IOC Report
APT41.exe

loading gif

Files

File Path
Type
Category
Malicious
APT41.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
initial sample
malicious
C:\Program Files (x86)\DHCP Monitor\dhcpmon.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Program Files (x86)\DHCP Monitor\dhcpmon.exe:Zone.Identifier
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\CLR_v2.0_32\UsageLogs\APT41.exe.log
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Local\Temp\tmpD2D4.tmp
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\run.dat
data
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\CLR_v2.0_32\UsageLogs\dhcpmon.exe.log
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\tmpD40E.tmp
XML 1.0 document, ASCII text, with CRLF line terminators
modified
C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\task.dat
ASCII text, with no line terminators
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\APT41.exe
C:\Users\user\Desktop\APT41.exe
malicious
C:\Windows\SysWOW64\schtasks.exe
schtasks.exe" /create /f /tn "DHCP Monitor" /xml "C:\Users\user\AppData\Local\Temp\tmpD2D4.tmp
malicious
C:\Windows\SysWOW64\schtasks.exe
schtasks.exe" /create /f /tn "DHCP Monitor Task" /xml "C:\Users\user\AppData\Local\Temp\tmpD40E.tmp
malicious
C:\Users\user\Desktop\APT41.exe
C:\Users\user\Desktop\APT41.exe 0
malicious
C:\Program Files (x86)\DHCP Monitor\dhcpmon.exe
"C:\Program Files (x86)\DHCP Monitor\dhcpmon.exe" 0
malicious
C:\Program Files (x86)\DHCP Monitor\dhcpmon.exe
"C:\Program Files (x86)\DHCP Monitor\dhcpmon.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

URLs

Name
IP
Malicious
229.ip.ply.gg
malicious
127.0.0.1
malicious

Domains

Name
IP
Malicious
229.ip.ply.gg
209.25.141.229
malicious

IPs

IP
Domain
Country
Malicious
209.25.141.229
229.ip.ply.gg
Canada
malicious
127.0.0.1
unknown
unknown
malicious

Registry

Path
Value
Malicious
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run
DHCP Monitor

Memdumps

Base Address
Regiontype
Protect
Malicious
46A1000
trusted library allocation
page read and write
malicious
5BA0000
trusted library section
page read and write
malicious
8A2000
unkown
page readonly
malicious
36A1000
trusted library allocation
page read and write
malicious
31F1000
trusted library allocation
page read and write
malicious
1500000
heap
page read and write
6363000
heap
page read and write
6341000
heap
page read and write
6344000
heap
page read and write
47A000
stack
page read and write
4005000
trusted library allocation
page read and write
29C2000
trusted library allocation
page read and write
A6B000
trusted library allocation
page execute and read and write
7D0000
heap
page read and write
5B80000
trusted library allocation
page read and write
9C0000
heap
page read and write
4090000
trusted library allocation
page read and write
5936000
trusted library allocation
page read and write
A10000
heap
page read and write
51D0000
trusted library allocation
page read and write
6363000
heap
page read and write
6367000
heap
page read and write
6344000
heap
page read and write
6363000
heap
page read and write
4F1E000
stack
page read and write
6344000
heap
page read and write
6341000
heap
page read and write
6354000
heap
page read and write
946000
heap
page read and write
4B10000
trusted library allocation
page read and write
635B000
heap
page read and write
6344000
heap
page read and write
6341000
heap
page read and write
FF7000
heap
page read and write
FC6000
heap
page read and write
3500000
heap
page read and write
DFE000
stack
page read and write
5952000
trusted library allocation
page read and write
127A000
trusted library allocation
page execute and read and write
5080000
trusted library allocation
page read and write
5FB7000
heap
page read and write
6344000
heap
page read and write
4106000
trusted library allocation
page read and write
635D000
heap
page read and write
CBF000
stack
page read and write
51F0000
trusted library allocation
page read and write
6344000
heap
page read and write
6351000
heap
page read and write
5935000
trusted library allocation
page read and write
5BFE000
stack
page read and write
720000
heap
page read and write
6368000
heap
page read and write
635B000
heap
page read and write
3F37000
trusted library allocation
page read and write
5B85000
trusted library allocation
page read and write
6362000
heap
page read and write
197E000
stack
page read and write
4C80000
trusted library allocation
page read and write
4C66000
trusted library allocation
page read and write
6341000
heap
page read and write
3F99000
trusted library allocation
page read and write
4151000
trusted library allocation
page read and write
5930000
trusted library allocation
page read and write
6351000
heap
page read and write
41D4000
trusted library allocation
page read and write
4B10000
trusted library allocation
page read and write
418F000
trusted library allocation
page read and write
6580000
trusted library allocation
page read and write
3F21000
trusted library allocation
page read and write
414C000
trusted library allocation
page read and write
3E61000
trusted library allocation
page read and write
2D80000
heap
page read and write
29A0000
trusted library allocation
page read and write
5085000
trusted library allocation
page read and write
6341000
heap
page read and write
5930000
trusted library allocation
page read and write
E0E000
stack
page read and write
10BA000
stack
page read and write
6341000
heap
page read and write
51C0000
trusted library allocation
page read and write
54B0000
trusted library allocation
page read and write
6344000
heap
page read and write
6363000
heap
page read and write
1280000
trusted library allocation
page read and write
6367000
heap
page read and write
51C0000
heap
page execute and read and write
5B80000
trusted library allocation
page read and write
4C77000
trusted library allocation
page read and write
F2B000
heap
page read and write
FF3000
heap
page read and write
5F81000
heap
page read and write
1A9D000
stack
page read and write
6354000
heap
page read and write
4E68000
trusted library allocation
page read and write
5AF0000
heap
page execute and read and write
1600000
trusted library allocation
page read and write
8EA000
heap
page read and write
5300000
trusted library section
page read and write
4F3E000
stack
page read and write
54B0000
trusted library allocation
page read and write
6341000
heap
page read and write
6341000
heap
page read and write
54B0000
trusted library allocation
page read and write
5930000
trusted library allocation
page read and write
6341000
heap
page read and write
51D7000
trusted library allocation
page read and write
410D000
trusted library allocation
page read and write
415B000
trusted library allocation
page read and write
7D5000
heap
page read and write
5930000
trusted library allocation
page read and write
2D50000
trusted library allocation
page read and write
6367000
heap
page read and write
343F000
stack
page read and write
5210000
trusted library allocation
page read and write
6344000
heap
page read and write
6354000
heap
page read and write
403B000
trusted library allocation
page read and write
F97000
heap
page read and write
4F5E000
stack
page read and write
FDC000
heap
page read and write
FF1000
heap
