Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
gunzipped.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
|
initial sample
|
||
C:\ProgramData\834793065949733\_8347930659.zip
|
Zip archive data, at least v2.0 to extract
|
dropped
|
||
C:\ProgramData\834793065949733\cookies\Google Chrome_Default.txt
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\ProgramData\834793065949733\screenshot.jpg
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 1280x1024,
frames 3
|
dropped
|
||
C:\ProgramData\834793065949733\system.txt
|
ISO-8859 text, with CRLF line terminators
|
dropped
|
||
C:\ProgramData\834793065949733\temp
|
SQLite 3.x database, last written using SQLite version 3032001
|
dropped
|
||
C:\ProgramData\freebl3.dll
|
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
|
dropped
|
||
C:\ProgramData\mozglue.dll
|
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
|
dropped
|
||
C:\ProgramData\msvcp140.dll
|
PE32 executable (DLL) (console) Intel 80386, for MS Windows
|
dropped
|
||
C:\ProgramData\nss3.dll
|
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
|
dropped
|
||
C:\ProgramData\softokn3.dll
|
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
|
dropped
|
||
C:\ProgramData\sqlite3.dll
|
PE32 executable (DLL) (console) Intel 80386, for MS Windows
|
dropped
|
||
C:\ProgramData\vcruntime140.dll
|
PE32 executable (DLL) (console) Intel 80386, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\3lzr9t8b2fewpx2
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\dxaqqkiiu
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\nsy255F.tmp\qhvek.dll
|
PE32 executable (DLL) (console) Intel 80386, for MS Windows
|
dropped
|
There are 6 hidden files, click here to show them.
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\gunzipped.exe
|
"C:\Users\user\Desktop\gunzipped.exe"
|
||
C:\Users\user\Desktop\gunzipped.exe
|
"C:\Users\user\Desktop\gunzipped.exe"
|
||
C:\Windows\SysWOW64\cmd.exe
|
"C:\Windows\System32\cmd.exe" /c taskkill /pid 1068 & erase C:\Users\user\Desktop\gunzipped.exe & RD /S /Q C:\\ProgramData\\834793065949733\\*
& exit
|
||
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
||
C:\Windows\SysWOW64\taskkill.exe
|
taskkill /pid 1068
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://2.56.57.108/osk//4.jpg
|
2.56.57.108
|
||
http://2.56.57.108/osk//5.jpg
|
2.56.57.108
|
||
http://2.56.57.108/osk//main.php
|
2.56.57.108
|
||
http://ocsp.thawte.com0
|
unknown
|
||
http://www.mozilla.com0
|
unknown
|
||
http://2.56.57.108/osk//1.jpg
|
2.56.57.108
|
||
http://2.56.57.108/osk//6.jpg
|
2.56.57.108
|
||
http://2.56.57.108/osk//2.jpg
|
2.56.57.108
|
||
http://2.56.57.108/osk//7.jpg
|
2.56.57.108
|
||
http://2.56.57.108/osk//1.jpghttp://2.56.57.108/osk//4.jpghttp://2.56.57.108/osk//7.jpghttp://2.56.5
|
unknown
|
||
http://2.56.57.108/osk//3.jpg
|
2.56.57.108
|
||
http://2.56.57.108/osk//5.jpg2
|
unknown
|
||
http://2.56.57.108/osk/
|
2.56.57.108
|
||
http://2.56.57.108/osk//2.jpghttp://2.56.57.108/osk//6.jpghttp://2.56.57.108/osk//3.jpghttp://2.56.5
|
unknown
|
||
http://2.56.57.108/osk//7.jpgB
|
unknown
|
||
https://duckduckgo.com/chrome_newtab
|
unknown
|
||
http://www.mozilla.com/en-US/blocklist/
|
unknown
|
||
https://duckduckgo.com/ac/?q=
|
unknown
|
||
https://www.google.com/images/branding/product/ico/googleg_lodp.ico
|
unknown
|
||
https://support.google.com/chrome/answer/6258784
|
unknown
|
||
https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
|
unknown
|
||
https://support.google.com/chrome/?p=plugin_flash
|
unknown
|
||
https://search.yahoo.com/favicon.icohttps://search.yahoo.com/search
|
unknown
|
||
http://nsis.sf.net/NSIS_ErrorError
|
unknown
|
||
https://ac.ecosia.org/autocomplete?q=
|
unknown
|
||
http://nsis.sf.net/NSIS_Error
|
unknown
|
||
http://crl.thawte.com/ThawteTimestampingCA.crl0
|
unknown
|
||
https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
|
unknown
|
||
https://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
|
unknown
|
There are 19 hidden URLs, click here to show them.
