IOC Report
file.exe

loading gif

Files

File Path
Type
Category
Malicious
file.exe
PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\file.exe.log
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Local\Temp\?????.sys
PE32+ executable (DLL) (native) x86-64, for MS Windows
dropped
malicious

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\file.exe
C:\Users\user\Desktop\file.exe
malicious
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\jsc.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\jsc.exe
malicious
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ComSvcConfig.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ComSvcConfig.exe

URLs

Name
IP
Malicious
http://5.42.94.169/customer/368
5.42.94.169
malicious
http://www.sysinternals.com
unknown
http://www.sysinternals.comopen/?ICONSHELLRUNASAboutUsage/raw/netonlyRunAsInvoker__COMPAT_LAYERcmd
unknown
http://109.206.241.33/files/Hadi.config.CfgEncFileMZ
unknown
http://5.42.94.169
unknown
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
unknown
https://www.sysinternals.com0
unknown

IPs

IP
Domain
Country
Malicious
5.42.94.169
unknown
Russian Federation

Registry

Path
Value
Malicious
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\file_RASAPI32
EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\file_RASAPI32
EnableAutoFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\file_RASAPI32
EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\file_RASAPI32
FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\file_RASAPI32
ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\file_RASAPI32
MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\file_RASAPI32
FileDirectory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\file_RASMANCS
EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\file_RASMANCS
EnableAutoFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\file_RASMANCS
EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\file_RASMANCS
FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\file_RASMANCS
ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\file_RASMANCS
MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\file_RASMANCS
FileDirectory
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TaskKill
Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TaskKill
ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TaskKill
Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TaskKill
ImagePath
There are 8 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
1F6C76CC000
trusted library allocation
page read and write
malicious
E30000
direct allocation
page execute and read and write
malicious
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5C40000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5BF0000
trusted library allocation
page read and write
1F6E0010000
heap
page execute and read and write
1F6C5AD0000
trusted library allocation
page read and write
1F6C5C70000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6DFFA0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7650000
trusted library allocation
page read and write
1F6DFF4F000
heap
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7650000
trusted library allocation
page read and write
7FFC9D0B0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6DFFC0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5C50000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
7FFC9CE63000
trusted library allocation
page execute and read and write
1F6C75A0000
trusted library allocation
page read and write
1F6C5C50000
trusted library allocation
page read and write
1F6C7650000
trusted library allocation
page read and write
1F6C5AD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C75C0000
trusted library allocation
page read and write
1F6C5C42000
trusted library allocation
page read and write
7FFC9CE78000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C7626000
trusted library allocation
page read and write
7FFC9CE84000
trusted library allocation
page read and write
1F6C5CD3000
trusted library allocation
page read and write
1F6DFFC0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6DFFC0000
trusted library allocation
page read and write
1F6C5B2C000
heap
page read and write
1F6C5C50000
trusted library allocation
page read and write
1F6C7640000
trusted library allocation
page read and write
1F6C7650000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5C40000
trusted library allocation
page read and write
1F6C5AE0000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
7FFC9D078000
trusted library allocation
page read and write
1F6C5C20000
trusted library allocation
page read and write
416000
remote allocation
page execute and read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5C60000
trusted library allocation
page read and write
1F6C5BCD000
heap
page read and write
EB0000
heap
page read and write
1F6C7640000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7650000
trusted library allocation
page read and write
1F6C75F0000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5C20000
trusted library allocation
page read and write
1F6C5C50000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6DFFF0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CC0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5C20000
trusted library allocation
page read and write
1F6C5BF0000
trusted library allocation
page read and write
1F6C7650000
trusted library allocation
page read and write
1F6C5CC0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7640000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7640000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
80A9CF4000
stack
page read and write
1F6C5CD0000
trusted library allocation
page read and write
7FFC9D128000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7640000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C5C00000
trusted library allocation
page read and write
1F6C5C20000
trusted library allocation
page read and write
1F6DFF80000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5CE0000
heap
page read and write
1F6C5C50000
