IOC Report
BE.exe

loading gif

Files

File Path
Type
Category
Malicious
BE.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Temp\-e04230_
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 8, database pages 89, cookie 0x37, schema 4, UTF-8, version-valid-for 8
dropped
C:\Users\user\AppData\Local\Temp\aut3E7F.tmp
data
dropped
C:\Users\user\AppData\Local\Temp\aut3EAF.tmp
data
dropped
C:\Users\user\AppData\Local\Temp\caprone
ASCII text, with very long lines (29698), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\vaccinators
data
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\BE.exe
"C:\Users\user\Desktop\BE.exe"
malicious
C:\Windows\SysWOW64\svchost.exe
"C:\Users\user\Desktop\BE.exe"
malicious
C:\Program Files (x86)\GqdTPudCvRtHbxaMYjJNwroHJWRNOAGXqdwapQrLKGZKKOxvRot\mjUxxQvdYhZcUTbGlnDuL.exe
"C:\Program Files (x86)\GqdTPudCvRtHbxaMYjJNwroHJWRNOAGXqdwapQrLKGZKKOxvRot\mjUxxQvdYhZcUTbGlnDuL.exe"
malicious
C:\Windows\SysWOW64\finger.exe
"C:\Windows\SysWOW64\finger.exe"
malicious
C:\Program Files (x86)\GqdTPudCvRtHbxaMYjJNwroHJWRNOAGXqdwapQrLKGZKKOxvRot\mjUxxQvdYhZcUTbGlnDuL.exe
"C:\Program Files (x86)\GqdTPudCvRtHbxaMYjJNwroHJWRNOAGXqdwapQrLKGZKKOxvRot\mjUxxQvdYhZcUTbGlnDuL.exe"
malicious
C:\Program Files\Mozilla Firefox\firefox.exe
"C:\Program Files\Mozilla Firefox\Firefox.exe"
malicious