page read and write
30E0000
trusted library allocation
page read and write
29A2000
trusted library allocation
page read and write
6090000
trusted library allocation
page read and write
51D0000
trusted library allocation
page read and write
1A50000
heap
page execute and read and write
6341000
heap
page read and write
6341000
heap
page read and write
4C90000
trusted library allocation
page read and write
60B0000
heap
page execute and read and write
6363000
heap
page read and write
6341000
heap
page read and write
2F8C000
trusted library allocation
page read and write
5CE000
unkown
page read and write
6344000
heap
page read and write
5F7D000
stack
page read and write
51D5000
trusted library allocation
page read and write
4037000
trusted library allocation
page read and write
6354000
heap
page read and write
4106000
trusted library allocation
page read and write
3050000
heap
page read and write
4C60000
trusted library allocation
page read and write
4058000
trusted library allocation
page read and write
6363000
heap
page read and write
161A000
trusted library allocation
page execute and read and write
6341000
heap
page read and write
31FE000
stack
page read and write
6354000
heap
page read and write
6341000
heap
page read and write
6354000
heap
page read and write
6341000
heap
page read and write
136A000
trusted library allocation
page execute and read and write
410D000
trusted library allocation
page read and write
4059000
trusted library allocation
page read and write
2EAE000
stack
page read and write
6590000
trusted library allocation
page read and write
8C2000
unkown
page readonly
57E0000
trusted library allocation
page read and write
5950000
trusted library allocation
page read and write
6341000
heap
page read and write
6354000
heap
page read and write
1370000
trusted library allocation
page read and write
6341000
heap
page read and write
6341000
heap
page read and write
54B6000
trusted library allocation
page read and write
6341000
heap
page read and write
5BFE000
stack
page read and write
3FE4000
trusted library allocation
page read and write
F6D000
stack
page read and write
6367000
heap
page read and write
552E000
stack
page read and write
3953000
trusted library allocation
page read and write
596E000
stack
page read and write
7F280000
trusted library allocation
page execute and read and write
5546000
heap
page execute and read and write
4164000
trusted library allocation
page read and write
6351000
heap
page read and write
4073000
trusted library allocation
page read and write
6341000
heap
page read and write
505E000
stack
page read and write
6354000
heap
page read and write
1380000
heap
page read and write
40E9000
trusted library allocation
page read and write
6354000
heap
page read and write
57C0000
trusted library allocation
page read and write
3F7D000
trusted library allocation
page read and write
30DD000
trusted library allocation
page read and write
6354000
heap
page read and write
193E000
stack
page read and write
6367000
heap
page read and write
4165000
trusted library allocation
page read and write
51D0000
trusted library allocation
page read and write
54B7000
trusted library allocation
page read and write
11C0000
heap
page read and write
6354000
heap
page read and write
5935000
trusted library allocation
page read and write
51D0000
trusted library allocation
page read and write
6341000
heap
page read and write
54B0000
trusted library allocation
page read and write
6354000
heap
page read and write
40B6000
trusted library allocation
page read and write
6344000
heap
page read and write
5932000
trusted library allocation
page read and write
1630000
trusted library allocation
page read and write
40B6000
trusted library allocation
page read and write
6351000
heap
page read and write
405F000
trusted library allocation
page read and write
8FB000
heap
page read and write
6362000
heap
page read and write
3FB8000
trusted library allocation
page read and write
5484000
heap
page read and write
57E0000
trusted library allocation
page read and write
6344000
heap
page read and write
6341000
heap
page read and write
12F0000
heap
page read and write
4014000
trusted library allocation
page read and write
4167000
trusted library allocation
page read and write
6353000
heap
page read and write
52BE000
stack
page read and write
5FBC000
heap
page read and write
5F81000
heap
page read and write
5320000
heap
page execute and read and write
5800000
trusted library allocation
page read and write
1308000
heap
page read and write
51D0000
trusted library allocation
page read and write
51C0000
trusted library allocation
page read and write
3F7C000
trusted library allocation
page read and write
5B80000
trusted library allocation
page read and write
FEC000
heap
page read and write
6354000
heap
page read and write
5910000
trusted library allocation
page read and write
41BB000
trusted library allocation
page read and write
5937000
trusted library allocation
page read and write
635B000
heap
page read and write
6341000
heap
page read and write
40F1000
trusted library allocation
page read and write
5910000
trusted library allocation
page read and write
12B0000
trusted library allocation
page read and write
1AB0000
heap
page read and write
3FDB000
trusted library allocation
page read and write
4E1E000
stack
page read and write
5220000
heap
page read and write
8A0000
unkown
page readonly
5B80000
trusted library section
page read and write
A2A000
trusted library allocation
page execute and read and write
3F3D000
trusted library allocation
page read and write
1297000
trusted library allocation
page execute and read and write
FF3000
heap
page read and write
5200000
trusted library allocation
page read and write
6440000
trusted library allocation
page read and write
E10000
heap
page read and write
51D0000
trusted library allocation
page read and write
51D6000
trusted library allocation
page read and write
51D0000
trusted library allocation
page read and write
309A000
trusted library allocation
page read and write
6354000
heap
page read and write
40EF000
trusted library allocation
page read and write
405B000
trusted library allocation
page read and write
5080000
trusted library allocation
page read and write
6341000
heap
page read and write
54B0000
trusted library allocation
page read and write
5930000
trusted library allocation
page read and write
4C70000
trusted library allocation
page read and write
519F000
stack
page read and write
403B000
trusted library allocation
page read and write
6354000
heap
page read and write
2D50000
trusted library allocation
page read and write
405F000
trusted library allocation
page read and write
2D50000
trusted library allocation
page read and write
5B88000
trusted library allocation
page read and write
6344000
heap
page read and write
5FB3000
heap
page read and write
51C6000
trusted library allocation
page read and write
5180000
heap
page read and write
6344000
heap
page read and write
6344000
heap
page read and write
6344000
heap
page read and write
54B0000
trusted library allocation
page read and write
5AAE000
stack
page read and write
6341000
heap
page read and write
5916000
trusted library allocation
page read and write
6354000
heap
page read and write
54B5000
trusted library allocation