trusted library allocation
page read and write
1F6C7640000
trusted library allocation
page read and write
1F6C5C8E000
trusted library allocation
page read and write
1F6DFF80000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6E0020000
trusted library allocation
page read and write
1F6C7685000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5C20000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6DFFC0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
7FFC9D041000
trusted library allocation
page read and write
1F6DFF80000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C5C60000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
FE0000
heap
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6DFFA0000
trusted library allocation
page read and write
1F6C58B2000
unkown
page readonly
80A9FFF000
stack
page read and write
1F6C7496000
heap
page read and write
1F6C7620000
trusted library allocation
page read and write
7FFC9D01A000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C5CB0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6DFFE0000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5BF0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
80AA6FE000
stack
page read and write
1F6C5CD1000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
8E0000
heap
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C75B0000
trusted library allocation
page read and write
1F6C5C20000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5BBF000
heap
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C7640000
trusted library allocation
page read and write
1F6DFFA0000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
80A9EFE000
stack
page read and write
1F6C7650000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5C70000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD4000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C5C51000
trusted library allocation
page read and write
1F6C5C00000
trusted library allocation
page read and write
7FFC9D0A0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7640000
trusted library allocation
page read and write
1F6C5C80000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
80AACFE000
stack
page read and write
1F6C5CB0000
trusted library allocation
page read and write
1F6C5C20000
trusted library allocation
page read and write
1F6C5C70000
trusted library allocation
page read and write
1F6C5C20000
trusted library allocation
page read and write
1F6DFFE0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5B19000
heap
page read and write
1F6E0040000
trusted library allocation
page read and write
7FFC9D05B000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5C20000
trusted library allocation
page read and write
1F6C5C90000
trusted library allocation
page read and write
9EE000
stack
page read and write
1F6C5C20000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7640000
trusted library allocation
page read and write
1F6C5C30000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
7FFC9D044000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C75B0000
trusted library allocation
page read and write
1F6C7640000
trusted library allocation
page read and write
FBE000
stack
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5BF0000
trusted library allocation
page read and write
1F6DFF80000
trusted library allocation
page read and write
1F6C5A75000
heap
page read and write
7FFC9D110000
trusted library allocation
page read and write
1F6C5BF0000
trusted library allocation
page read and write
1F6C5CD5000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
80AA0FE000
stack
page read and write
1F6DFF80000
trusted library allocation
page read and write
1F6DFFA0000
trusted library allocation
page read and write
1F6C5A40000
heap
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5C51000
trusted library allocation
page read and write
1F6E0050000
trusted library allocation
page read and write
7FFC9D06F000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5BF4000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6DFE60000
trusted library allocation
page read and write
7FFC9D01F000
trusted library allocation
page read and write
1F6C5C50000
trusted library allocation
page read and write
1F6C5C41000
trusted library allocation
page read and write
1F6C7650000
trusted library allocation
page read and write
1F6D7671000
trusted library allocation
page read and write
1F6DFF1C000
heap
page read and write
7FFC9D100000
trusted library allocation
page read and write
1F6DFFE8000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
80AA4FD000
stack
page read and write
1F6C7640000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6DF6A0000
trusted library allocation
page read and write
1F6C5AE0000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5C10000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6D7691000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5AD4000
trusted library allocation
page read and write
7FFC9CE80000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
80AA5FF000
stack
page read and write
1F6C7640000
trusted library allocation
page read and write
80AA1FB000
stack
page read and write
1F6C5AD1000
trusted library allocation
page read and write
1F6C5CD1000
trusted library allocation
page read and write
1F6C5BD4000
heap
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5C60000
trusted library allocation
page read and write
7FFC9CF20000
trusted library allocation
page execute and read and write
7FFC9CF16000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5C50000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD2000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6DFF90000
trusted library allocation
page read and write
1F6C5BF1000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5A70000
heap
page read and write
1F6C5A00000
heap
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6DFF18000
heap
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6DFF90000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C5C70000
trusted library allocation
page read and write
1F6C77A3000
