IOC Report

loading gif

Files

File Path
Type
Category
Malicious
enjoin,12.27.2021.doc
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1251, Comments: ta, Template: Normal, Last Saved By: Windows, Revision Number: 2, Name of Creating Application: Microsoft Office Word, Create Time/Date: Mon Dec 27 11:02:00 2021, Last Saved Time/Date: Mon Dec 27 11:02:00 2021, Number of Pages: 1, Number of Words: 116, Number of Characters: 16118, Security: 0
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\vaci3[1].htm
HTML document, ASCII text
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRF{64EB5F3D-FB2E-4BD3-8AEA-82C307C336B9}.tmp
data
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{B70C9704-7AD7-458C-BF06-A25E66915659}.tmp
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DFDA21D6ED226BEFAA.TMP
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\My Documents.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Tue Oct 17 10:04:00 2017, mtime=Fri Dec 31 19:23:16 2021, atime=Fri Dec 31 19:23:16 2021, length=8192, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\enjoin,12.27.2021.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Mon Aug 30 20:08:55 2021, mtime=Mon Aug 30 20:08:55 2021, atime=Fri Dec 31 19:23:12 2021, length=80896, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\i7Gigabyte.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Fri Dec 31 19:23:16 2021, mtime=Fri Dec 31 19:23:16 2021, atime=Fri Dec 31 19:23:16 2021, length=4060, window=hide
modified
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
data
dropped
clean
C:\Users\user\Desktop\~$join,12.27.2021.doc
data
dropped
clean
C:\Users\user\Documents\i7Gigabyte.hta (copy)
HTML document, ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\Documents\~$Gigabyte.hta
data
dropped
clean
C:\Users\user\Documents\~WRD0000.tmp
HTML document, ASCII text, with very long lines, with CRLF line terminators
dropped
clean
There are 4 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /Automation -Embedding
malicious
C:\Windows\explorer.exe
explorer i7Gigabyte.hta
malicious
C:\Windows\explorer.exe
C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding
malicious
C:\Windows\SysWOW64\mshta.exe
"C:\Windows\SysWOW64\mshta.exe" "C:\Users\user\Documents\i7Gigabyte.hta"
malicious

URLs

Name
IP
Malicious
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://www.windows.com/pctv.
unknown
clean
http://patelboostg.com/frhe/L8dclCye7SQ5WTFva78FDxOjGBOF9iJro4DRgV/5inYIaSBt0KLfMB9kXwZBv6ZpTsny6/qAhIQjrAaLKJeTLQnbCarASpMADNe9u19Kylnkoreo7/SjqMh4eEx0Hx9b4h5e2fMcQgeIbFT/kKeSzfUaenwSFB/ISkVIHedx0p/49280/SruwcI68Yb5pVaVqfvyOHztDsbEuhGxtlV6bpgPIFvGFQ277/7FkN9pAcaWDfFlGNBeuaqGed8iDibaWexT/GyAAzLRbFAU1XErrU1F/vaci3?page=V8BBaQuem65&page=XYvyd0Dcrg6fJYLGHRVWp7s1tv&page=dvZwXcjcYCjBX8tPaALshiDAx85PEq&sid=10tOgWzOZj9xyAidNJAz3d9Ob0
45.67.229.54
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://www.%s.comPA
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://patelboostg.com/frhe/L8dclCye7SQ5WTFva78FDxOjGBOF9iJro4DRgV/5inYIaSBt0KLfMB9kXwZBv6ZpTsny6/qA
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://investor.msn.com/
unknown
clean
There are 2 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
patelboostg.com
45.67.229.54
clean

IPs

IP
Domain
Country
Malicious
45.67.229.54
patelboostg.com
Moldova Republic of
clean