page read and write
5936000
trusted library allocation
page read and write
5930000
trusted library allocation
page read and write
F5B000
heap
page read and write
6344000
heap
page read and write
51D0000
trusted library allocation
page read and write
6351000
heap
page read and write
51D0000
trusted library allocation
page read and write
1125000
heap
page read and write
6363000
heap
page read and write
3120000
trusted library allocation
page read and write
6341000
heap
page read and write
6354000
heap
page read and write
160C000
trusted library allocation
page execute and read and write
30E2000
trusted library allocation
page read and write
54B0000
trusted library allocation
page read and write
FAA000
stack
page read and write
5914000
trusted library allocation
page read and write
6354000
heap
page read and write
4CA0000
trusted library allocation
page read and write
6341000
heap
page read and write
FE7000
heap
page read and write
6340000
heap
page read and write
6341000
heap
page read and write
4DDE000
stack
page read and write
4CA2000
trusted library allocation
page read and write
4148000
trusted library allocation
page read and write
40B6000
trusted library allocation
page read and write
6341000
heap
page read and write
6363000
heap
page read and write
41B2000
trusted library allocation
page read and write
405B000
trusted library allocation
page read and write
6344000
heap
page read and write
4CDD000
stack
page read and write
3F7C000
trusted library allocation
page read and write
4126000
trusted library allocation
page read and write
51D0000
trusted library allocation
page read and write
4C76000
trusted library allocation
page read and write
6344000
heap
page read and write
40B6000
trusted library allocation
page read and write
14A0000
heap
page read and write
6341000
heap
page read and write
6362000
heap
page read and write
4C76000
trusted library allocation
page read and write
635B000
heap
page read and write
8E0000
heap
page read and write
51D0000
trusted library allocation
page read and write
1602000
trusted library allocation
page execute and read and write
5FB6000
heap
page read and write
6341000
heap
page read and write
12B7000
trusted library allocation
page execute and read and write
6341000
heap
page read and write
4092000
trusted library allocation
page read and write
635B000
heap
page read and write
6341000
heap
page read and write
4092000
trusted library allocation
page read and write
41B1000
trusted library allocation
page read and write
6344000
heap
page read and write
405B000
trusted library allocation
page read and write
3F36000
trusted library allocation
page read and write
6354000
heap
page read and write
4035000
trusted library allocation
page read and write
5A40000
trusted library allocation
page read and write
FE9000
heap
page read and write
5E3E000
stack
page read and write
4052000
trusted library allocation
page read and write
3508000
heap
page read and write
4090000
trusted library allocation
page read and write
6344000
heap
page read and write
6354000
heap
page read and write
51D6000
trusted library allocation
page read and write
4C7E000
trusted library allocation
page read and write
5BC5000
trusted library allocation
page read and write
5450000
heap
page read and write
51D0000
trusted library allocation
page read and write
593E000
stack
page read and write
6354000
heap
page read and write
6354000
heap
page read and write
6344000
heap
page read and write
4034000
trusted library allocation
page read and write
6341000
heap
page read and write
3F21000
trusted library allocation
page read and write
54A0000
trusted library allocation
page read and write
54B0000
trusted library allocation
page read and write
3F8C000
trusted library allocation
page read and write
A70000
heap
page read and write
6344000
heap
page read and write
129A000
trusted library allocation
page execute and read and write
6353000
heap
page read and write
4015000
trusted library allocation
page read and write
6344000
heap
page read and write
561E000
stack
page read and write
6344000
heap
page read and write
6354000
heap
page read and write
6341000
heap
page read and write
41BC000
trusted library allocation
page read and write
6353000
heap
page read and write
6344000
heap
page read and write
4039000
trusted library allocation
page read and write
6354000
heap
page read and write
6354000
heap
page read and write
6341000
heap
page read and write
29B2000
trusted library allocation
page execute and read and write
4092000
trusted library allocation
page read and write
3F21000
trusted library allocation
page read and write
415B000
trusted library allocation
page read and write
6354000
heap
page read and write
40E9000
trusted library allocation
page read and write
6341000
heap
page read and write
4165000
trusted library allocation
page read and write
40B1000
trusted library allocation
page read and write
3F3C000
trusted library allocation
page read and write
6354000
heap
page read and write
51B0000
trusted library allocation
page execute and read and write
6354000
heap
page read and write
5930000
trusted library allocation
page read and write
6344000
heap
page read and write
6341000
heap
page read and write
5205000
trusted library allocation
page read and write
5930000
trusted library allocation
page read and write
37C0000
heap
page read and write
6341000
heap
page read and write
5B80000
trusted library allocation
page read and write
6341000
heap
page read and write
4C70000
trusted library allocation
page read and write
6367000
heap
page read and write
3F5D000
trusted library allocation
page read and write
2CEE000
stack
page read and write
6362000
heap
page read and write
6344000
heap
page read and write
54C0000
trusted library allocation
page read and write
4C76000
trusted library allocation
page read and write
6351000
heap
page read and write
589C000
stack
page read and write
6364000
heap
page read and write
5930000
trusted library allocation
page read and write
6341000
heap
page read and write
6341000
heap
page read and write
5930000
trusted library allocation
page read and write
40E9000
trusted library allocation
page read and write
6344000
heap
page read and write
6341000
heap
page read and write
41AB000
trusted library allocation
page read and write
51C0000
trusted library allocation
page read and write
E30000
heap
page read and write
7CE000
stack
page read and write
F1E000
stack
page read and write
6354000
heap
page read and write
6367000
heap
page read and write
41B1000
trusted library allocation
page read and write
6344000
heap
page read and write
5200000
trusted library allocation
page read and write
4B80000
heap
page read and write
6364000
heap
page read and write
FFA000
heap
page read and write
4B10000
trusted library allocation
page read and write
6354000
heap
page read and write
51D0000
trusted library allocation
page read and write
57E5000
trusted library allocation
page read and write
4005000
trusted library allocation
page read and write
635B000
heap
page read and write
4034000
trusted library allocation
page read and write
635B000
heap
page read and write
15FA000
trusted library allocation
page execute and read and write
6344000
heap
page read and write
6344000
heap
page read and write
FEC000
heap