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
2.56.57.108
|
unknown
|
Netherlands
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
2CB0000
|
unkown
|
page read and write
|
||
7B0000
|
unkown
|
page execute and read and write
|
||
7B0000
|
unkown
|
page execute and read and write
|
||
7B0000
|
unkown
|
page execute and read and write
|
||
7B0000
|
unkown
|
page execute and read and write
|
||
2725000
|
heap private
|
page read and write
|
||
7B0000
|
unkown
|
page execute and read and write
|
||
38D0000
|
unkown
|
page read and write
|
||
40000
|
unkown image
|
page readonly
|
||
E16000
|
unkown image
|
page readonly
|
||
400000
|
unkown image
|
page readonly
|
||
407000
|
unkown image
|
page readonly
|
||
7FFC2000
|
unkown image
|
page readonly
|
||
25AE000
|
stack
|
page read and write
|
||
2F9B000
|
unkown
|
page read and write
|
||
33F1000
|
unkown
|
page read and write
|
||
6F301000
|
unkown image
|
page execute read
|
||
400000
|
unkown image
|
page readonly
|
||
3626000
|
heap private
|
page read and write
|
||
2581000
|
unkown
|
page read and write
|
||
C9A000
|
unkown
|
page read and write
|
||
3626000
|
heap private
|
page read and write
|
||
7FFB0000
|
unkown image
|
page readonly
|
||
25E0000
|
heap private
|
page read and write
|
||
409000
|
unkown image
|
page write copy
|
||
40000
|
unkown image
|
page readonly
|
||
7FC12000
|
unkown image
|
page readonly
|
||
2F9B000
|
unkown
|
page read and write
|
||
FE0000
|
unkown image
|
page readonly
|
||
7FFC2000
|
unkown image
|
page readonly
|
||
7FFB2000
|
unkown image
|
page readonly
|
||
2674000
|
unkown
|
page read and write
|
||
7AB000
|
unkown image
|
page readonly
|
||
7FFD0000
|
unkown image
|
page readonly
|
||
C3C000
|
heap default
|
page read and write
|
||
2BA8000
|
unkown
|
page read and write
|
||
7AB000
|
unkown image
|
page readonly
|
||
7FFC2000
|
unkown image
|
page readonly
|
||
2DEF000
|
stack
|
page read and write
|
||
3ABA000
|
heap private
|
page read and write
|
||
CA5000
|
unkown
|
page read and write
|
||
94A000
|
unkown
|
page read and write
|
||
2E06000
|
unkown
|
page read and write
|
||
7AB000
|
unkown image
|
page readonly
|
||
7AB000
|
unkown image
|
page readonly
|
||
7FFD0000
|
unkown image
|
page readonly
|
||
33F0000
|
unkown
|
page read and write
|
||
2CF0000
|
unkown
|
page read and write
|
||
C6F000
|
stack
|
page read and write
|
||
407000
|
unkown image
|
page readonly
|
||
2F9F000
|
unkown
|
page read and write
|
||
7FFC0000
|
unkown image
|
page readonly
|
||
A40000
|
unkown
|
page read and write
|
||
C9A000
|
unkown
|
page read and write
|
||
C9A000
|
unkown
|
page read and write
|
||
1B0000
|
unkown image
|
page readonly
|
||
1A0000
|
unkown image
|
page readonly
|
||
409000
|
unkown image
|
page write copy
|
||
2E80000
|
unkown
|
page read and write
|
||
400000
|
unkown image
|
page readonly
|
||
409000
|
unkown image
|
page write copy
|
||
2768000
|
heap private
|
page read and write
|
||
1160000
|
unkown image
|
page readonly
|
||
7FFB0000
|
unkown image
|
page readonly
|
||
CA5000
|
unkown
|
page read and write
|
||
BD0000
|
unkown image
|
page readonly
|
||
2CF0000
|
unkown
|
page read and write
|
||
2B90000
|
unkown
|
page read and write
|
||
2E80000
|
unkown
|
page read and write
|
||
2E80000
|
unkown
|
page read and write
|
||
A2E000
|
stack
|
page read and write
|
||
7FFB2000
|
unkown image
|