trusted library allocation
page read and write
1F6C7640000
trusted library allocation
page read and write
1F6C5C20000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
11DE000
stack
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5C20000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5BD2000
heap
page read and write
1F6C58B2000
unkown
page readonly
1F6C5CD0000
trusted library allocation
page read and write
1F6C7650000
trusted library allocation
page read and write
1F6C5C40000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5C20000
trusted library allocation
page read and write
1F6C75D0000
trusted library allocation
page read and write
1F6C7640000
trusted library allocation
page read and write
7FF40AE40000
trusted library allocation
page execute and read and write
1F6C5BF0000
trusted library allocation
page read and write
1F6C5C30000
trusted library allocation
page read and write
1F6C5C20000
trusted library allocation
page read and write
1F6C7813000
trusted library allocation
page read and write
7FFC9CE6D000
trusted library allocation
page execute and read and write
1F6DFFA0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
E6B000
direct allocation
page execute and read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
80AA3FE000
stack
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
CFC000
stack
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6D7771000
trusted library allocation
page read and write
1F6C5AC0000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6DFFB0000
trusted library allocation
page read and write
1F6DFFE0000
trusted library allocation
page read and write
1F6DFFC0000
trusted library allocation
page read and write
1F6C7CF4000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6DFF80000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5BF0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
7FFC9CE72000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C75AD000
trusted library allocation
page read and write
1F6DFEB3000
heap
page read and write
1F6C5A20000
heap
page read and write
7FFC9D088000
trusted library allocation
page read and write
7FFC9D050000
trusted library allocation
page read and write
1F6C7640000
trusted library allocation
page read and write
1F6DFF80000
trusted library allocation
page read and write
1F6C5CDC000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5C60000
trusted library allocation
page read and write
80AA2FE000
stack
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C7640000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
E60000
direct allocation
page execute and read and write
1F6C7630000
trusted library allocation
page read and write
1F6DFE60000
trusted library allocation
page read and write
7FFC9D0EF000
trusted library allocation
page read and write
7FFC9CF46000
trusted library allocation
page execute and read and write
1F6DFFA0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6DFF80000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6DFFA0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5C50000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
7FFC9D065000
trusted library allocation
page read and write
1F6C5C00000
trusted library allocation
page read and write
7FFC9D070000
trusted library allocation
page read and write
1F6C5C20000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5C50000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CDC000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5C20000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
E50000
direct allocation
page execute and read and write
1F6D767F000
trusted library allocation
page read and write
1F6C5C60000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
7FFC9D130000
trusted library allocation
page execute and read and write
1F6C5C30000
trusted library allocation
page read and write
1F6C7650000
trusted library allocation
page read and write
1F6DFE60000
trusted library allocation
page read and write
80A9DFE000
stack
page read and write
1F6E0030000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C5CD1000
trusted library allocation
page read and write
1F6C5AB0000
trusted library allocation
page read and write
E66000
direct allocation
page execute and read and write
1F6C5C50000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C7650000
trusted library allocation
page read and write
1F6C5C30000
trusted library allocation
page read and write
1F6C5BF0000
trusted library allocation
page read and write
1F6C58B0000
unkown
page readonly
2A10000
heap
page read and write
1F6C5B2F000
heap
page read and write
1F6C5C52000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6DFF14000
heap
page read and write
1F6C5CD0000
trusted library allocation
page read and write
7FFC9D048000
trusted library allocation
page read and write
1F6C7640000
trusted library allocation
page read and write
7FFC9CEBC000
trusted library allocation
page execute and read and write
1F6DFFD0000
trusted library allocation
page read and write
1F6C5CE5000
heap
page read and write
1F6C5AE0000
trusted library allocation
page read and write
1F6C5C20000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5C50000
trusted library allocation
page read and write
1F6C5C50000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6E0000000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5BF0000
trusted library allocation
page read and write
1F6C5CD1000
trusted library allocation
page read and write
1F6DFF90000
trusted library allocation
page read and write
1F6C7650000
trusted library allocation
page read and write
1F6DFF90000
trusted library allocation
page read and write
1F6C5C50000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
9F0000
heap
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5C60000
trusted library allocation
page read and write
1F6C5C20000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5C40000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5C50000
trusted library section
page read and write
1F6C7640000
trusted library allocation
page read and write
1F6DFE60000
trusted library allocation
page read and write