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
rx&
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
iy&
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
k{&
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\2D182
2D182
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Place MRU
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 21
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\file mru
Item 21
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\2DBDE
2DBDE
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
WORDFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\2D182
2D182
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hta\OpenWithProgids
htafile
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
There are 55 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
33B000
unkown
page read and write
clean
310000
unkown
page read and write
clean
D59000
unkown
page read and write
clean
44E000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
D9E000
unkown
page read and write
clean
2FFE000
stack
page read and write
clean
41E000
unkown
page read and write
clean
220F000
stack
page read and write
clean
41E000
unkown
page read and write
clean
338000
unkown
page read and write
clean
373000
unkown
page read and write
clean
319000
unkown
page read and write
clean
2560000
unkown
page read and write
clean
D6D000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
D2C000
unkown
page read and write
clean
33C000
unkown
page read and write
clean
6694000
heap private
page read and write
clean
319E000
stack
page read and write
clean
10000
unkown image
page read and write
clean
2BC0000
unkown image
page readonly
clean
347000
unkown
page read and write
clean
3ED000
unkown
page read and write
clean
2343000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
618C000
stack
page read and write
clean
2E00000
unkown image
page readonly
clean
2C32000
unkown
page read and write
clean
6740000
unkown
page read and write
clean
274E000
stack
page read and write
clean
1FB000
unkown
page read and write
clean
1A0000
heap default
page read and write
clean
310000
unkown
page read and write
clean
64CD000
stack
page read and write
clean
353000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
29A000
unkown
page read and write
clean
2C30000
unkown
page read and write
clean
416000
unkown
page read and write
clean
373000
unkown
page read and write
clean
2345000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
2C26000
unkown
page read and write
clean
DA4000
unkown
page read and write
clean
30C000
unkown
page read and write
clean
E80000
unkown image
page readonly
clean
28BF000
stack
page read and write
clean
34E000
unkown
page read and write
clean
D86000
unkown
page read and write
clean
D84000
unkown
page read and write
clean
434000
unkown
page read and write
clean
338000
unkown
page read and write
clean
364000
unkown
page read and write
clean
2D5000
heap default
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
2350000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
2560000
unkown
page read and write
clean
2C25000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
6745000
unkown
page read and write
clean
310000
unkown
page read and write
clean
3FF000
heap default
page read and write
clean
24A0000
unkown image
page readonly
clean
347000
unkown
page read and write
clean
100000
unkown
page read and write
clean
58F000
heap private
page read and write
clean
33B000
unkown
page read and write
clean
43B000
unkown
page read and write
clean
3E5000
heap default
page read and write
clean
340000
unkown
page read and write
clean
409000
unkown
page read and write
clean
31E000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
6EFD000
stack
page read and write
clean
2C24000
unkown
page read and write
clean
D9E000
unkown
page read and write
clean
586000
heap private
page read and write
clean
2BA0000
unkown
page read and write
clean
310000
unkown
page read and write
clean
332000
unkown
page read and write
clean
D52000
unkown
page read and write
clean
345000
unkown
page read and write
clean
34E000
unkown
page read and write
clean
1D4000
heap private
page read and write
clean
40000
unkown image
page readonly
clean
32C000
unkown
page read and write
clean
1D0000
heap private
page read and write
clean
5E70000
heap private
page read and write
clean
3EB000
unkown
page read and write
clean
2F8000
heap default
page read and write
clean
347000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
DBA000
unkown
page read and write
clean
2D5000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
343000
unkown
page read and write
clean
2C33000
unkown
page read and write
clean
258F000
unkown
page read and write
clean
2C22000
unkown
page read and write
clean
33E000
unkown
page read and write
clean
2DC0000
unkown
page read and write
clean
297000
heap default
page read and write
clean
430000
unkown
page read and write
clean
2D3F000
stack
page read and write
clean
298F000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
34B000
unkown
page read and write
clean
38B7000
unkown image
page readonly
clean
D23000
unkown
page read and write
clean
580000
heap private
page read and write
clean
D0000
unkown image
page readonly
clean
33B000
unkown
page read and write
clean
416000
unkown
page read and write
clean
3BE000
heap default
page read and write
clean
33E000
unkown
page read and write
clean
600000
unkown image
page readonly
clean
D87000
unkown
page read and write
clean
2DA6000
unkown
page read and write
clean
610000
unkown image
page readonly
clean
611C000
stack
page read and write