page readonly
|
||
31F1000
|
unkown
|
page read and write
|
||
7FC20000
|
unkown image
|
page readonly
|
||
BD0000
|
unkown image
|
page readonly
|
||
FB0000
|
unkown image
|
page readonly
|
||
2B7000
|
unkown
|
page read and write
|
||
3170000
|
heap default
|
page read and write
|
||
3622000
|
heap private
|
page read and write
|
||
C9A000
|
unkown
|
page read and write
|
||
2675000
|
unkown
|
page read and write
|
||
2BB3000
|
unkown image
|
page readonly
|
||
7FFD0000
|
unkown image
|
page readonly
|
||
7E5000
|
unkown
|
page execute and read and write
|
||
7FFB0000
|
unkown image
|
page readonly
|
||
3A60000
|
unkown image
|
page readonly
|
||
6F346000
|
unkown image
|
page read and write
|
||
1B0000
|
unkown image
|
page readonly
|
||
7FFC0000
|
unkown image
|
page readonly
|
||
400000
|
unkown image
|
page readonly
|
||
7FC22000
|
unkown image
|
page readonly
|
||
7AB000
|
unkown image
|
page readonly
|
||
1A0000
|
unkown image
|
page readonly
|
||
7FFB0000
|
unkown image
|
page readonly
|
||
2E06000
|
unkown
|
page read and write
|
||
409000
|
unkown image
|
page write copy
|
||
400000
|
unkown image
|
page readonly
|
||
C9A000
|
unkown
|
page read and write
|
||
30AE000
|
stack
|
page read and write
|
||
7FFD0000
|
unkown image
|
page readonly
|
||
7FC22000
|
unkown image
|
page readonly
|
||
26FE000
|
stack
|
page read and write
|
||
7FC12000
|
unkown image
|
page readonly
|
||
37F0000
|
unkown
|
page read and write
|
||
BD0000
|
unkown image
|
page readonly
|
||
C44000
|
heap default
|
page read and write
|
||
B6D000
|
stack
|
page read and write
|
||
40000
|
unkown image
|
page readonly
|
||
2E06000
|
unkown
|
page read and write
|
||
8D0000
|
heap private
|
page read and write
|
||
7FFB0000
|
unkown image
|
page readonly
|
||
26BE000
|
stack
|
page read and write
|
||
2F9F000
|
unkown
|
page read and write
|
||
CA5000
|
unkown
|
page read and write
|
||
2550000
|
unkown
|
page read and write
|
||
8FA000
|
heap default
|
page read and write
|
||
C8E000
|
heap default
|
page read and write
|
||
2F2F000
|
stack
|
page read and write
|
||
7D7000
|
unkown
|
page readonly
|
||
CA5000
|
unkown
|
page read and write
|
||
31F0000
|
unkown
|
page read and write
|
||
2F9F000
|
unkown
|
page read and write
|
||
784000
|
unkown image
|
page read and write
|
||
7FFB2000
|
unkown image
|
page readonly
|
||
3C90000
|
heap private
|
page read and write
|
||
2E06000
|
unkown
|
page read and write
|
||
2E80000
|
unkown
|
page read and write
|
||
BE8000
|
heap default
|
page read and write
|
||
31F1000
|
unkown
|
page read and write
|
||
7FFD0000
|
unkown image
|
page readonly
|
||
7E0000
|
heap default
|
page read and write
|
||
7FFC2000
|
unkown image
|
page readonly
|
||
40000
|
unkown image
|
page readonly
|
||
31B000
|
unkown
|
page read and write
|
||
948000
|
heap default
|
page read and write
|
||
2674000
|
unkown
|
page read and write
|
||
C82000
|
unkown
|
page read and write
|
||
7FFD0000
|
unkown image
|
page readonly
|
||
91C000
|
stack
|
page read and write
|
||
2AF5000
|
unkown image
|
page readonly
|
||
BE0000
|
heap default
|
page read and write
|
||
C9A000
|
unkown
|
page read and write
|
||
409000
|
unkown image
|
page write copy
|
||
401000
|
unkown image
|
page execute read
|
||
1A0000
|
unkown image
|
page readonly
|
||
CAA000
|
unkown
|
page read and write
|
||
CA5000
|
unkown
|
page read and write
|
||
D70000
