IOC Report

loading gif

Files

File Path
Type
Category
Malicious
DOC_MDR0307_019.doc
Rich Text Format data, unknown version
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\plugmanzx[1].exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
downloaded
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRF{31EE4F20-8102-4B92-84BC-9897A1B6A0AD}.tmp
Composite Document File V2 Document, Cannot read section info
dropped
malicious
C:\Users\user\AppData\Local\Temp\tmp90FA.tmp
XML 1.0 document, ASCII text
dropped
malicious
C:\Users\user\AppData\Roaming\EA860E7A-A87F-4A88-92EF-38F744458171\run.dat
Non-ISO extended-ASCII text, with no line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\ZdNnwVcb.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\AppData\Roaming\plugmancdht5461.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Program Files (x86)\SMTP Service\smtpsvc.exe
PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{389992DD-2DC9-4AE9-A20A-17842FFF7D86}.tmp
data
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{67E7F9AB-C509-437A-87CC-02623FAC39E8}.tmp
data
dropped
C:\Users\user\AppData\Local\Temp\tmpBC45.tmp
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\tmpCAE4.tmp
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Roaming\EA860E7A-A87F-4A88-92EF-38F744458171\catalog.dat
data
dropped
C:\Users\user\AppData\Roaming\EA860E7A-A87F-4A88-92EF-38F744458171\task.dat
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\DOC_MDR0307_019.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Mon Aug 30 20:08:56 2021, mtime=Mon Aug 30 20:08:56 2021, atime=Mon Jan 24 23:37:13 2022, length=445364, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
data
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\CC3LSTOKK0VB6393QYBO.temp
data
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms (copy)
data
dropped
C:\Users\user\Desktop\~$C_MDR0307_019.doc
data
dropped
There are 10 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
"C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE" -Embedding
malicious
C:\Users\user\AppData\Roaming\plugmancdht5461.exe
C:\Users\user\AppData\Roaming\plugmancdht5461.exe
malicious
C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\ZdNnwVcb.exe
malicious
C:\Windows\SysWOW64\schtasks.exe
C:\Windows\System32\schtasks.exe" /Create /TN "Updates\ZdNnwVcb" /XML "C:\Users\user\AppData\Local\Temp\tmp90FA.tmp
malicious
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe
malicious
C:\Windows\SysWOW64\schtasks.exe
schtasks.exe" /create /f /tn "SMTP Service" /xml "C:\Users\user\AppData\Local\Temp\tmpCAE4.tmp
malicious
C:\Windows\SysWOW64\schtasks.exe
schtasks.exe" /create /f /tn "SMTP Service Task" /xml "C:\Users\user\AppData\Local\Temp\tmpBC45.tmp
malicious
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe 0
malicious
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /Automation -Embedding
C:\Windows\System32\taskeng.exe
taskeng.exe {C8C4FF1A-D055-4E86-80AC-43603134EA50} S-1-5-21-966771315-3019405637-367336477-1006:user-PC\user:Interactive:[1]
C:\Program Files (x86)\SMTP Service\smtpsvc.exe
"C:\Program Files (x86)\SMTP Service\smtpsvc.exe" 0
C:\Program Files (x86)\SMTP Service\smtpsvc.exe
"C:\Program Files (x86)\SMTP Service\smtpsvc.exe"
There are 2 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://paxz.tk/plugmanzx.exe
2.58.149.41
malicious
4,0,403183674,0000000000138000,00000002,00000001,01000000,00000003,3,2C678C69C60A9225
malicious
vijayikohli1.bounceme.net
malicious
127.0.0.1
malicious
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
unknown

Domains

Name
IP
Malicious
paxz.tk
2.58.149.41
malicious
vijayikohli1.bounceme.net
103.153.78.234
malicious

IPs

IP
Domain
Country
Malicious
103.153.78.234
vijayikohli1.bounceme.net
unknown
malicious
2.58.149.41
paxz.tk
Netherlands
malicious

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
94*
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
05*
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
n8*
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\2DDB2
2DDB2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Arial Unicode MS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Batang
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@BatangChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@DFKai-SB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Dotum
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@DotumChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@FangSong
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Gulim
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@GulimChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Gungsuh
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@GungsuhChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@KaiTi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Malgun Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Meiryo
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Meiryo UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Microsoft JhengHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@Microsoft YaHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU_HKSCS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU_HKSCS-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS Mincho
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS PGothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS PMincho
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@MS UI Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@NSimSun
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@PMingLiU
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@PMingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimSun
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
@SimSun-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Agency FB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Aharoni
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Algerian
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Andalus
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Angsana New
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
AngsanaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Aparajita
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arabic Typesetting