page read and write
311C000
trusted library allocation
page read and write
509E000
stack
page read and write
29AA000
trusted library allocation
page execute and read and write
6341000
heap
page read and write
6354000
heap
page read and write
4C70000
trusted library allocation
page read and write
6341000
heap
page read and write
6368000
heap
page read and write
3F8F000
trusted library allocation
page read and write
128C000
trusted library allocation
page execute and read and write
4C60000
trusted library allocation
page read and write
635B000
heap
page read and write
292D000
trusted library allocation
page read and write
293E000
trusted library allocation
page read and write
6344000
heap
page read and write
6354000
heap
page read and write
7FCB0000
trusted library allocation
page execute and read and write
6341000
heap
page read and write
6341000
heap
page read and write
2941000
trusted library allocation
page read and write
6354000
heap
page read and write
6341000
heap
page read and write
4C70000
trusted library allocation
page read and write
6344000
heap
page read and write
3FE2000
trusted library allocation
page read and write
6354000
heap
page read and write
40B2000
trusted library allocation
page read and write
4C76000
trusted library allocation
page read and write
54B7000
trusted library allocation
page read and write
1230000
heap
page read and write
5CFE000
stack
page read and write
415B000
trusted library allocation
page read and write
51D6000
trusted library allocation
page read and write
408E000
trusted library allocation
page read and write
149E000
stack
page read and write
6354000
heap
page read and write
565E000
stack
page read and write
FA5000
heap
page read and write
6354000
heap
page read and write
133C000
heap
page read and write
5B80000
trusted library allocation
page read and write
5080000
trusted library allocation
page read and write
5307000
trusted library allocation
page read and write
6344000
heap
page read and write
4019000
trusted library allocation
page read and write
6341000
heap
page read and write
416D000
trusted library allocation
page read and write
6364000
heap
page read and write
4B15000
trusted library allocation
page read and write
415C000
trusted library allocation
page read and write
5070000
trusted library allocation
page read and write
6341000
heap
page read and write
6341000
heap
page read and write
6344000
heap
page read and write
1372000
trusted library allocation
page execute and read and write
6354000
heap
page read and write
51D0000
trusted library allocation
page read and write
3F5C000
trusted library allocation
page read and write
6354000
heap
page read and write
51D6000
trusted library allocation
page read and write
6341000
heap
page read and write
41B7000
trusted library allocation
page read and write
6341000
heap
page read and write
51E0000
trusted library allocation
page read and write
41EE000
trusted library allocation
page read and write
6363000
heap
page read and write
6354000
heap
page read and write
6344000
heap
page read and write
54B0000
trusted library allocation
page read and write
54A0000
heap
page execute and read and write
4148000
trusted library allocation
page read and write
6354000
heap
page read and write
5936000
trusted library allocation
page read and write
6344000
heap
page read and write
4165000
trusted library allocation
page read and write
40B1000
trusted library allocation
page read and write
FDA000
heap
page read and write
4108000
trusted library allocation
page read and write
6344000
heap
page read and write
5930000
trusted library allocation
page read and write
54B0000
trusted library allocation
page read and write
6344000
heap
page read and write
6354000
heap
page read and write
41B4000
trusted library allocation
page read and write
4096000
trusted library allocation
page read and write
6341000
heap
page read and write
6341000
heap
page read and write
6344000
heap
page read and write
410A000
trusted library allocation
page read and write
6341000
heap
page read and write
54B6000
trusted library allocation
page read and write
6344000
heap
page read and write
2D60000
trusted library allocation
page execute and read and write
1610000
trusted library allocation
page read and write
41BD000
trusted library allocation
page read and write
6580000
unkown
page read and write
2B0E000
stack
page read and write
54D2000
trusted library allocation
page read and write
4008000
trusted library allocation
page read and write
5B7B000
stack
page read and write
6367000
heap
page read and write
5E7D000
stack
page read and write
6353000
heap
page read and write
14B0000
heap
page read and write
4070000
trusted library allocation
page read and write
6341000
heap
page read and write
57E0000
trusted library allocation
page read and write
6354000
heap
page read and write
564E000
stack
page read and write
6354000
heap
page read and write
5FB6000
heap
page read and write
14B5000
heap
page read and write
6341000
heap
page read and write
41B7000
trusted library allocation
page read and write
54A6000
trusted library allocation
page read and write
5930000
trusted library allocation
page read and write
4106000
trusted library allocation
page read and write
6363000
heap
page read and write
6354000
heap
page read and write
6344000
heap
page read and write
2D50000
trusted library allocation
page read and write
4257000
trusted library allocation
page read and write
51DC000
trusted library allocation
page read and write
6341000
heap
page read and write
6341000
heap
page read and write
FC0000
heap
page read and write
3F21000
trusted library allocation
page read and write
4106000
trusted library allocation
page read and write
4132000
trusted library allocation
page read and write
4C77000
trusted library allocation
page read and write
54A4000
trusted library allocation
page read and write
6341000
heap
page read and write
54A0000
trusted library allocation
page read and write
64F000
unkown
page read and write
6341000
heap
page read and write
41ED000
trusted library allocation
page read and write
4C70000
trusted library allocation
page read and write
51E0000
trusted library allocation
page read and write
FED000
heap
page read and write
15E0000
trusted library allocation
page read and write
29BA000
trusted library allocation
page execute and read and write
5F81000
heap
page read and write
6344000
heap
page read and write
3060000
heap
page read and write
11A0000
heap
page read and write
54B0000
trusted library allocation
page read and write
4C90000
heap
page execute and read and write
5480000
heap
page read and write
3FD8000
trusted library allocation
page read and write
14FE000
stack
page read and write
6363000
heap
page read and write
E10000
trusted library allocation
page read and write
39A0000
trusted library allocation
page read and write
BD0000
heap
page read and write
54B0000
trusted library allocation
page read and write
4B84000
heap
page read and write
FC6000
heap
page read and write
3FA000
stack
page read and write
6344000
heap
page read and write
54BC000
trusted library allocation
page read and write
29C7000
trusted library allocation
page execute and read and write
5210000
trusted library allocation
page execute and read and write
11B6000
stack
page read and write