|
unkown
|
page read and write
|
||
C9A000
|
unkown
|
page read and write
|
||
D30000
|
unkown image
|
page readonly
|
||
1B0000
|
unkown image
|
page readonly
|
||
6F300000
|
unkown image
|
page readonly
|
||
324000
|
unkown
|
page read and write
|
||
3409000
|
unkown
|
page read and write
|
||
D40000
|
unkown image
|
page readonly
|
||
D40000
|
unkown image
|
page readonly
|
||
7FFC2000
|
unkown image
|
page readonly
|
||
1B0000
|
unkown image
|
page readonly
|
||
2E06000
|
unkown
|
page read and write
|
||
303E000
|
stack
|
page read and write
|
||
328D000
|
unkown
|
page read and write
|
||
2A6E000
|
stack
|
page read and write
|
||
CA5000
|
unkown
|
page read and write
|
||
400000
|
unkown image
|
page readonly
|
||
CA5000
|
unkown
|
page read and write
|
||
30F000
|
unkown
|
page read and write
|
||
401000
|
unkown image
|
page execute read
|
||
C9A000
|
unkown
|
page read and write
|
||
407000
|
unkown image
|
page readonly
|
||
2E80000
|
unkown
|
page read and write
|
||
401000
|
unkown image
|
page execute read
|
||
7FFD0000
|
unkown image
|
page readonly
|
||
30000
|
unkown image
|
page read and write
|
||
332B000
|
unkown
|
page read and write
|
||
7FFC2000
|
unkown image
|
page readonly
|
||
C97000
|
unkown
|
page read and write
|
||
25D0000
|
heap private
|
page read and write
|
||
C2D000
|
unkown
|
page read and write
|
||
A60000
|
heap default
|
page read and write
|
||
2E80000
|
unkown
|
page read and write
|
||
1A0000
|
unkown image
|
page readonly
|
||
7E0000
|
unkown
|
page execute and read and write
|
||
7FC12000
|
unkown image
|
page readonly
|
||
7FC12000
|
unkown image
|
page readonly
|
||
7FC20000
|
unkown image
|
page readonly
|
||
7FFB2000
|
unkown image
|
page readonly
|
||
2B12000
|
unkown image
|
page readonly
|
||
780000
|
unkown image
|
page read and write
|
||
7FFB2000
|
unkown image
|
page readonly
|
||
D30000
|
unkown image
|
page readonly
|
||
31F1000
|
unkown
|
page read and write
|
||
400000
|
unkown image
|
page readonly
|
||
D30000
|
unkown image
|
page readonly
|
||
3626000
|
heap private
|
page read and write
|
||
C9A000
|
unkown
|
page read and write
|
||
400000
|
unkown image
|
page readonly
|
||
25B0000
|
unkown
|
page read and write
|
||
8F0000
|
stack
|
page read and write
|
||
C9A000
|
unkown
|
page read and write
|
||
BAE000
|
stack
|
page read and write
|
||
7FEB0000
|
unkown image
|
page readonly
|
||
2BB8000
|
unkown image
|
page readonly
|
||
948000
|
unkown
|
page read and write
|
||
7FFB2000
|
unkown image
|
page readonly
|
||
40000
|
unkown image
|
page readonly
|
||
2F9B000
|
unkown
|
page read and write
|
||
CA5000
|
unkown
|
page read and write
|
||
401000
|
unkown image
|
page execute read
|
||
7FC22000
|
unkown image
|
page readonly
|
||
407000
|
unkown image
|
page readonly
|
||
3341000
|
unkown
|
page read and write
|
||
C93000
|
unkown
|
page read and write
|
||
1A0000
|
unkown image
|
page readonly
|
||
1B0000
|
unkown image
|
page readonly
|
||
7FFC2000
|
unkown image
|
page readonly
|
||
7FFB2000
|
unkown image
|
page readonly
|
||
2CF0000
|
unkown
|
page read and write
|
||
400000
|
unkown image
|
page readonly
|
||
6F341000
|
unkown image
|
page readonly
|
||
332A000
|
unkown
|
page read and write
|
||
7FC10000
|
unkown image
|
page readonly
|
||
407000
|
unkown image
|
page readonly
|
||
30000
|
unkown image
|
page read and write
|
||
A3E000
|
stack