1F6C5BF0000
trusted library allocation
page read and write
1F6C5C20000
trusted library allocation
page read and write
7FFC9CE60000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
80AA9FE000
stack
page read and write
1F6DFF04000
heap
page read and write
1F6C5C20000
trusted library allocation
page read and write
1F6C5AE0000
trusted library allocation
page read and write
1F6C5CD1000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7660000
heap
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C7811000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6D767D000
trusted library allocation
page read and write
1F6C5C50000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C7640000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD1000
trusted library allocation
page read and write
1F6C5C60000
trusted library allocation
page read and write
1F6C5C20000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5C20000
trusted library allocation
page read and write
7FFC9CE70000
trusted library allocation
page read and write
7FFC9D120000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5C10000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
94C000
stack
page read and write
7FFC9D010000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5C90000
trusted library allocation
page read and write
1F6C5CD1000
trusted library allocation
page read and write
1F6C7640000
trusted library allocation
page read and write
1F6C5CA0000
trusted library allocation
page read and write
1F6C5CD1000
trusted library allocation
page read and write
1F6DFE60000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD1000
trusted library allocation
page read and write
1F6DFFD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6DFFB0000
trusted library allocation
page read and write
1F6C5C30000
trusted library allocation
page read and write
1F6C5BF0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C58BA000
unkown
page readonly
1F6C7630000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C5C60000
trusted library allocation
page read and write
1F6C7621000
trusted library allocation
page read and write
1F6C7625000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5C40000
trusted library allocation
page read and write
1F6DFF80000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5AF0000
heap
page read and write
1F6DFFC0000
trusted library allocation
page read and write
1F6DFE60000
trusted library allocation
page read and write
1F6DFE60000
trusted library allocation
page read and write
1F6E0000000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5BF7000
trusted library allocation
page read and write
1F6C7640000
trusted library allocation
page read and write
7FFC9D080000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7624000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
7FFC9D090000
trusted library allocation
page read and write
1F6E0030000
trusted library allocation
page read and write
80AA8FE000
stack
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7600000
trusted library allocation
page read and write
1F6DFFD0000
trusted library allocation
page read and write
1F6C58BA000
unkown
page readonly
1F6C7640000
trusted library allocation
page read and write
1F6C5C50000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5C50000
trusted library allocation
page read and write
1F6C5CD6000
trusted library allocation
page read and write
1F6C5C20000
trusted library allocation
page read and write
1F6DFF5D000
heap
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
80AA7FE000
stack
page read and write
1F6C5BF1000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
7FFC9CE8D000
trusted library allocation
page execute and read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5C50000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5C60000
trusted library allocation
page read and write
80AABFE000
stack
page read and write
1F6C7620000
trusted library allocation
page read and write
400000
remote allocation
page execute and read and write
1F6C5C60000
trusted library allocation
page read and write
1F6DFFD0000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
7FFC9D104000
trusted library allocation
page read and write
1F6C7652000
trusted library allocation
page read and write
1F6DFFAC000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C7640000
trusted library allocation
page read and write
7FFC9D023000
trusted library allocation
page read and write
FE8000
heap
page read and write
1F6C7640000
trusted library allocation
page read and write
1F6C5C20000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5C30000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6DFF80000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C5CD1000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
80A99CE000
stack
page read and write
1F6C5CD2000
trusted library allocation
page read and write
1F6DFFB0000
trusted library allocation
page read and write
1F6C5C20000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C58C0000
heap
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5C70000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C762E000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5C00000
trusted library allocation
page read and write
1F6C7610000
heap
page execute and read and write
1F6C7630000
trusted library allocation
page read and write
1F6C7640000
trusted library allocation
page read and write
E40000
heap
page read and write
7FFC9CF80000
trusted library allocation
page read and write
1F6C7633000
trusted library allocation
page read and write
1F6DFE70000
heap
page read and write
1F6C5C40000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6DFF90000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C5C20000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
7FFC9D0C0000
trusted library allocation
page read and write
1F6C5C70000
trusted library allocation
page read and write
1F6C5C40000
trusted library allocation
page read and write
1F6C5BF0000
trusted library allocation
page read and write
1F6DFF68000
heap
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C7640000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6DFED1000