415E000
trusted library allocation
page read and write
1640000
heap
page read and write
6341000
heap
page read and write
410E000
trusted library allocation
page read and write
3F21000
trusted library allocation
page read and write
A22000
trusted library allocation
page execute and read and write
BBE000
stack
page read and write
4C72000
trusted library allocation
page read and write
5080000
trusted library allocation
page read and write
6344000
heap
page read and write
6341000
heap
page read and write
6344000
heap
page read and write
6341000
heap
page read and write
6344000
heap
page read and write
5920000
trusted library allocation
page execute and read and write
6341000
heap
page read and write
4180000
trusted library allocation
page read and write
57D0000
heap
page read and write
6354000
heap
page read and write
6090000
unclassified section
page read and write
6341000
heap
page read and write
5B80000
trusted library allocation
page read and write
4C70000
trusted library allocation
page read and write
11F0000
heap
page read and write
6363000
heap
page read and write
3F8E000
trusted library allocation
page read and write
575F000
stack
page read and write
F00000
heap
page read and write
6362000
heap
page read and write
6341000
heap
page read and write
5910000
trusted library allocation
page read and write
6344000
heap
page read and write
6354000
heap
page read and write
54B0000
trusted library allocation
page read and write
6344000
heap
page read and write
3EA5000
trusted library allocation
page read and write
54C0000
trusted library allocation
page read and write
6341000
heap
page read and write
6CE000
stack
page read and write
6344000
heap
page read and write
503E000
stack
page read and write
6341000
heap
page read and write
3FD8000
trusted library allocation
page read and write
A90000
heap
page read and write
5B90000
trusted library allocation
page read and write
A3C000
trusted library allocation
page execute and read and write
54B6000
trusted library allocation
page read and write
5B80000
trusted library allocation
page read and write
5936000
trusted library allocation
page read and write
6341000
heap
page read and write
54B5000
trusted library allocation
page read and write
96A000
stack
page read and write
54D0000
trusted library allocation
page read and write
6341000
heap
page read and write
3921000
trusted library allocation
page read and write
6341000
heap
page read and write
5FBA000
heap
page read and write
54B0000
trusted library allocation
page read and write
335E000
stack
page read and write
6344000
heap
page read and write
6354000
heap
page read and write
6344000
heap
page read and write
3F8B000
trusted library allocation
page read and write
6341000
heap
page read and write
6341000
heap
page read and write
6341000
heap
page read and write
3987000
trusted library allocation
page read and write
3FBA000
trusted library allocation
page read and write
5910000
heap
page execute and read and write
4105000
trusted library allocation
page read and write
6341000
heap
page read and write
51F0000
heap
page read and write
6341000
heap
page read and write
1060000
heap
page read and write
6344000
heap
page read and write
410B000
trusted library allocation
page read and write
41C3000
trusted library allocation
page read and write
6341000
heap
page read and write
6344000
heap
page read and write
5B88000
trusted library allocation
page read and write
43D000
stack
page read and write
390000
heap
page read and write
F36000
stack
page read and write
4C80000
trusted library allocation
page read and write
420D000
trusted library allocation
page read and write
51D5000
trusted library allocation
page read and write
4160000
trusted library allocation
page read and write
6341000
heap
page read and write
600000
heap
page read and write
FF3000
heap
page read and write
6344000
heap
page read and write
2D40000
trusted library allocation
page read and write
41B7000
trusted library allocation
page read and write
6341000
heap
page read and write
6344000
heap
page read and write
54D0000
trusted library allocation
page read and write
6344000
heap
page read and write
11B0000
heap
page execute and read and write
6341000
heap
page read and write
3F21000
trusted library allocation
page read and write
51D0000
trusted library allocation
page read and write
4005000
trusted library allocation
page read and write
5B87000
trusted library allocation
page read and write
911000
heap
page read and write
51D0000
trusted library allocation
page read and write
6354000
heap
page read and write
6354000
heap
page read and write
6341000
heap
page read and write
6344000
heap
page read and write
6368000
heap
page read and write
405F000
trusted library allocation
page read and write
6351000
heap
page read and write
57E0000
trusted library allocation
page read and write
6354000
heap
page read and write
6344000
heap
page read and write
1190000
trusted library allocation
page read and write
11A5000
heap
page read and write
3F01000
trusted library allocation
page read and write
6344000
heap
page read and write
4C70000
trusted library allocation
page read and write
41A7000
trusted library allocation
page read and write
54B0000
trusted library allocation
page read and write
4C70000
trusted library allocation
page read and write
2F24000
trusted library allocation
page read and write
6344000
heap
page read and write
6341000
heap
page read and write
F20000
heap
page read and write
5930000
trusted library allocation
page read and write
15D0000
heap
page read and write
6368000
heap
page read and write
5F81000
heap
page read and write
54B0000
trusted library allocation
page read and write
6351000
heap
page read and write
3FDA000
trusted library allocation
page read and write
6344000
heap
page read and write
4C7C000
trusted library allocation
page read and write
4104000
trusted library allocation
page read and write
6354000
heap
page read and write
3FD9000
trusted library allocation
page read and write
5A3E000
stack
page read and write
6354000
heap
page read and write
6354000
heap
page read and write
4C70000
trusted library allocation
page read and write
4C70000
trusted library allocation
page read and write
F93000
heap
page read and write
A4A000
trusted library allocation
page execute and read and write
6341000
heap
page read and write
6F6000
stack
page read and write
4270000
trusted library allocation
page read and write
5AF6000
heap
page execute and read and write
51D0000
trusted library allocation
page read and write
4C70000
trusted library allocation
page read and write
54BE000
trusted library allocation
page read and write
5930000
trusted library allocation
page read and write
3F7C000
trusted library allocation
page read and write
4C70000
trusted library allocation
page read and write
403B000
trusted library allocation
page read and write
51D6000
trusted library allocation
page read and write
4004000
trusted library allocation
page read and write
4B10000
trusted library allocation
page read and write
54A0000
trusted library allocation
page read and write
6341000
heap
page read and write
4AFE000
stack
page read and write
5050000
trusted library allocation
page read and write
1300000
heap
page read and write
951000
heap
page read and write
AB0000