|
page read and write
|
||
7FFC0000
|
unkown image
|
page readonly
|
||
2580000
|
unkown
|
page read and write
|
||
37F0000
|
unkown
|
page read and write
|
||
3443000
|
unkown
|
page read and write
|
||
40000
|
unkown image
|
page readonly
|
||
2F6C000
|
stack
|
page read and write
|
||
926000
|
heap default
|
page read and write
|
||
7FFC0000
|
unkown image
|
page readonly
|
||
DAE000
|
stack
|
page read and write
|
||
948000
|
unkown
|
page read and write
|
||
7E5000
|
heap default
|
page read and write
|
||
2760000
|
heap private
|
page read and write
|
||
7FFD0000
|
unkown image
|
page readonly
|
||
E16000
|
unkown image
|
page readonly
|
||
7AB000
|
unkown image
|
page readonly
|
||
401000
|
unkown image
|
page execute read
|
||
2F9F000
|
unkown
|
page read and write
|
||
7B0000
|
unkown
|
page execute and read and write
|
||
7FFC2000
|
unkown image
|
page readonly
|
||
40000
|
unkown image
|
page readonly
|
||
D50000
|
unkown
|
page read and write
|
||
7FFB2000
|
unkown image
|
page readonly
|
||
D2E000
|
unkown
|
page read and write
|
||
6F349000
|
unkown image
|
page readonly
|
||
7FC30000
|
unkown image
|
page readonly
|
||
409000
|
unkown image
|
page write copy
|
||
7FFB2000
|
unkown image
|
page readonly
|
||
7FFD0000
|
unkown image
|
page readonly
|
||
8F0000
|
heap default
|
page read and write
|
||
7FFB2000
|
unkown image
|
page readonly
|
||
2F7B000
|
unkown
|
page read and write
|
||
60900000
|
unkown image
|
page readonly
|
||
3178000
|
unkown
|
page read and write
|
||
7FFC0000
|
unkown image
|
page readonly
|
||
31AF000
|
stack
|
page read and write
|
||
2E2E000
|
stack
|
page read and write
|
||
C9A000
|
unkown
|
page read and write
|
||
1A0000
|
unkown image
|
page readonly
|
||
345B000
|
unkown
|
page read and write
|
||
C9A000
|
unkown
|
page read and write
|
||
7FFC2000
|
unkown image
|
page readonly
|
||
400000
|
unkown image
|
page readonly
|
||
2CEE000
|
stack
|
page read and write
|
||
2720000
|
heap private
|
page read and write
|
||
CA5000
|
unkown
|
page read and write
|
||
C9A000
|
unkown
|
page read and write
|
||
7FC30000
|
unkown image
|
page readonly
|
||
C87000
|
unkown
|
page read and write
|
||
1B0000
|
unkown image
|
page readonly
|
||
1A0000
|
unkown image
|
page readonly
|
||
7FC30000
|
unkown image
|
page readonly
|
||
409000
|
unkown image
|
page write copy
|
||
7B0000
|
unkown
|
page read and write
|
||
7E5000
|
unkown
|
page readonly
|
||
2CA0000
|
unkown image
|
page readonly
|
||
318A000
|
unkown
|
page read and write
|
||
2B98000
|
unkown
|
page read and write
|
||
2B6F000
|
stack
|
page read and write
|
||
2F7F000
|
unkown
|
page read and write
|
||
7FFB0000
|
unkown image
|
page readonly
|
||
1B0000
|
unkown image
|
page readonly
|
||
3447000
|
unkown
|
page read and write
|
||
401000
|
unkown image
|
page execute read
|
||
B2F000
|
stack
|
page read and write
|
||
409000
|
unkown image
|
page write copy
|
||
2E06000
|
unkown
|
page read and write
|
||
407000
|
unkown image
|
page readonly
|
||
1B0000
|
unkown image
|
page readonly
|
||
400000
|
unkown image
|
page readonly
|
||
401000
|
unkown image
|
page execute read
|
||
3920000
|
unkown
|
page read and write
|
||
407000
|
unkown image
|
page readonly
|
||
40000
|
unkown image
|
page readonly
|
||
344A000
|
unkown
|
page read and write
|
||
3AEE000
|
unkown
|
page read and write
|
||
409000
|
unkown image
|