heap
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CDC000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5C20000
trusted library allocation
page read and write
1F6C5C50000
trusted library allocation
page read and write
1F6DFFE3000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5CC0000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C75A0000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6DFF90000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
7FFC9CF90000
trusted library allocation
page execute and read and write
1F6DFF90000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
7FFC9CF10000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6DFE60000
trusted library allocation
page read and write
1F6DFF80000
trusted library allocation
page read and write
7FFC9CE7D000
trusted library allocation
page execute and read and write
1F6C7620000
trusted library allocation
page read and write
1F6C58B0000
unkown
page readonly
1F6DFF90000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
7FFC9D015000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6E0020000
trusted library allocation
page read and write
1F6C5C90000
trusted library allocation
page read and write
1F6C7657000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C5BF0000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5A90000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5C40000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5C50000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5BB6000
heap
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6DFFB0000
trusted library allocation
page read and write
1F6C5CD2000
trusted library allocation
page read and write
1F6C5AD4000
trusted library allocation
page read and write
E0E000
stack
page read and write
1F6DFFB0000
trusted library allocation
page read and write
1F6C5C80000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5CA0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
7FFC9D076000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5AD1000
trusted library allocation
page read and write
1F6DFFBB000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
7FFC9D0F0000
trusted library allocation
page read and write
1F6C5AC4000
trusted library allocation
page read and write
80A998E000
stack
page read and write
1F6C5BF4000
trusted library allocation
page read and write
7FFC9D0E0000
trusted library allocation
page read and write
1F6DFE60000
trusted library allocation
page read and write
1F6C5C50000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6DFE80000
heap
page read and write
1F6C7640000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5C20000
trusted library allocation
page read and write
1F6C5C50000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5B56000
heap
page read and write
1F6C5B58000
heap
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6DFE60000
trusted library allocation
page read and write
1F6C5C70000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7671000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
7FFC9CE64000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7640000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6DFFB0000
trusted library allocation
page read and write
1F6C5BAE000
heap
page read and write
1F6C5C20000
trusted library allocation
page read and write
1F6DFE60000
trusted library allocation
page read and write
1F6DFFD0000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6DFFF0000
trusted library allocation
page read and write
1F6C5C60000
trusted library allocation
page read and write
1F6C5AD7000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C7650000
trusted library allocation
page read and write
7FFC9D02A000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6E0040000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C7640000
trusted library allocation
page read and write
1F6C5BD8000
heap
page read and write
1F6C7650000
trusted library allocation
page read and write
7FFC9D0D0000
trusted library allocation
page execute and read and write
1F6C5CA0000
trusted library allocation
page read and write
1F6C5C00000
trusted library allocation
page read and write
1F6C5C20000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C7630000
trusted library allocation
page read and write
1F6C5AE1000
trusted library allocation
page read and write
1F6E0020000
heap
page read and write
1F6DFE60000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
80AAAFD000
stack
page read and write
1F6C5BB5000
heap
page read and write
1F6C5C80000
trusted library allocation
page read and write
1F6C75A0000
trusted library allocation
page read and write
1F6C5C62000
trusted library allocation
page read and write
1F6C5C60000
trusted library allocation
page read and write
1F6C5CB0000
trusted library allocation
page read and write
1F6C7640000
trusted library allocation
page read and write
1F6C5C50000
trusted library allocation
page read and write
7FFC9CF1C000
trusted library allocation
page execute and read and write
1F6C7630000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5BF0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C75A0000
trusted library allocation
page read and write
1F6C7650000
trusted library allocation
page read and write
1F6C7620000
trusted library allocation
page read and write
1F6C75E0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
7FFC9D152000
trusted library allocation
page read and write
1F6C7650000
trusted library allocation
page read and write
1F6C5AD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
7FFC9CE8B000
trusted library allocation
page execute and read and write
7FFC9D140000
trusted library allocation
page execute and read and write
1F6C5C20000
trusted library allocation
page read and write
1F6DFF90000
trusted library allocation
page read and write
1F6C5AD0000
trusted library allocation
page read and write
1F6C5CD0000
trusted library allocation
page read and write
1F6C5CD1000
trusted library allocation
page read and write
There are 796 hidden memdumps, click here to show them.