heap
page read and write
5F81000
heap
page read and write
51D0000
trusted library allocation
page read and write
3EE0000
trusted library allocation
page read and write
49FC000
stack
page read and write
405F000
trusted library allocation
page read and write
6344000
heap
page read and write
6341000
heap
page read and write
6354000
heap
page read and write
6354000
heap
page read and write
900000
heap
page read and write
6363000
heap
page read and write
5080000
trusted library allocation
page read and write
5316000
heap
page execute and read and write
4C70000
trusted library allocation
page read and write
6344000
heap
page read and write
41AF000
trusted library allocation
page read and write
40CC000
trusted library allocation
page read and write
3F01000
trusted library allocation
page read and write
3E87000
trusted library allocation
page read and write
6351000
heap
page read and write
2D2C000
stack
page read and write
6354000
heap
page read and write
6341000
heap
page read and write
6354000
heap
page read and write
6341000
heap
page read and write
6341000
heap
page read and write
4B30000
trusted library allocation
page read and write
6354000
heap
page read and write
3F01000
trusted library allocation
page read and write
5B91000
trusted library allocation
page read and write
3F5C000
trusted library allocation
page read and write
6374000
heap
page read and write
3FE4000
trusted library allocation
page read and write
FE4000
heap
page read and write
5B80000
trusted library allocation
page read and write
6344000
heap
page read and write
1637000
trusted library allocation
page execute and read and write
4B50000
heap
page read and write
FF7000
heap
page read and write
51C0000
trusted library allocation
page read and write
6341000
heap
page read and write
4C75000
trusted library allocation
page read and write
3FE2000
trusted library allocation
page read and write
51D0000
trusted library allocation
page read and write
3F21000
trusted library allocation
page read and write
4106000
trusted library allocation
page read and write
6341000
heap
page read and write
5B90000
trusted library allocation
page read and write
FEF000
heap
page read and write
4C70000
trusted library allocation
page read and write
5F81000
heap
page read and write
593E000
trusted library allocation
page read and write
6344000
heap
page read and write
6368000
heap
page read and write
635B000
heap
page read and write
51F0000
trusted library allocation
page read and write
12E0000
trusted library allocation
page read and write
8B0000
heap
page read and write
6341000
heap
page read and write
574E000
stack
page read and write
6341000
heap
page read and write
29CB000
trusted library allocation
page execute and read and write
4107000
trusted library allocation
page read and write
6341000
heap
page read and write
5930000
trusted library allocation
page read and write
403B000
trusted library allocation
page read and write
5930000
trusted library allocation
page read and write
6354000
heap
page read and write
3F5D000
trusted library allocation
page read and write
54B0000
trusted library allocation
page read and write
579E000
stack
page read and write
6367000
heap
page read and write
6341000
heap
page read and write
40AE000
trusted library allocation
page read and write
7F6F0000
trusted library allocation
page execute and read and write
6341000
heap
page read and write
4C75000
trusted library allocation
page read and write
3F01000
trusted library allocation
page read and write
54C8000
trusted library allocation
page read and write
415B000
trusted library allocation
page read and write
5930000
trusted library allocation
page read and write
5940000
trusted library allocation
page read and write
1050000
heap
page read and write
4C70000
trusted library allocation
page read and write
15F2000
trusted library allocation
page execute and read and write
10AE000
stack
page read and write
2EB4000
trusted library allocation
page read and write
FBF000
heap
page read and write
41BC000
trusted library allocation
page read and write
4C60000
heap
page execute and read and write
FEC000
heap
page read and write
4223000
trusted library allocation
page read and write
57A0000
trusted library allocation
page read and write
FE9000
heap
page read and write
3F37000
trusted library allocation
page read and write
40EE000
trusted library allocation
page read and write
3F01000
trusted library allocation
page read and write
6341000
heap
page read and write
145E000
stack
page read and write
3F7C000
trusted library allocation
page read and write
2DA0000
heap
page execute and read and write
410A000
trusted library allocation
page read and write
3F20000
trusted library allocation
page read and write
6341000
heap
page read and write
5930000
trusted library allocation
page read and write
54B0000
trusted library allocation
page read and write
164A000
heap
page read and write
41D8000
trusted library allocation
page read and write
41C3000
trusted library allocation
page read and write
54B0000
trusted library allocation
page read and write
6341000
heap
page read and write
57D3000
heap
page read and write
5A7D000
stack
page read and write
6354000
heap
page read and write
4092000
trusted library allocation
page read and write
6354000
heap
page read and write
1260000
trusted library allocation
page read and write
5B86000
trusted library allocation
page read and write
6362000
heap
page read and write
9F0000
heap
page execute and read and write
5D3D000
stack
page read and write
5940000
trusted library allocation
page read and write
6344000
heap
page read and write
6354000
heap
page read and write
54B0000
trusted library allocation
page read and write
6344000
heap
page read and write
5930000
trusted library allocation
page read and write
6344000
heap
page read and write
57E0000
trusted library allocation
page read and write
5937000
trusted library allocation
page read and write
6341000
heap
page read and write
3FD9000
trusted library allocation
page read and write
29A6000
trusted library allocation
page execute and read and write
5930000
trusted library allocation
page read and write
6363000
heap
page read and write
3F8D000
trusted library allocation
page read and write
4B10000
trusted library allocation
page read and write
6341000
heap
page read and write
5224000
heap
page read and write
5F81000
heap
page read and write
3FE6000
trusted library allocation
page read and write
163B000
trusted library allocation
page execute and read and write
51E8000
trusted library allocation
page read and write
5FB4000
heap
page read and write
6341000
heap
page read and write
6341000
heap
page read and write
3F21000
trusted library allocation
page read and write
6354000
heap
page read and write
4C76000
trusted library allocation
page read and write
54B2000
trusted library allocation
page read and write
6354000
heap
page read and write
4C70000
trusted library allocation
page read and write
6368000
heap
page read and write
6341000
heap
page read and write
4239000
trusted library allocation
page read and write
5490000
trusted library allocation
page execute and read and write
6354000
heap
page read and write
4C60000
trusted library allocation
page read and write
5F81000
heap
page read and write
393D000