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Black
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Narrow
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Rounded MT Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Arial Unicode MS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Baskerville Old Face
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Batang
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
BatangChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bauhaus 93
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bell MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Berlin Sans FB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Berlin Sans FB Demi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bernard MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Blackadder ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Black
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bodoni MT Poster Compressed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Book Antiqua
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bookman Old Style
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bookshelf Symbol 7
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Bradley Hand ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Britannic Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Broadway
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Browallia New
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
BrowalliaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Brush Script MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calibri
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calibri Light
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Californian FB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Calisto MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cambria
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cambria Math
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Candara
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Castellar
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Centaur
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Century Schoolbook
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Chiller
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Colonna MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Comic Sans MS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Consolas
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Constantia
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cooper Black
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Copperplate Gothic Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Copperplate Gothic Light
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Corbel
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Cordia New
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
CordiaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Courier New
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Curlz MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DaunPenh
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
David
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DFKai-SB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DilleniaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DokChampa
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Dotum
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
DotumChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Ebrima
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Edwardian Script ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Elephant
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Engravers MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Bold ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Demi ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Light ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Eras Medium ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Estrangelo Edessa
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
EucrosiaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Euphemia
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FangSong
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Felix Titling
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Footlight MT Light
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Forte
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Book
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Demi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Demi Cond
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Heavy
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Medium
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Franklin Gothic Medium Cond
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FrankRuehl
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
FreesiaUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Freestyle Script
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
French Script MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gabriola
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Garamond
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gautami
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Georgia
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gigi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans MT Ext Condensed Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans Ultra Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gill Sans Ultra Bold Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gisha
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gloucester MT Extra Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Goudy Old Style
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Goudy Stout
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gulim
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
GulimChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Gungsuh
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
GungsuhChe
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Haettenschweiler
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Harlow Solid Italic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Harrington
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