page write copy
|
||
19A000
|
unkown
|
page read and write
|
||
92E000
|
stack
|
page read and write
|
||
2F9B000
|
unkown
|
page read and write
|
||
2F9F000
|
unkown
|
page read and write
|
||
7FFD0000
|
unkown image
|
page readonly
|
||
409000
|
unkown image
|
page write copy
|
||
CA5000
|
unkown
|
page read and write
|
||
401000
|
unkown image
|
page execute read
|
||
7FFB2000
|
unkown image
|
page readonly
|
||
7FC10000
|
unkown image
|
page readonly
|
||
327000
|
unkown
|
page read and write
|
||
7AB000
|
unkown image
|
page readonly
|
||
82C000
|
stack
|
page read and write
|
||
31F1000
|
unkown
|
page read and write
|
||
CA5000
|
unkown
|
page read and write
|
||
40000
|
unkown image
|
page readonly
|
||
407000
|
unkown image
|
page readonly
|
||
D40000
|
unkown image
|
page readonly
|
||
2BB8000
|
unkown image
|
page readonly
|
||
7FFB0000
|
unkown image
|
page readonly
|
||
3620000
|
heap private
|
page read and write
|
||
31F7000
|
unkown
|
page read and write
|
||
2CF0000
|
unkown
|
page read and write
|
||
A50000
|
unkown image
|
page readonly
|
||
DE0000
|
unkown image
|
page readonly
|
||
7C0000
|
unkown image
|
page readonly
|
||
A65000
|
heap default
|
page read and write
|
||
CA5000
|
unkown
|
page read and write
|
||
38F0000
|
unkown
|
page read and write
|
||
7FFC0000
|
unkown image
|
page readonly
|
||
37F0000
|
unkown
|
page read and write
|
||
7AB000
|
unkown image
|
page readonly
|
||
C4A000
|
heap default
|
page read and write
|
||
1B0000
|
unkown image
|
page readonly
|
||
786000
|
unkown image
|
page read and write
|
||
306C000
|
stack
|
page read and write
|
||
7AB000
|
unkown image
|
page readonly
|
||
401000
|
unkown image
|
page execute read
|
||
920000
|
heap default
|
page read and write
|
||
7A0000
|
unkown image
|
page read and write
|
||
7FFB0000
|
unkown image
|
page readonly
|
||
CA5000
|
unkown
|
page read and write
|
||
C8A000
|
unkown
|
page read and write
|
||
2CF0000
|
unkown
|
page read and write
|
||
7FB10000
|
unkown image
|
page readonly
|
||
7FFD0000
|
unkown image
|
page readonly
|
||
7FC10000
|
unkown image
|
page readonly
|
||
1A0000
|
unkown image
|
page readonly
|
||
C9A000
|
unkown
|
page read and write
|
||
7B0000
|
unkown
|
page execute and read and write
|
||
BD0000
|
unkown image
|
page readonly
|
||
2BB8000
|
unkown image
|
page readonly
|
||
CA5000
|
unkown
|
page read and write
|
||
3189000
|
unkown
|
page read and write
|
||
318000
|
unkown
|
page read and write
|
||
2F9F000
|
unkown
|
page read and write
|
||
2CF0000
|
unkown
|
page read and write
|
||
31F1000
|
unkown
|
page read and write
|
||
343C000
|
unkown
|
page read and write
|
||
332B000
|
unkown
|
page read and write
|
||
DDF000
|
stack
|
page read and write
|
||
31F1000
|
unkown
|
page read and write
|
||
7FC30000
|
unkown image
|
page readonly
|
||
332A000
|
unkown
|
page read and write
|
||
33F0000
|
unkown
|
page read and write
|
||
6F300000
|
unkown image
|
page readonly
|
||
2A2F000
|
stack
|
page read and write
|
||
40000
|
unkown image
|
page readonly
|
||
326F000
|
unkown
|
page read and write
|
||
31F1000
|
unkown
|
page read and write
|
||
B6E000
|
stack
|
page read and write
|
||
C9A000
|
unkown
|
page read and write
|
||
CA5000
|
unkown
|
page read and write
|
||
7FC20000
|
unkown image
|
page readonly
|
||
2BB8000
|
unkown image
|
page readonly
|
||
308000
|
unkown
|
page read and write
|
||