trusted library allocation
page read and write
4C76000
trusted library allocation
page read and write
4B10000
trusted library allocation
page read and write
41B1000
trusted library allocation
page read and write
6341000
heap
page read and write
6368000
heap
page read and write
6363000
heap
page read and write
1290000
trusted library allocation
page read and write
4C64000
trusted library allocation
page read and write
50A0000
trusted library allocation
page read and write
6354000
heap
page read and write
6367000
heap
page read and write
3EC7000
trusted library allocation
page read and write
6363000
heap
page read and write
410D000
trusted library allocation
page read and write
51D0000
trusted library allocation
page read and write
6341000
heap
page read and write
6344000
heap
page read and write
635B000
heap
page read and write
5930000
trusted library allocation
page read and write
2D70000
trusted library allocation
page read and write
4C70000
trusted library allocation
page read and write
6344000
heap
page read and write
6363000
heap
page read and write
A10000
trusted library allocation
page read and write
FAD000
heap
page read and write
4165000
trusted library allocation
page read and write
6341000
heap
page read and write
6341000
heap
page read and write
4C80000
trusted library allocation
page read and write
579E000
stack
page read and write
54B0000
trusted library allocation
page read and write
6344000
heap
page read and write
4C70000
trusted library allocation
page read and write
4C96000
heap
page execute and read and write
6354000
heap
page read and write
5930000
trusted library allocation
page read and write
5080000
trusted library allocation
page read and write
6354000
heap
page read and write
FCB000
heap
page read and write
6341000
heap
page read and write
10EE000
stack
page read and write
3F36000
trusted library allocation
page read and write
5930000
trusted library allocation
page read and write
136E000
heap
page read and write
6354000
heap
page read and write
6363000
heap
page read and write
6344000
heap
page read and write
6363000
heap
page read and write
6354000
heap
page read and write
51D6000
trusted library allocation
page read and write
1673000
heap
page read and write
635B000
heap
page read and write
40AE000
trusted library allocation
page read and write
6363000
heap
page read and write
FBE000
heap
page read and write
4B20000
trusted library allocation
page execute and read and write
4092000
trusted library allocation
page read and write
6344000
heap
page read and write
31BF000
unkown
page read and write
41A9000
trusted library allocation
page read and write
29B0000
trusted library allocation
page read and write
6363000
heap
page read and write
6363000
heap
page read and write
54B0000
trusted library allocation
page read and write
54A0000
trusted library allocation
page read and write
41B0000
trusted library allocation
page read and write
57F0000
trusted library allocation
page execute and read and write
6354000
heap
page read and write
415A000
trusted library allocation
page read and write
3FF6000
trusted library allocation
page read and write
4196000
trusted library allocation
page read and write
6354000
heap
page read and write
5900000
trusted library allocation
page read and write
635B000
heap
page read and write
6080000
trusted library allocation
page read and write
2D50000
trusted library allocation
page read and write
4119000
trusted library allocation
page read and write
4076000
trusted library allocation
page read and write
52FE000
stack
page read and write
3FBB000
trusted library allocation
page read and write
6363000
heap
page read and write
4140000
trusted library allocation
page read and write
6344000
heap
page read and write
5948000
trusted library allocation
page read and write
6364000
heap
page read and write
6363000
heap
page read and write
6344000
heap
page read and write
6344000
heap
page read and write
6368000
heap
page read and write
1B0000
heap
page read and write
6344000
heap
page read and write
635B000
heap
page read and write
4C70000
trusted library allocation
page read and write
FEF000
heap
page read and write
6341000
heap
page read and write
122F000
stack
page read and write
4C88000
trusted library allocation
page read and write
6341000
heap
page read and write
4197000
trusted library allocation
page read and write
4017000
trusted library allocation
page read and write
6341000
heap
page read and write
6344000
heap
page read and write
4140000
trusted library allocation
page read and write
6344000
heap
page read and write
2D50000
trusted library allocation
page read and write
57E0000
trusted library allocation
page read and write
FEC000
heap
page read and write
410E000
trusted library allocation
page read and write
41B1000
trusted library allocation
page read and write
4B00000
trusted library allocation
page read and write
6344000
heap
page read and write
6344000
heap
page read and write
1282000
trusted library allocation
page execute and read and write
E3A000
stack
page read and write
5FBA000
heap
page read and write
54B6000
trusted library allocation
page read and write
51D0000
trusted library allocation
page read and write
6344000
heap
page read and write
60FE000
stack
page read and write
29C0000
trusted library allocation
page read and write
6351000
heap
page read and write
6344000
heap
page read and write
6354000
heap
page read and write
6341000
heap
page read and write
54B0000
trusted library allocation
page read and write
6362000
heap
page read and write
6354000
heap
page read and write
6341000
heap
page read and write
54B0000
trusted library allocation
page read and write
414B000
trusted library allocation
page read and write
6354000
heap
page read and write
6367000
heap
page read and write
6080000
trusted library allocation
page read and write
6344000
heap
page read and write
5F80000
heap
page read and write
415B000
trusted library allocation
page read and write
6341000
heap
page read and write
6341000
heap
page read and write
414E000
trusted library allocation
page read and write
6354000
heap
page read and write
5A6E000
stack
page read and write
3F01000
trusted library allocation
page read and write
51D0000
trusted library allocation
page read and write
593C000
trusted library allocation
page read and write
5936000
trusted library allocation
page read and write
5D0000
heap
page read and write
2948000
trusted library allocation
page read and write
51D0000
trusted library allocation
page read and write
1362000
trusted library allocation
page execute and read and write
5930000
trusted library allocation
page read and write
6341000
heap
page read and write
51C4000
trusted library allocation
page read and write
40EC000
trusted library allocation
page read and write
4C60000
trusted library allocation
page read and write
6341000
heap
page read and write
3EA9000
trusted library allocation
page read and write
5936000
trusted library allocation
page read and write
5B80000
trusted library allocation
page read and write
538E000
stack
page read and write
6363000
heap
page read and write
4093000
trusted library allocation
page read and write
CF6000
stack
page read and write
405F000
trusted library allocation
page read and write
5210000
trusted library allocation