High Tower Text
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Impact
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Imprint MT Shadow
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Informal Roman
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
IrisUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Iskoola Pota
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
JasmineUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Jokerman
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Juice ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
KaiTi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kalinga
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kartika
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Khmer UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
KodchiangUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kokila
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kristen ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Kunstler Script
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lao UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Latha
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Leelawadee
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Levenim MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
LilyUPC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Bright
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Calligraphy
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Console
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Fax
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Handwriting
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans Typewriter
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Lucida Sans Unicode
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Magneto
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Maiandra GD
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Malgun Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mangal
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Marlett
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Matura MT Script Capitals
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Meiryo
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Meiryo UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Himalaya
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft JhengHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft New Tai Lue
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft PhagsPa
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Sans Serif
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Tai Le
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Uighur
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft YaHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Microsoft Yi Baiti
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU_HKSCS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU_HKSCS-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Miriam
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Miriam Fixed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mistral
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Modern No. 20
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Mongolian Baiti
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Monotype Corsiva
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MoolBoran
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Mincho
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Outlook
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS PGothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS PMincho
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Reference Sans Serif
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS Reference Specialty
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MS UI Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MT Extra
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
MV Boli
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Narkisim
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Niagara Engraved
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Niagara Solid
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
NSimSun
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Nyala
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
OCR A Extended
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Old English Text MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Onyx
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Palace Script MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Palatino Linotype
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Papyrus
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Parchment
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Perpetua
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Perpetua Titling MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Plantagenet Cherokee
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Playbill
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
PMingLiU
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
PMingLiU-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Poor Richard
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Pristina
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Raavi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rage Italic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Ravie
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rockwell Extra Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Rod
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Sakkal Majalla
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Script MT Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe Print
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe Script
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Light
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Semibold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Segoe UI Symbol
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Shonar Bangla
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Showcard Gothic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Shruti
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimHei
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Simplified Arabic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Simplified Arabic Fixed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimSun
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
SimSun-ExtB
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Snap ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Stencil
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Sylfaen
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Symbol
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tahoma
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tempus Sans ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Times New Roman
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Traditional Arabic
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Trebuchet MS
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tunga
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT Condensed
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Tw Cen MT Condensed Extra Bold
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Utsaah
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vani
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Verdana
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vijaya
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Viner Hand ITC
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vivaldi
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vladimir Script
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Vrinda
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Webdings
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wide Latin
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings 2
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\MathFonts
Wingdings 3
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\3737B
3737B
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Security\Trusted Documents
LastPurgeTime
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
WORDFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100A0C00100000000F01FEC\Usage
SpellingAndGrammarFiles_3082
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400100000000F01FEC\Usage
SpellingAndGrammarFiles_1036
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400100000000F01FEC\Usage
SpellingAndGrammarFiles_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\3737B
3737B
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Data
Settings
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Options
ZoomApp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTF
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
EquationEditorFilesIntl_1033
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run
SMTP Service
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\Handshake\{C8C4FF1A-D055-4E86-80AC-43603134EA50}
data
There are 315 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
5F0000
trusted library section
page read and write
malicious
35E9000
trusted library allocation
page read and write
malicious
402000
remote allocation
page execute and read and write
malicious
3529000
trusted library allocation
page read and write
malicious
23EF000
trusted library allocation
page read and write
malicious
402000
remote allocation
page execute and read and write
malicious
402000
remote allocation
page execute and read and write
malicious
2381000
trusted library allocation
page read and write
malicious
402000
remote allocation
page execute and read and write
malicious
402000
remote allocation
page execute and read and write
malicious
60000
unkown
page readonly
50000
unkown
page readonly
440000
trusted library allocation
page read and write
5BA0000
trusted library allocation
page read and write
B4E000
stack
page read and write
381E000
trusted library allocation
page read and write
6D0000
trusted library allocation
page read and write
20B000
trusted library allocation
page execute and read and write
650000
trusted library allocation
page read and write
610000
trusted library allocation
page read and write
601F000
stack
page read and write
10000
heap
page read and write
AE000
heap
page read and write
2AE000
stack
page read and write
880000
heap
page read and write
1C0000
trusted library allocation
page read and write
4B0000
heap
page read and write
A0F000
stack
page read and write
6A0000
trusted library allocation
page read and write
700000
trusted library allocation
page read and write
350000
heap
page read and write
2190000
trusted library allocation
page read and write
630000
heap
page read and write
2240000
heap
page execute and read and write
17B000
trusted library allocation
page execute and read and write
390000
trusted library allocation
page execute and read and write
6A0000
trusted library allocation
page read and write
403000
trusted library allocation
page read and write
2742000
heap
page read and write
13D000
trusted library allocation
page execute and read and write
C0000
unkown
page readonly
23FF000
stack
page read and write
650000
trusted library section
page read and write
546000
trusted library allocation
page read and write
546000
trusted library allocation
page read and write
655000
trusted library allocation
page read and write
6B0000
trusted library allocation
page read and write
63B0000
trusted library allocation
page read and write
51CB000
trusted library allocation
page read and write
4A4000
heap
page read and write
2BE000
heap
page read and write
650000
trusted library allocation
page read and write
26BB000
heap
page read and write
54AC000
stack
page read and write
1F70000
heap
page read and write
110000
heap
page read and write
69E000
stack
page read and write
50000
unkown
page readonly
4A0000
heap
page read and write
4A20000
heap
page read and write
7EFE0000
unkown
page readonly
D4000
trusted library allocation
page read and write
3A0000
heap
page read and write
338000
trusted library allocation
page read and write
5ECC000
stack
page read and write
650000
trusted library allocation
page read and write
1E7E000
stack
page read and write
4F8000
stack
page read and write
2230000
trusted library allocation
page read and write
3EA000
unkown
page readonly
820000
heap
page read and write
1F4E000
stack
page read and write
136000
unkown
page readonly
3381000
trusted library allocation
page read and write
210E000