clean
27CE000
stack
page read and write
clean
6DC0000
heap private
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
120000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
44A000
unkown
page read and write
clean
2C2A000
unkown
page read and write
clean
D86000
unkown
page read and write
clean
D65000
unkown
page read and write
clean
7EFC2000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
41E000
unkown
page read and write
clean
1CC0000
heap private
page read and write
clean
44B000
unkown
page read and write
clean
404000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
228F000
stack
page read and write
clean
6540000
heap private
page read and write
clean
2584000
unkown
page read and write
clean
2C2C000
unkown
page read and write
clean
1BA0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
345000
unkown
page read and write
clean
D9E000
unkown
page read and write
clean
319000
unkown
page read and write
clean
263E000
stack
page read and write
clean
30E000
unkown
page read and write
clean
60DC000
stack
page read and write
clean
44E000
unkown
page read and write
clean
600000
unkown image
page readonly
clean
34B000
unkown
page read and write
clean
720000
unkown image
page readonly
clean
2C2E000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
1C50000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
D9E000
unkown
page read and write
clean
72A0000
heap private
page read and write
clean
2990000
unkown
page execute
clean
165000
unkown
page read and write
clean
6700000
heap private
page read and write
clean
590000
unkown image
page readonly
clean
300000
unkown image
page readonly
clean
44E000
unkown
page read and write
clean
3BE000
heap default
page read and write
clean
6225000
unkown
page read and write
clean
408000
unkown
page read and write
clean
319000
unkown
page read and write
clean
310000
unkown image
page readonly
clean
1F0000
unkown
page read and write
clean
2364000
heap private
page read and write
clean
329000
unkown
page read and write
clean
32BD000
stack
page read and write
clean
2360000
heap private
page read and write
clean
DA2000
unkown
page read and write
clean
DA4000
unkown
page read and write
clean
373000
unkown
page read and write
clean
2F8000
unkown
page read and write
clean
384000
unkown
page read and write
clean
D68000
unkown
page read and write
clean
72AB000
heap private
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
38F000
unkown
page read and write
clean
380000
heap default
page read and write
clean
40000
unkown image
page readonly
clean
1E0000
unkown image
page readonly
clean
5FA0000
heap private
page read and write
clean
3E0000
unkown
page read and write
clean
3F5000
unkown
page read and write
clean
22FF000
stack
page read and write
clean
2DA0000
unkown
page read and write
clean
6190000
heap private
page read and write
clean
2D80000
unkown
page execute
clean
26BE000
stack
page read and write
clean
439000
unkown
page read and write
clean
2310000
unkown
page read and write
clean
190000
unkown
page read and write
clean
42B000
unkown
page read and write
clean
38F000
unkown
page read and write
clean
D27000
unkown
page read and write
clean
33B000
unkown
page read and write
clean
16B000
unkown
page read and write
clean
1C0B000
heap private
page read and write
clean
387000
heap default
page read and write
clean
7EFC0000
unkown image
page readonly
clean
332000
unkown
page read and write
clean
320000
unkown
page read and write
clean
27EE000
stack
page read and write
clean
E0000
unkown image
page read and write
clean
200000
unkown
page read and write
clean
2D7D000
stack
page read and write
clean
2C20000
unkown
page read and write
clean
E40000
unkown
page read and write
clean
38F000
unkown
page read and write
clean
345000
unkown
page read and write
clean
365000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
621B000
unkown
page read and write
clean
6360000
heap private
page read and write
clean
25B0000
heap private
page read and write
clean
38F000
unkown
page read and write
clean
2560000
unkown
page read and write
clean
352000
unkown
page read and write
clean
72A8000
heap private
page read and write
clean
6742000
unkown
page read and write
clean
319000
unkown
page read and write
clean
622B000
unkown
page read and write
clean
40A000
heap default
page read and write
clean
409000
unkown
page read and write
clean
3DF000
heap default
page read and write
clean
D83000
unkown
page read and write
clean
61EE000
unkown
page read and write
clean
319000
unkown
page read and write
clean
2340000
unkown
page read and write
clean
210000
unkown
page read and write
clean
401000
unkown
page read and write
clean
41E000
unkown
page read and write
clean
2ED000
heap default
page read and write
clean
33E000
unkown
page read and write
clean
416000
unkown
page read and write
clean
D65000
unkown
page read and write
clean
340000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
459000
unkown
page read and write
clean
2C28000
unkown
page read and write
clean
445000
unkown
page read and write
clean
6FFC000
stack
page read and write
clean
2040000
unkown image
page readonly
clean
370000
heap private
page read and write
clean
36CF000
stack
page read and write
clean
5F40000
heap private
page read and write
clean
7EFC0000
unkown image
page readonly
clean
290000
heap default
page read and write
clean
DA5000
unkown
page read and write
clean
2C21000
unkown
page read and write
clean
335000
unkown
page read and write
clean
1F0000
unkown image
page read and write
clean
6D30000
heap private
page read and write
clean
106000
unkown
page read and write
clean
362000
unkown