30C0000
|
heap default
|
page read and write
|
||
2E80000
|
unkown
|
page read and write
|
||
7FFC0000
|
unkown image
|
page readonly
|
||
7FC20000
|
unkown image
|
page readonly
|
||
BC0000
|
unkown image
|
page read and write
|
||
7E5000
|
unkown
|
page execute and read and write
|
||
401000
|
unkown image
|
page execute read
|
||
3451000
|
unkown
|
page read and write
|
||
2BAF000
|
stack
|
page read and write
|
||
7FFB0000
|
unkown image
|
page readonly
|
||
3BED000
|
stack
|
page read and write
|
||
E16000
|
unkown image
|
page readonly
|
||
7AB000
|
unkown image
|
page readonly
|
||
E16000
|
unkown image
|
page readonly
|
||
31F1000
|
unkown
|
page read and write
|
||
7FC22000
|
unkown image
|
page readonly
|
||
7FFB0000
|
unkown image
|
page readonly
|
||
CA5000
|
unkown
|
page read and write
|
||
2CF0000
|
unkown
|
page read and write
|
||
2E06000
|
unkown
|
page read and write
|
||
407000
|
unkown image
|
page readonly
|
||
7E5000
|
unkown
|
page execute and read and write
|
||
77A000
|
unkown image
|
page read and write
|
||
7FFC0000
|
unkown image
|
page readonly
|
||
7FC10000
|
unkown image
|
page readonly
|
||
CA5000
|
unkown
|
page read and write
|
||
1130000
|
unkown image
|
page readonly
|
||
31F1000
|
unkown
|
page read and write
|
||
7FFC0000
|
unkown image
|
page readonly
|
||
7FFB0000
|
unkown image
|
page readonly
|
||
7FFC2000
|
unkown image
|
page readonly
|
||
31F1000
|
unkown
|
page read and write
|
||
1A0000
|
unkown image
|
page readonly
|
||
7FFC0000
|
unkown image
|
page readonly
|
||
D40000
|
unkown image
|
page readonly
|
||
CAE000
|
stack
|
page read and write
|
||
2F9B000
|
unkown
|
page read and write
|
||
40000
|
unkown image
|
page readonly
|
||
2B1B000
|
unkown image
|
page readonly
|
||
7B0000
|
unkown
|
page execute and read and write
|
||
407000
|
unkown image
|
page readonly
|
||
7FFC2000
|
unkown image
|
page readonly
|
||
326F000
|
unkown
|
page read and write
|
||
2F9F000
|
unkown
|
page read and write
|
||
DB0000
|
unkown image
|
page readonly
|
||
3189000
|
heap default
|
page read and write
|
||
400000
|
unkown image
|
page readonly
|
||
9C000
|
unkown
|
page read and write
|
||
2B3000
|
unkown
|
page read and write
|
||
7FEB0000
|
unkown image
|
page readonly
|
||
3AB0000
|
heap private
|
page read and write
|
||
2730000
|
unkown
|
page read and write
|
||
D30000
|
unkown image
|
page readonly
|
||
3451000
|
unkown
|
page read and write
|
||
7AB000
|
unkown image
|
page readonly
|
||
7FFC0000
|
unkown image
|
page readonly
|
||
7B1000
|
unkown
|
page execute read
|
||
3207000
|
unkown
|
page read and write
|
||
7A8000
|
unkown image
|
page read and write
|
||
409000
|
unkown image
|
page read and write
|
||
407000
|
unkown image
|
page readonly
|
||
401000
|
unkown image
|
page execute read
|
||
3341000
|
unkown
|
page read and write
|
||
31F1000
|
unkown
|
page read and write
|
||
BB0000
|
unkown
|
page read and write
|
||
2B17000
|
unkown image
|
page readonly
|
||
2F9B000
|
unkown
|
page read and write
|
||
343F000
|
stack
|
page read and write
|
||
3445000
|
unkown
|
page read and write
|
||
2F9B000
|
unkown
|
page read and write
|
||
19E000
|
unkown
|
page execute and read and write
|
||
31F7000
|
unkown
|
page read and write
|
||
2CAF000
|
stack
|
page read and write
|
||
400000
|
unkown image
|
page readonly
|
There are 440 hidden memdumps, click here to show them.