stack
page read and write | page guard
820000
trusted library allocation
page read and write
2E7000
trusted library allocation
page read and write
5E0000
trusted library allocation
page read and write
4B0000
heap
page read and write
656000
trusted library allocation
page read and write
422000
remote allocation
page execute and read and write
510000
trusted library allocation
page read and write
6A0000
trusted library allocation
page read and write
2200000
trusted library allocation
page read and write
509C000
stack
page read and write
519A000
trusted library allocation
page read and write
1070000
heap
page read and write
658000
trusted library allocation
page read and write
406000
heap
page read and write
25B000
stack
page read and write
248000
trusted library allocation
page read and write
37B7000
trusted library allocation
page read and write
50000
unkown
page readonly
540000
trusted library allocation
page read and write
400000
trusted library allocation
page read and write
60000
unkown
page readonly
573000
heap
page read and write
5E0000
trusted library allocation
page read and write
22AE000
stack
page read and write
133000
trusted library allocation
page execute and read and write
20000
heap
page read and write
455E000
stack
page read and write
51AF000
trusted library allocation
page read and write
3D0000
trusted library allocation
page read and write
1F74000
heap
page read and write
2A5B000
trusted library allocation
page read and write
211B000
trusted library allocation
page read and write
540000
trusted library allocation
page read and write
48F0000
heap
page execute and read and write
C2000
unkown
page execute read
720000
heap
page read and write
E0000
heap
page read and write
3271000
trusted library allocation
page read and write
400000
remote allocation
page execute and read and write
BAF000
stack
page read and write
1BC000
stack
page read and write
C7E000
stack
page read and write
20000
heap
page read and write
430000
trusted library allocation
page read and write
14D000
trusted library allocation
page execute and read and write
51EC000
stack
page read and write
1B0000
trusted library allocation
page read and write
4D0000
heap
page execute and read and write
920000
heap
page execute and read and write
6D5000
trusted library allocation
page read and write
26C000
stack
page read and write
490000
heap
page read and write
3E0000
unkown
page readonly
730000
heap
page read and write
5B9E000
stack
page read and write
C2E000
stack
page read and write
84E000
stack
page read and write
1CA000
trusted library allocation
page execute and read and write
538F000
stack
page read and write
2B0000
trusted library allocation
page read and write
500000
trusted library allocation
page read and write
540000
trusted library allocation
page read and write
410000
trusted library allocation
page execute and read and write
4F3B000
trusted library allocation
page read and write
50000
unkown
page readonly
650000
trusted library allocation
page read and write
48AF000
stack
page read and write
493E000
stack
page read and write
840000
heap
page read and write
8D0000
heap
page read and write
60000
unkown
page readonly
4E6000
heap
page read and write
6A2000
trusted library allocation
page read and write
1F0000
heap
page read and write
16B000
stack
page read and write
10000
heap
page read and write
23D000
stack
page read and write
5D0000
trusted library allocation
page read and write
613E000
stack
page read and write | page guard
550000
heap
page read and write
70000
heap
page read and write
6B0000
trusted library allocation
page read and write
451D000
stack
page read and write
60000
unkown
page readonly
6B2000
trusted library allocation
page read and write
836000
trusted library allocation
page read and write
3C4000
heap
page read and write
86E000
stack
page read and write
20000
heap
page read and write
6E0000
trusted library allocation
page read and write
548000
trusted library allocation
page read and write
650000
trusted library allocation
page read and write
1F9000
heap
page read and write
20C0000
trusted library allocation
page read and write
21C0000
heap
page read and write
2D4000
heap
page read and write
4EC0000
heap
page read and write
DD000
trusted library allocation
page execute and read and write
2110000
trusted library allocation
page read and write
5D0000
trusted library allocation
page read and write
280000
heap
page read and write
584000
heap
page read and write
1C0000
trusted library allocation
page read and write
380000
trusted library allocation
page execute and read and write
530000
trusted library allocation
page read and write
23FE000
stack
page read and write | page guard
D32000
unkown
page execute read
1FFD000
stack
page read and write
160000
heap
page read and write
400000
remote allocation
page execute and read and write
548D000
stack
page read and write
5B60000
trusted library allocation
page read and write
637000
heap
page read and write
540000
trusted library allocation
page read and write
1E0000
trusted library allocation
page read and write
3ED000
heap
page read and write
1C7000
trusted library allocation
page read and write
6B5000
trusted library allocation
page read and write
8E0000
heap
page execute and read and write
7D0000
heap
page read and write
D30000
unkown
page readonly
5C60000
heap
page read and write
5E0000
trusted library allocation
page read and write
474000
heap
page read and write
5E8F000
stack
page read and write
3389000
trusted library allocation
page read and write
3F0000
trusted library allocation
page read and write
4D4000
heap
page read and write
540000
trusted library allocation
page read and write
660000
heap
page read and write
54EE000
stack
page read and write
C2000
unkown
page execute read
277000
heap
page read and write
284F000
trusted library allocation
page read and write
3509000
trusted library allocation
page read and write
5F50000
heap
page read and write
540000
trusted library allocation
page read and write
5D0000
trusted library allocation
page read and write
6E7000
heap
page read and write
4B7E000
stack
page read and write
422000
remote allocation
page execute and read and write
5E5E000
stack
page read and write
4B0E000
stack
page read and write
5F0000
trusted library section
page read and write
32A000
stack
page read and write
420000
trusted library allocation