page read and write
clean
2B00000
unkown
page read and write
clean
D9E000
unkown
page read and write
clean
236000
unkown
page read and write
clean
2D5000
unkown
page read and write
clean
50000
unkown image
page readonly
clean
2C23000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
34B000
unkown
page read and write
clean
338000
unkown
page read and write
clean
2F68000
heap private
page read and write
clean
30E000
unkown
page read and write
clean
2C31000
unkown
page read and write
clean
373000
unkown
page read and write
clean
31E000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
419000
unkown
page read and write
clean
661C000
stack
page read and write
clean
D9E000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
402000
unkown
page read and write
clean
2B4000
heap default
page read and write
clean
2BA9000
unkown
page read and write
clean
41E000
unkown
page read and write
clean
34F000
unkown
page read and write
clean
DB5000
unkown
page read and write
clean
380000
heap default
page read and write
clean
66B1000
heap private
page read and write
clean
382000
unkown
page read and write
clean
621A000
unkown
page read and write
clean
290000
unkown
page read and write
clean
6C5F000
stack
page read and write
clean
310000
unkown
page read and write
clean
362000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
387000
heap default
page read and write
clean
3DF000
heap default
page read and write
clean
2560000
unkown
page read and write
clean
2DAB000
unkown
page read and write
clean
343000
unkown
page read and write
clean
2580000
unkown
page read and write
clean
2560000
unkown
page read and write
clean
2C29000
unkown
page read and write
clean
340000
unkown
page read and write
clean
2F86000
heap private
page read and write
clean
343000
unkown
page read and write
clean
D88000
unkown
page read and write
clean
D8A000
unkown
page read and write
clean
30000
unkown image
page read and write
clean
320000
unkown
page read and write
clean
2560000
unkown
page read and write
clean
408000
unkown
page read and write
clean
374000
heap private
page read and write
clean
41C000
unkown
page read and write
clean
480000
unkown image
page readonly
clean
D8A000
unkown
page read and write
clean
2560000
unkown
page read and write
clean
2560000
unkown
page read and write
clean
6744000
unkown
page read and write
clean
610000
unkown image
page readonly
clean
1CC5000
heap private
page read and write
clean
362000
unkown
page read and write
clean
235B000
unkown
page read and write
clean
712D000
stack
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
6743000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
382000
unkown
page read and write
clean
2DB4000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
382000
unkown
page read and write
clean
382000
unkown
page read and write
clean
359000
unkown
page read and write
clean
362000
unkown
page read and write
clean
297B000
unkown
page read and write
clean
DA4000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
D4A000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
1BD0000
heap private
page read and write
clean
3F6000
unkown
page read and write
clean
25B4000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
61F8000
unkown
page read and write
clean
710000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
298A000
unkown
page read and write
clean
26A000
unkown
page read and write
clean
72A4000
heap private
page read and write
clean
1BD5000
heap private
page read and write
clean
442000
unkown
page read and write
clean
350000
unkown
page read and write
clean
2ED000
unkown
page read and write
clean
6222000
unkown
page read and write
clean
36D0000
unkown image
page readonly
clean
3AB0000
unkown image
page readonly
clean
2560000
unkown
page read and write
clean
34DE000
stack
page read and write
clean
2BC4000
unkown image
page readonly
clean
2B0000
unkown
page read and write
clean
480000
unkown image
page readonly
clean
25D2000
heap private
page read and write
clean
D5D000
unkown
page read and write
clean
31E000
unkown
page read and write
clean
382000
unkown
page read and write
clean
416000
unkown
page read and write
clean
43D000
unkown
page read and write
clean
6690000
heap private
page read and write
clean
2560000
unkown
page read and write
clean
2C2B000
unkown
page read and write
clean
332000
unkown
page read and write
clean
388000
unkown
page read and write
clean
292E000
stack
page read and write
clean
D86000
unkown
page read and write
clean
335000
unkown
page read and write
clean
D0000
unkown
page read and write
clean
327000
unkown
page read and write
clean
31E000
unkown
page read and write
clean
30E000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
6741000
unkown
page read and write
clean
2F60000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
2F8000
unkown
page read and write
clean
2C2D000
unkown
page read and write
clean
2E3000
unkown
page read and write
clean
1CFB000
heap private
page read and write
clean
7EFE0000
unkown image
page readonly
clean
1D40000
unkown image
page readonly
clean
31E000
unkown
page read and write
clean
32F0000
heap private
page read and write
clean
44E000
unkown
page read and write
clean
DA4000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
5E20000
heap private
page read and write
clean
2BCF000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
61D0000
unkown
page read and write
clean
652E000
stack
page read and write
clean
2C27000
unkown
page read and write
clean
D9E000
unkown
page read and write
clean
258B000
unkown
page read and write
clean
There are 394 hidden memdumps, click here to show them.