page read and write
41B4000
trusted library allocation
page read and write
6344000
heap
page read and write
A47000
trusted library allocation
page execute and read and write
6351000
heap
page read and write
6341000
heap
page read and write
6354000
heap
page read and write
6341000
heap
page read and write
6341000
heap
page read and write
30D6000
trusted library allocation
page read and write
78E000
stack
page read and write
5910000
trusted library allocation
page read and write
41B6000
trusted library allocation
page read and write
6344000
heap
page read and write
58E0000
heap
page read and write
5310000
heap
page execute and read and write
41EE000
trusted library allocation
page read and write
41BC000
trusted library allocation
page read and write
5930000
trusted library allocation
page read and write
183E000
stack
page read and write
16A1000
heap
page read and write
6344000
heap
page read and write
6344000
heap
page read and write
11B4000
heap
page execute and read and write
6354000
heap
page read and write
4C70000
trusted library allocation
page read and write
6354000
heap
page read and write
3FB8000
trusted library allocation
page read and write
41F1000
trusted library allocation
page read and write
4160000
trusted library allocation
page read and write
4109000
trusted library allocation
page read and write
6341000
heap
page read and write
6341000
heap
page read and write
3969000
trusted library allocation
page read and write
7F850000
trusted library allocation
page execute and read and write
1617000
trusted library allocation
page execute and read and write
6367000
heap
page read and write
FF7000
heap
page read and write
6341000
heap
page read and write
6341000
heap
page read and write
6351000
heap
page read and write
54B6000
trusted library allocation
page read and write
40B6000
trusted library allocation
page read and write
6363000
heap
page read and write
5940000
trusted library allocation
page read and write
A67000
trusted library allocation
page execute and read and write
728000
heap
page read and write
5BA0000
trusted library allocation
page read and write
6354000
heap
page read and write
6341000
heap
page read and write
4C70000
trusted library allocation
page read and write
4094000
trusted library allocation
page read and write
40E9000
trusted library allocation
page read and write
4140000
trusted library allocation
page read and write
6341000
heap
page read and write
6362000
heap
page read and write
6344000
heap
page read and write
51D0000
trusted library allocation
page read and write
51D0000
trusted library allocation
page read and write
4C70000
trusted library allocation
page read and write
6341000
heap
page read and write
41C6000
trusted library allocation
page read and write
40EC000
trusted library allocation
page read and write
54EE000
stack
page read and write
4C70000
trusted library allocation
page read and write
40F4000
trusted library allocation
page read and write
51E0000
trusted library allocation
page read and write
5BC0000
trusted library allocation
page read and write
6341000
heap
page read and write
6344000
heap
page read and write
415E000
trusted library allocation
page read and write
62FE000
stack
page read and write
FAE000
heap
page read and write
4C70000
trusted library allocation
page read and write
29BC000
trusted library allocation
page execute and read and write
6354000
heap
page read and write
6363000
heap
page read and write
54B6000
trusted library allocation
page read and write
51D0000
trusted library allocation
page read and write
12BB000
trusted library allocation
page execute and read and write
114E000
stack
page read and write
5930000
trusted library allocation
page read and write
6341000
heap
page read and write
1160000
heap
page read and write
317E000
unkown
page read and write
6367000
heap
page read and write
6341000
heap
page read and write
3F01000
trusted library allocation
page read and write
A30000
trusted library allocation
page read and write
FE9000
heap
page read and write
3F7D000
trusted library allocation
page read and write
68E000
stack
page read and write
4036000
trusted library allocation
page read and write
4C70000
trusted library allocation
page read and write
E15000
heap
page read and write
54C0000
trusted library allocation
page read and write
6362000
heap
page read and write
6368000
heap
page read and write
2E61000
trusted library allocation
page read and write
6341000
heap
page read and write
6354000
heap
page read and write
2A0E000
stack
page read and write
6354000
heap
page read and write
6344000
heap
page read and write
5950000
trusted library allocation
page read and write
5090000
trusted library allocation
page execute and read and write
3F01000
trusted library allocation
page read and write
51D0000
trusted library allocation
page read and write
5BB0000
trusted library allocation
page read and write
40D4000
trusted library allocation
page read and write
6588000
trusted library allocation
page read and write
41A4000
trusted library allocation
page read and write
3F8C000
trusted library allocation
page read and write
FE7000
heap
page read and write
5540000
heap
page execute and read and write
6341000
heap
page read and write
6354000
heap
page read and write
6341000
heap
page read and write
6354000
heap
page read and write
6341000
heap
page read and write
6351000
heap
page read and write
551E000
stack
page read and write
6368000
heap
page read and write
51D7000
trusted library allocation
page read and write
A32000
trusted library allocation
page execute and read and write
4170000
trusted library allocation
page read and write
5300000
trusted library allocation
page read and write
FE9000
heap
page read and write
4C70000
trusted library allocation
page read and write
6354000
heap
page read and write
6362000
heap
page read and write
6344000
heap
page read and write
6344000
heap
page read and write
54B0000
trusted library allocation
page read and write
6363000
heap
page read and write
6367000
heap
page read and write
2935000
trusted library allocation
page read and write
6341000
heap
page read and write
6354000
heap
page read and write
54B0000
trusted library allocation
page read and write
6341000
heap
page read and write
1272000
trusted library allocation
page execute and read and write
3F37000
trusted library allocation
page read and write
2921000
trusted library allocation
page read and write
6354000
heap
page read and write
4C50000
trusted library allocation
page execute and read and write
1990000
heap
page read and write
5205000
trusted library allocation
page read and write
6351000
heap
page read and write
6354000
heap
page read and write
3F35000
trusted library allocation
page read and write
6344000
heap
page read and write
41B1000
trusted library allocation
page read and write
6354000
heap
page read and write
6364000
heap
page read and write
1120000
heap
page read and write
4038000
trusted library allocation
page read and write
6344000
heap
page read and write
2D55000
trusted library allocation
page read and write
6354000
heap
page read and write
6341000
heap
page read and write
CFE000
stack
page read and write
6368000
heap
page read and write
61FE000
stack
page read and write
There are 1256 hidden memdumps, click here to show them.