page read and write
600000
trusted library allocation
page read and write
20000
heap
page read and write
7EF58000
trusted library allocation
page execute and read and write
209C000
stack
page read and write
560000
heap
page read and write
21A0000
trusted library allocation
page read and write
2E0000
trusted library allocation
page read and write
2720000
heap
page read and write
77C000
heap
page read and write
24B000
stack
page read and write
554000
heap
page read and write
527D000
unkown
page read and write
55ED000
stack
page read and write
D30000
unkown
page readonly
7EF15000
unkown
page read and write
7F2000
heap
page read and write
5A9E000
stack
page read and write
540000
trusted library allocation
page read and write
3F0000
trusted library allocation
page execute and read and write
5160000
trusted library allocation
page read and write
80E000
stack
page read and write
657000
trusted library allocation
page read and write
4DEC000
stack
page read and write
B4000
trusted library allocation
page read and write
650000
trusted library allocation
page read and write
501E000
stack
page read and write
22B0000
heap
page execute and read and write
400000
remote allocation
page execute and read and write
490F000
stack
page read and write
36C8000
trusted library allocation
page read and write
ADD000
stack
page read and write
8AE000
stack
page read and write
745000
heap
page read and write
237E000
stack
page read and write | page guard
650000
trusted library allocation
page read and write
1D3000
trusted library allocation
page execute and read and write
4E60000
trusted library allocation
page read and write
1E0000
trusted library allocation
page read and write
6B5000
trusted library allocation
page read and write
10000
heap
page read and write
F6E000
stack
page read and write | page guard
60000
unkown
page readonly
2210000
trusted library allocation
page read and write
6E1E000
stack
page read and write
6D0000
trusted library allocation
page read and write
540000
trusted library allocation
page read and write
530000
heap
page read and write
540000
trusted library allocation
page read and write
B90000
heap
page read and write
370000
trusted library allocation
page execute and read and write
380000
trusted library allocation
page read and write
600000
trusted library allocation
page read and write
613F000
stack
page read and write
B60000
heap
page read and write
400000
remote allocation
page execute and read and write
A0000
trusted library allocation
page read and write
3E2000
unkown
page execute read
370000
heap
page read and write
51B5000
trusted library allocation
page read and write
550000
heap
page read and write
3EA000
unkown
page readonly
4EE0000
trusted library allocation
page read and write
9B000
stack
page read and write
4B7000
heap
page read and write
6B0000
trusted library allocation
page read and write
5F0000
trusted library allocation
page read and write
278F000
stack
page read and write
C0000
trusted library allocation
page read and write
538E000
stack
page read and write | page guard
168000
heap
page read and write
6C0000
heap
page read and write
211F000
stack
page read and write
120000
trusted library allocation
page read and write
42B000
heap
page read and write
34E9000
trusted library allocation
page read and write
6BF000
trusted library allocation
page read and write
637F000
stack
page read and write
719D000
stack
page read and write
518B000
trusted library allocation
page read and write
20000
heap
page read and write
3E0000
heap
page read and write
2724000
heap
page read and write
77000
heap
page read and write
5CA0000
trusted library allocation
page read and write
555E000
stack
page read and write
177000
trusted library allocation
page execute and read and write
B0E000
stack
page read and write
1CE000
stack
page read and write
3797000
trusted library allocation
page read and write
6C0000
trusted library allocation
page read and write
6B0000
trusted library allocation
page read and write
DA7000
heap
page read and write
6B0000
trusted library allocation
page read and write
501E000
stack
page read and write
2180000
trusted library allocation
page read and write
2160000
trusted library allocation
page read and write
260000
trusted library allocation
page execute and read and write
103E000
stack
page read and write
540000
trusted library allocation
page read and write
160000
trusted library allocation
page read and write
1C3000
trusted library allocation
page execute and read and write
620000
heap
page execute and read and write
295F000
trusted library allocation
page read and write
540000
trusted library allocation
page read and write
2685000
heap
page read and write
47FE000
stack
page read and write
567000
heap
page read and write
2B7000
heap
page read and write
50000
unkown
page readonly
4C0000
trusted library allocation
page read and write
5D0000
trusted library allocation
page read and write
6B0000
trusted library allocation
page read and write
6F1E000
stack
page read and write
FFC000
stack
page read and write
400000
remote allocation
page execute and read and write
6B0000
trusted library allocation
page read and write
7E0000
trusted library allocation
page read and write
610000
trusted library allocation
page read and write
63E000
stack
page read and write
400000
trusted library allocation
page read and write
2A0000
trusted library allocation
page execute and read and write
3698000
trusted library allocation
page read and write
1ED000
trusted library allocation
page execute and read and write
461E000
stack
page read and write
54DE000
stack
page read and write
21D000
trusted library allocation
page execute and read and write
637E000
stack
page read and write | page guard
6A0000
trusted library allocation
page read and write
630000
trusted library allocation
page read and write
25C000
stack
page read and write
424000
heap
page read and write
3620000
trusted library allocation
page read and write
2ED000
heap
page read and write
26B000
stack
page read and write
35B9000
trusted library allocation
page read and write
4C0000
trusted library allocation
page read and write
610000
trusted library allocation
page read and write
C0000
unkown
page readonly
210F000
stack
page read and write
72D000
heap
page read and write
5BA0000
trusted library allocation
page read and write
847000
heap
page read and write