URLs

Name
IP
Malicious
http://www.297tamatest1kb.com/nrup/
162.255.119.150
malicious
http://www.agoraeubebo.com/nrup/?4zB=dWrD1PFadq7V5KkU7LJ42aAFaLe4dulu4bG3e9Abb7XIEj/TR5WidBzHl5Crj+jPOsSaqiQVqCgntzF+MJy+oot/yT776gG7my4wD72kf8G6IhzmdCzOQoXZHw+LgxKFftSdLF8=&E4=mL5lCZwhnX
162.240.81.18
malicious
http://www.quirkyquotients.online/nrup/?4zB=rSdoiViGYDYLrRKdMyHGmEsrD5O2dR0rBzK7mFXa25NHqewciJOPgwBtfxfGP4wRjyyyhUkHMzPABqGifAtUAP3JPEm7qheA9XvzANxM3e958jhsRDqrjDbyoEoYrKWnOm7f8wg=&E4=mL5lCZwhnX
66.96.162.142
malicious
http://www.agoraeubebo.com/nrup/
162.240.81.18
malicious
http://www.deniztemiz.fun/nrup/?4zB=3O5z/vVa1aiBIg/xxVUxONkRy0clKD44MhhTC4igeHW13Qm1DZfD61e1zUoBYKe6btEt/czcNwG19z5y+5X/1/hH+2bFzZ870voW6rcohYnXcgzlwkBQj3Z3EfrZ/COvHm1g32k=&E4=mL5lCZwhnX
46.28.105.2
malicious
http://www.thechurchinkaty.com/nrup/?4zB=a+HLDFsiIkHuV4rn+gi5rsotYCX3prWMO9xbFOtVeNEzn7JMPDdWPqWyvrOReB4/XTuVmtp3VnCvPO8MCLmbCPyWTQaoVCzAm8BOGyiHZqCCSQPZX+grn8/y5VBeIny6Q7Ksroc=&E4=mL5lCZwhnX
91.195.240.19
malicious
http://www.deniztemiz.fun/nrup/
46.28.105.2
malicious
http://www.gudvain.top/nrup/
203.161.62.199
malicious
http://www.eh28mf3cdv.xyz/nrup/
172.67.131.93
malicious
http://www.zopter.dev/nrup/?4zB=i3HAzC/U9OJxIpd4ZFE61YQ3tTjHAL+S67PrGCHTQB0skmoYQlANd9KUV9Q5JBr9nmo5zLmqMM+UGTcdqDZY6bty5y8oC86dSXLZSbEv4AYydQS0u4ITiyiPHi6hZSaRELyYPnw=&E4=mL5lCZwhnX
192.185.225.30
malicious
http://www.zopter.dev/nrup/
192.185.225.30
malicious
http://www.quirkyquotients.online/nrup/
66.96.162.142
malicious
http://www.5597043.com/nrup/?4zB=2at1c1MHk4LdsVUEU7ldBtKGEgzqeGLnTyG93G2uP4ilKgyCyFz2asP5AaTCMTK+FwXayJ+KsNmilZED2txklDFoTdNS5Ym8YrIOtvEOZYMpOqGqSE/eXVAT3OGK9XHhpGGp26Q=&E4=mL5lCZwhnX
91.195.240.94
malicious
http://www.rtp7winbet.one/nrup/?4zB=kzrlZ2T9Vt9w6xD5OjL89g1fHoSFoRZWAwja/KbUtVmCMoB2+UC4SxnLGcP1NiN5dQ0PuJ1cEwvak2ooM6DpshgnptKCHbUIhiWFqqUHKJpCyFmwiiDWuuU8YdUMVDfD6X7y8X0=&E4=mL5lCZwhnX
172.67.145.66
malicious
http://www.hggg2qyws.sbs/nrup/
47.238.226.135
malicious
http://www.297tamatest1kb.com/nrup/?4zB=aN7x9cBVxwix9wZ24XKnp02DSufHFhw/orbHVM7uweNeZbe3aghpZ46wHwFUV/sydBj8rADN805v00PDoFlvXFUra5D5qxZGjmf2w10JWvUNcvN3k6vcsZaPmK+/ymPRsBgKXm4=&E4=mL5lCZwhnX
162.255.119.150
malicious
http://www.nimaster.com/nrup/?4zB=QRCJemSun6KfUPjc1ra1p0KD1DfNQWayr2LzNdaeeYxuOQk1p7mHgMDWyXNbqqPBLxuVlq/ZBm0Oma1g/sQvYwOD4miMjYPxgCNdvCuM/bvV/UvzeqGcXCXks33B8x4qhMHiVpA=&E4=mL5lCZwhnX
217.26.48.101
malicious
http://www.nimaster.com/nrup/
217.26.48.101
malicious
http://www.northeastcol0r.com/nrup/
208.91.197.27
malicious
http://www.5597043.com/nrup/
91.195.240.94
malicious
http://www.rtp7winbet.one/nrup/
172.67.145.66
malicious
http://www.hggg2qyws.sbs/nrup/?4zB=cxIeN1iVhQqOwso3qyh3afqsjymHjIXfdqpS9UswCbkbA/58Vi1sm+p80ycRzZQ3wyr0SPrfaOIY33X3gObGEgshGKYe9SriGy0z6CPVUFDac+zMNq37Dmd0gl4JqD8C9xqTvhA=&E4=mL5lCZwhnX
47.238.226.135
malicious
http://www.gudvain.top/nrup/?4zB=SizHnN/9xgcqSIkW0NZvl7gyOxH20BZ/0t0LsappuxDuweYFtCvxeO53HOaQyRIbafE/EtAb6ZPlU84V9ptZ1Jny3q6qBTQyh900ljmAne3h0OsFBB09soOZZqhxwkbIClKVv7o=&E4=mL5lCZwhnX
203.161.62.199
malicious
http://www.eh28mf3cdv.xyz/nrup/?4zB=VL9Zs38GJPfFaE6WM3J2DDHYpAc2VPFvT1CfgJidINT/bL3xtTnXNHZHm0n+ibwOL0yfM3AnXSzCgI8y/4Mb5Sh/J7VRy4Dt719Fp/6uDabdidV4BfufcLcTDbBNt2HLOtFT6ig=&E4=mL5lCZwhnX
172.67.131.93
malicious
http://www.domprojekt.pro/nrup/
46.242.239.47
malicious
http://www.domprojekt.pro/nrup/?4zB=cS0qtSAcX+pXbswCZ3zAHmB/Q/MHrKwsBUXhui9hTGS1u1fOXkoxNKS6rQ+eLLVB4nR1GYwQqdn4Z8GMIDdK+7ND2UvcrP7jQ+gJGXZsckM16e5TaCBYb5oSYEJtHveTNZggks8=&E4=mL5lCZwhnX
46.242.239.47
malicious
https://duckduckgo.com/chrome_newtab
unknown
http://297-tamaki-drive-auckland-au-1071-sales.properties.sothebysrealty.com
unknown
https://duckduckgo.com/ac/?q=
unknown
https://rtp7winbet.one
unknown
http://www.eh28mf3cdv.xyz
unknown
https://hg.mozilla.org/releases/mozilla-release/rev/68e4c357d26c5a1f075a1ec0c696d4fe684ed881
unknown
