write
|
||
140000
|
unkown
|
page read and write
|
||
3E0000
|
heap default
|
page read and write
|
||
3290000
|
unkown
|
page read and write
|
||
7700000
|
unkown
|
page read and write
|
||
7FFFFFB2000
|
unkown image
|
page readonly
|
||
76D0000
|
unkown
|
page read and write
|
||
7FEFF1A0000
|
unkown
|
page execute read
|
||
32C0000
|
unkown
|
page read and write
|
||
41A0000
|
unkown
|
page read and write
|
||
30000
|
unkown image
|
page read and write
|
||
3410000
|
unkown
|
page read and write
|
||
20000
|
unkown image
|
page readonly
|
||
7FFFFFD0000
|
unkown image
|
page readonly
|
||
771A000
|
unkown
|
page read and write
|
||
4AC0000
|
unkown
|
page read and write
|
||
7EFB2000
|
unkown image
|
page readonly
|
||
7EFC0000
|
unkown image
|
page readonly
|
||
40000
|
unkown image
|
page readonly
|
||
7940000
|
unkown
|
page read and write
|
||
7400000
|
heap private
|
page read and write
|
||
78B6000
|
unkown
|
page read and write
|
||
580000
|
unkown image
|
page readonly
|
||
7B30000
|
stack
|
page read and write
|
||
330000
|
heap private
|
page read and write
|
||
414000
|
heap private
|
page read and write
|
||
41BD000
|
unkown
|
page read and write
|
||
76D0000
|
unkown
|
page read and write
|
||
72ED000
|
unkown
|
page read and write
|
||
7CC0000
|
heap private
|
page read and write
|
||
7340000
|
unkown
|
page read and write
|
||
6E441000
|
unkown image
|
page execute read
|
||
577E000
|
stack
|
page read and write
|
||
7B30000
|
stack
|
page read and write
|
||
7290000
|
unkown
|
page read and write
|
||
76D2000
|
unkown
|
page read and write
|
||
76D0000
|
unkown
|
page read and write
|
||
7B30000
|
stack
|
page read and write
|
||
4110000
|
heap private
|
page execute and read and write
|
||
5670000
|
unkown
|
page read and write
|
||
2420000
|
heap private
|
page read and write
|
||
20A0000
|
heap private
|
page read and write
|
||
342B000
|
unkown
|
page read and write
|
||
3F90000
|
unkown
|
page read and write
|
||
76D0000
|
unkown
|
page read and write
|
||
10000
|
unkown image
|
page read and write
|
||
4EF8000
|
unkown
|
page read and write
|
||
8A0000
|
unkown image
|
page readonly
|
||
2E0000
|
unkown
|
page read and write
|
||
7EFB0000
|
unkown image
|
page readonly
|
||
6CCA000
|
unkown
|
page read and write
|
||
60000
|
unkown image
|
page readonly
|
||
54F0000
|
unkown
|
page read and write
|
||
6AF0000
|
unkown
|
page read and write
|
||
60000
|
unkown image
|
page readonly
|
||
59B1000
|
unkown
|
page read and write
|
||
7EFC2000
|
unkown image
|
page readonly
|
||
7EFB2000
|
unkown image
|
page readonly
|
||
130000
|
unkown
|
page read and write
|
||
75B0000
|
unkown image
|
page read and write
|
||
41B0000
|
unkown
|
page read and write
|
||
58DF000
|
unkown
|
page read and write
|
||
4EF5000
|
unkown
|
page read and write
|
||
7FFFFFB2000
|
unkown image
|
page readonly
|
||
7886000
|
unkown
|
page read and write
|
||
4E0000
|
unkown image
|
page readonly
|
||
3A0000
|
unkown image
|
page readonly
|
||
11D000
|
unkown
|
page read and write
|
||
430F000
|
stack
|
page read and write
|
||
7FFFFFB0000
|
unkown image
|
page readonly
|
||
50000
|
unkown image
|
page readonly
|
||
6E874000
|
unkown image
|
page read and write
|
||
7320000
|
unkown
|
page read and write
|
||
3550000
|
heap private
|
page read and write
|
||
7BAC000
|
stack
|
page read and write
|
||
599A000
|
unkown
|
page read and write
|
||
7B50000
|
stack
|
page read and write
|
||
370000
|
heap private
|
page read and write
|
||
54F0000
|
unkown
|
page read and write
|
||
1DAE000
|
unkown
|
page read and write
|
||
550C000
|
unkown
|
page read and write
|
||
B0000
|
unkown image
|
page readonly
|
||
75C0000
|
unkown
|
page read and write
|
||
7BAC000
|
stack
|
page read and write
|
||
455000
|
unkown
|
page read and write
|
||
4700000
|
unkown
|
page read and write
|
||
940000
|
heap private
|
page read and write
|
||
7320000
|
unkown
|
page read and write
|
||
6E90000
|
unkown
|
page read and write
|
||
76D2000
|
unkown
|
page read and write
|
||
730B000
|
unkown
|
page read and write
|
||
3E7000
|
heap default
|
page read and write
|
||
3DD3000
|
unkown
|
page read and write
|
||
5A03000
|
unkown
|
page read and write
|
||
7EFE0000
|
unkown image
|
page readonly
|
||
60000
|
unkown image
|
page readonly
|
||
8232000
|
unkown
|
page read and write
|
||
477000
|
unkown
|
page read and write
|
||
7FFFFFC0000
|
unkown image
|
page readonly
|
||
3E0000
|
unkown
|
page read and write
|
||
161000
|
unkown
|
page read and write
|
||