650000
trusted library allocation
page read and write
10000
heap
page read and write
814000
trusted library allocation
page read and write
49BE000
stack
page read and write
DC5000
heap
page read and write
10000
heap
page read and write
668D000
stack
page read and write
60000
unkown
page readonly
50000
unkown
page readonly
E20000
heap
page read and write
50000
unkown
page readonly
380E000
trusted library allocation
page read and write
520000
heap
page read and write
650000
trusted library allocation
page read and write
34E1000
trusted library allocation
page read and write
5E0D000
stack
page read and write
5F0000
trusted library allocation
page read and write
533D000
stack
page read and write
17F000
stack
page read and write
2271000
trusted library allocation
page read and write
1D7000
trusted library allocation
page execute and read and write
5050000
trusted library section
page read and write
42D000
heap
page read and write
570000
heap
page execute and read and write
1E0000
trusted library allocation
page read and write
4F4E000
stack
page read and write
20000
heap
page read and write
1DB000
trusted library allocation
page execute and read and write
EE000
heap
page read and write
172000
trusted library allocation
page read and write
350000
heap
page read and write
207000
trusted library allocation
page execute and read and write
1FAB000
heap
page read and write
3610000
trusted library allocation
page read and write
A0000
heap
page read and write
4A5E000
stack
page read and write
237F000
stack
page read and write
226E000
stack
page read and write
1DD000
trusted library allocation
page execute and read and write
1D4000
trusted library allocation
page read and write
2210000
trusted library allocation
page read and write
52FE000
stack
page read and write
D3000
trusted library allocation
page execute and read and write
5F0000
trusted library allocation
page read and write
2401000
trusted library allocation
page read and write
F6F000
stack
page read and write
29F000
stack
page read and write
1D0000
trusted library allocation
page read and write
24E1000
trusted library allocation
page read and write
6B0000
heap
page read and write
5D0000
trusted library allocation
page read and write
635E000
stack
page read and write
50000
unkown
page readonly
2851000
trusted library allocation
page read and write
4A70000
heap
page execute and read and write
A0000
unkown
page readonly
BD000
trusted library allocation
page execute and read and write
D32000
unkown
page execute read
AFD000
stack
page read and write
600000
trusted library allocation
page read and write
3688000
trusted library allocation
page read and write
140000
trusted library allocation
page read and write
683000
heap
page read and write
62E000
stack
page read and write
55FE000
stack
page read and write
F3000
heap
page read and write
1C4000
trusted library allocation
page read and write
550000
trusted library allocation
page read and write
63A0000
trusted library allocation
page read and write
50000
unkown
page readonly
421000
heap
page read and write
440000
trusted library allocation
page read and write
3D61000
trusted library allocation
page read and write
2F6000
heap
page read and write
4F8C000
stack
page read and write
3D0000
trusted library allocation
page read and write
3E5000
stack
page read and write
5BA0000
trusted library allocation
page read and write
590000
trusted library allocation
page read and write
2C6000
heap
page read and write
10000
heap
page read and write
10000
heap
page read and write
6B0000
heap
page read and write
1E0000
trusted library allocation
page read and write
34F9000
trusted library allocation
page read and write
371F000
trusted library allocation
page read and write
510000
trusted library allocation
page read and write
1E0000
trusted library allocation
page read and write
864000
heap
page read and write
576C000
stack
page read and write
D3A000
unkown
page readonly
572000
heap
page read and write
63A8000
trusted library allocation
page read and write
690E000
stack
page read and write
284000
heap
page read and write
5E5000
trusted library allocation
page read and write
2586000
trusted library allocation
page read and write
50000
unkown
page readonly
610000
trusted library allocation
page read and write
63B8000
trusted library allocation
page read and write
5190000
trusted library allocation
page read and write
5D0000
trusted library allocation
page read and write
400000
trusted library allocation
page read and write
42F000
heap
page read and write
3E0000
unkown
page readonly
3401000
trusted library allocation
page read and write
2220000
trusted library allocation
page read and write
654000
heap
page read and write
1B0000
trusted library allocation
page read and write
338C000
trusted library allocation
page read and write
422000
remote allocation
page execute and read and write
6B0000
trusted library allocation
page read and write
1B0000
trusted library allocation
page execute and read and write
134000
trusted library allocation
page read and write
51A8000
trusted library allocation
page read and write
49D000
heap
page read and write
540000
trusted library allocation
page read and write
510000
trusted library allocation
page read and write
A4E000
stack
page read and write
37A7000
trusted library allocation
page read and write
650000
trusted library allocation
page read and write
4FE0000
trusted library allocation
page read and write
A0000
unkown
page readonly
523E000
stack
page read and write
5E0000
trusted library allocation
page read and write
5F0000
trusted library allocation
page read and write
290000
heap
page read and write
8CB000
heap
page read and write
6B0000
trusted library allocation
page read and write
5A0000
heap
page execute and read and write
226E000
stack
page read and write | page guard
3E2000
unkown
page execute read
5FE000
stack
page read and write
2B0000
heap
page read and write
23A000
stack
page read and write
390000
trusted library allocation
page read and write
215E000
stack
page read and write
69F000
stack
page read and write
5E0000
trusted library section
page read and write
6390000
trusted library allocation
page read and write
4EEE000
stack
page read and write
4A1E000
stack
page read and write
7EF40000
trusted library allocation
page execute and read and write
510D000
stack
page read and write
51A3000
trusted library allocation
page read and write
2B0000
trusted library allocation
page read and write
457000
heap
page read and write
7D0000
heap
page read and write
5D0000
trusted library allocation
page read and write
6B0000
trusted library allocation
page read and write
26EA000
trusted library allocation
page read and write
624D000
stack
page read and write
34E1000
trusted library allocation
page read and write
656000
trusted library allocation
page read and write
210000
trusted library allocation
page read and write
51AA000
trusted library allocation
page read and write
10000
heap
page read and write
600000
trusted library allocation
page read and write
3C8000
stack
page read and write
20B0000
heap
page read and write
538000
heap
page read and write
6E0000
trusted library allocation
page read and write
294000
heap
page read and write
1074000
heap
page read and write
540000
trusted library allocation
page read and write
1E5000
trusted library allocation
page read and write
270000
heap
page read and write
D3F000
stack
page read and write
7D4000
heap
page read and write
5EE000
stack
page read and write
565E000
stack
page read and write
51AE000
stack
page read and write
640000
heap
page read and write
372F000
trusted library allocation
page read and write
2C0000
heap
page read and write
69D000
stack
page read and write
136000
unkown
page readonly
6E0000
heap
page read and write
4F90000
heap
page execute and read and write
5D6E000
stack
page read and write
650000
trusted library allocation
page read and write
518F000
trusted library allocation
page read and write
20A0000
trusted library allocation
page read and write
156000
trusted library allocation
page execute and read and write
450000
heap
page read and write
5F0000
trusted library allocation
page read and write
519A000
trusted library allocation
page read and write
5193000
trusted library allocation
page read and write
540000
trusted library allocation
page read and write
43BF000
stack
page read and write
460F000
stack
page read and write
25C000
stack
page read and write
264E000
trusted library allocation
page read and write
A0000
unkown
page readonly
1CD000
trusted library allocation
page execute and read and write
93B000
heap
page read and write
5193000
trusted library allocation
page read and write
67AD000
stack
page read and write
5E0000
trusted library allocation
page read and write
28AF000
trusted library allocation
page read and write
88D000
heap
page read and write
4EFD000
trusted library allocation
page read and write
1BB000
stack
page read and write
4ACE000
stack
page read and write
1D2000
trusted library allocation
page read and write
640000
trusted library allocation
page read and write
60000
unkown
page readonly
5E0000
trusted library allocation
page read and write
50000
unkown
page readonly
2F2000
heap
page read and write
515E000
stack
page read and write
704000
heap
page read and write
1BD000
trusted library allocation
page execute and read and write
5E0000
heap
page execute and read and write
8E6000
heap
page read and write
18B000
stack
page read and write
6D0000
trusted library allocation
page read and write
277000
trusted library allocation
page execute and read and write
282F000
trusted library allocation
page read and write
DA0000
heap
page read and write
704E000
unkown
page read and write
A0000
unkown
page readonly
50000
unkown
page readonly
15A000
trusted library allocation
page execute and read and write
6E0000
trusted library allocation
page read and write
87E000
stack
page read and write
6D0E000
stack
page read and write
26AE000
trusted library allocation
page read and write
608000
trusted library allocation
page read and write
300000
heap
page read and write
23C1000
trusted library allocation
page read and write
60EE000
stack
page read and write
1C7000
trusted library allocation
page execute and read and write
400000
remote allocation
page execute and read and write
508000
stack
page read and write
6C0000
trusted library allocation
page execute and read and write
6ABD000
stack
page read and write
26FC000
trusted library allocation
page read and write
60000
unkown
page readonly
2D0000
heap
page read and write
2532000
trusted library allocation
page read and write
3A7000
heap
page read and write
600000
trusted library allocation
page read and write
6F0000
trusted library allocation
page read and write
1D0000
heap
page execute and read and write
4C0000
trusted library allocation
page read and write
10000
heap
page read and write
16D000
trusted library allocation
page execute and read and write
30000
heap
page read and write
10000
heap
page read and write
57F000
stack
page read and write
237000
trusted library allocation
page execute and read and write
226F000
stack
page read and write
21B0000
trusted library allocation
page read and write
7AD000
heap
page read and write
36B8000
trusted library allocation
page read and write
1092000
heap
page read and write
1EC0000
heap
page read and write
25A6000
trusted library allocation
page read and write
23B000
trusted library allocation
page execute and read and write
D7F000
stack
page read and write
64E000
stack
page read and write
27B000
trusted library allocation
page execute and read and write
5D0000
trusted library allocation
page read and write
20F000
stack
page read and write
2090000
heap
page execute and read and write
5D0000
trusted library allocation
page read and write
6B0000
trusted library allocation
page read and write
2680000
heap
page read and write
E20000
heap
page execute and read and write
D3A000
unkown
page readonly
51A5000
trusted library allocation
page read and write
D3E000
stack
page read and write | page guard
6B0000
trusted library allocation
page read and write
FDE000
stack
page read and write
560000
heap
page read and write
2B0000
heap
page read and write
348000
stack
page read and write
B3000
trusted library allocation
page execute and read and write
36A8000
trusted library allocation
page read and write
880000
heap
page read and write
51CB000
trusted library allocation
page read and write
2170000
trusted library allocation
page read and write
24E1000
trusted library allocation
page read and write
There are 637 hidden memdumps, click here to show them.

DOM / HTML

URL
Malicious
4,0,403183674,0000000000138000,00000002,00000001,01000000,00000003,3,2C678C69C60A9225