7EFE0000
|
unkown image
|
page readonly
|
||
30000
|
unkown image
|
page readonly
|
||
7BAC000
|
stack
|
page read and write
|
||
420000
|
unkown
|
page read and write
|
||
7295000
|
unkown
|
page read and write
|
||
7FFFFFC0000
|
unkown image
|
page readonly
|
||
3050000
|
unkown
|
page read and write
|
||
40000
|
unkown image
|
page readonly
|
||
7716000
|
unkown
|
page read and write
|
||
58C8000
|
unkown
|
page read and write
|
||
6B90000
|
heap private
|
page read and write
|
||
5660000
|
unkown
|
page read and write
|
||
7EFD0000
|
unkown image
|
page readonly
|
||
600000
|
heap private
|
page read and write
|
||
210000
|
unkown
|
page read and write
|
||
6C2A000
|
unkown
|
page read and write
|
||
7EFC2000
|
unkown image
|
page readonly
|
||
2044000
|
unkown
|
page read and write
|
||
72A0000
|
unkown
|
page read and write
|
||
50000
|
unkown image
|
page readonly
|
||
5177000
|
unkown image
|
page readonly
|
||
7EFC2000
|
unkown image
|
page readonly
|
||
7EFC0000
|
unkown image
|
page readonly
|
||
7ED0000
|
unkown
|
page read and write
|
||
6E87C000
|
unkown image
|
page read and write
|
||
7EFD0000
|
unkown image
|
page readonly
|
||
4A2F000
|
stack
|
page read and write
|
||
20000
|
heap private
|
page read and write
|
||
10000
|
unkown image
|
page read and write
|
||
6B00000
|
heap private
|
page read and write
|
||
40D0000
|
unkown
|
page read and write
|
||
7350000
|
unkown
|
page read and write
|
||
73F3000
|
unkown
|
page read and write
|
||
41A8000
|
unkown
|
page read and write
|
||
143000
|
unkown
|
page read and write
|
||
7EFB2000
|
unkown image
|
page readonly
|
||
2ED000
|
unkown
|
page read and write
|
||
300000
|
unkown image
|
page readonly
|
||
7EFC0000
|
unkown image
|
page readonly
|
||
73B4000
|
unkown
|
page read and write
|
||
54A0000
|
unkown image
|
page readonly
|
||
7FFFFFC2000
|
unkown image
|
page readonly
|
||
7550000
|
unkown image
|
page readonly
|
||
41B9000
|
unkown
|
page read and write
|
||
60000
|
unkown image
|
page readonly
|
||
677000
|
heap default
|
page read and write
|
||
4200000
|
unkown
|
page read and write
|
||
2F0000
|
unkown
|
page read and write
|
||
7290000
|
unkown
|
page read and write
|
||
72D0000
|
unkown
|
page read and write
|
||
7EFB2000
|
unkown image
|
page readonly
|
||
3170000
|
unkown
|
page read and write
|
||
2087000
|
unkown image
|
page readonly
|
||
310000
|
unkown
|
page read and write
|
||
6CBE000
|
unkown
|
page read and write
|
||
7890000
|
unkown
|
page read and write
|
||
1DBE000
|
unkown
|
page read and write
|
||
7730000
|
heap private
|
page read and write
|
||
375000
|
heap private
|
page read and write
|
||
72A0000
|
unkown
|
page read and write
|
||
7EFB2000
|
unkown image
|
page readonly
|
||
59B9000
|
unkown
|
page read and write
|
||
7B30000
|
stack
|
page read and write
|
||
41B2000
|
unkown
|
page read and write
|
||
7EE5000
|
unkown
|
page read and write
|
||
1E7000
|
heap default
|
page read and write
|
||
6C27000
|
unkown
|
page read and write
|
||
7FFFFFB0000
|
unkown image
|
page readonly
|
||
7EFB0000
|
unkown image
|
page readonly
|
||
4EF1000
|
unkown
|
page read and write
|
||
598A000
|
unkown
|
page read and write
|
||
7EFC2000
|
unkown image
|
page readonly
|
||
7EFB2000
|
unkown image
|
page readonly
|
||
54D000
|
heap default
|
page read and write
|
||
7F70000
|
unkown
|
page read and write
|
||
65300000
|
unkown image
|
page readonly
|
||
41B5000
|
unkown
|
page read and write
|
||
6E479000
|
unkown image
|
page readonly
|
||
7EFC0000
|
unkown image
|
page readonly
|
||
3D0000
|
unkown
|
page read and write
|
||
7290000
|
unkown
|
page read and write
|
||
7F22000
|
unkown
|
page read and write
|
||
7B50000
|
stack
|
page read and write
|
||
7404000
|
heap private
|
page read and write
|
||
342C000
|
heap private
|
page read and write
|
||
7FFFFFB0000
|
unkown image
|
page readonly
|
||
72B0000
|
unkown
|
page read and write
|
||
153000
|
unkown
|
page read and write
|
||
50000
|
unkown image
|
page readonly
|
||
4EDF000
|
unkown
|
page read and write
|
||
3400000
|
unkown image
|
page read and write
|
||
4F07000
|
unkown
|
page read and write
|
||
58C0000
|
unkown
|
page read and write
|
||
59B1000
|
unkown
|
page read and write
|
||
6E440000
|
unkown image
|
page readonly
|
||
32B0000
|
unkown
|
page read and write
|
||
7EFC0000
|
unkown image
|
page readonly
|
||
6C30000
|
heap private
|
page read and write
|
||
3420000
|
heap private
|
page read and write
|
There are 615 hidden memdumps, click here to show them.