https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
unknown
http://nginx.net/
unknown
https://img.maskanalyse.com/node/script?appId=mdtv&channel=
unknown
http://fedoraproject.org/
unknown
https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search
unknown
http://www.searchvity.com/?dn=
unknown
https://mozilla.org0/
unknown
https://crash-reports.mozilla.com/submit?id=
unknown
https://hm.baidu.com/hm.js?92670261e24653d39b714ffd838f4d3d
unknown
https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
unknown
https://www.ecosia.org/newtab/
unknown
http://www.northeastcol0r.com/px.js?ch=2
unknown
http://www.northeastcol0r.com/px.js?ch=1
unknown
https://ac.ecosia.org/autocomplete?q=
unknown
https://hm.baidu.com/hm.js?41eabc9f6a9d26dcbe950fd13f552516
unknown
http://www.searchvity.com/
unknown
https://gw.alipayobjects.com/zos/rmsportal/KDpgvguMpGfqaHPjicRK.svg
unknown
https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
unknown
http://www.northeastcol0r.com/sk-logabpstatus.php?a=S0FsMUJmMDBqRVVraW9HalVKTTBGd05XWXAwRGdyejBQdDZF
unknown
There are 41 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
agoraeubebo.com
162.240.81.18
malicious
www.gudvain.top
203.161.62.199
malicious
www.deniztemiz.fun
46.28.105.2
malicious
www.rtp7winbet.one
172.67.145.66
malicious
domprojekt.pro
46.242.239.47
malicious
xiaoyue.zhuangkou.com
47.238.226.135
malicious
www.5597043.com
91.195.240.94
malicious
www.nimaster.com
217.26.48.101
malicious
zopter.dev
192.185.225.30
malicious
www.quirkyquotients.online
66.96.162.142
malicious
www.northeastcol0r.com
208.91.197.27
malicious
www.eh28mf3cdv.xyz
172.67.131.93
malicious
www.297tamatest1kb.com
162.255.119.150
malicious
www.zopter.dev
unknown
malicious
www.domprojekt.pro
unknown
malicious
www.inform-you.com
unknown
malicious
www.thechurchinkaty.com
unknown
malicious
www.hggg2qyws.sbs
unknown
malicious
www.agoraeubebo.com
unknown
malicious
www.berkahmadanicenter.com
unknown
malicious
berkahmadanicenter.com
156.67.209.21
parkingpage.namecheap.com
91.195.240.19
There are 12 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
192.185.225.30
zopter.dev
United States
malicious
162.240.81.18
agoraeubebo.com
United States
malicious
91.195.240.94
www.5597043.com
Germany
malicious
46.242.239.47
domprojekt.pro
Poland
malicious
46.28.105.2
www.deniztemiz.fun
Czech Republic
malicious
162.255.119.150
www.297tamatest1kb.com
United States
malicious
208.91.197.27
www.northeastcol0r.com
Virgin Islands (BRITISH)
malicious
172.67.131.93
www.eh28mf3cdv.xyz
United States
malicious
66.96.162.142
www.quirkyquotients.online
United States
malicious
203.161.62.199
www.gudvain.top
Malaysia
malicious
47.238.226.135
xiaoyue.zhuangkou.com
United States
malicious
217.26.48.101
www.nimaster.com
Switzerland
malicious
172.67.145.66
www.rtp7winbet.one
United States
malicious
91.195.240.19
parkingpage.namecheap.com
Germany
There are 4 hidden IPs, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
5270000
system
page execute and read and write
malicious
420000
system
page execute and read and write
malicious
3750000
unclassified section
page execute and read and write
malicious
4690000
unkown
page execute and read and write
malicious
7B0000
trusted library allocation
page read and write
malicious
5400000
unclassified section
page execute and read and write
malicious
400000
system
page execute and read and write
malicious
910000
trusted library allocation
page read and write
malicious
1520000
unkown
page read and write
73E1000
heap
page read and write
811000
heap
page read and write
3013000
heap
page read and write
13A0000
unkown
page readonly
3548000
unkown
page read and write
6A2000
heap
page read and write
7AFC000
heap
page read and write
811000
heap
page read and write
811000
heap
page read and write
3A1000
unkown
page execute read
1B10000
unkown
page readonly
3700000
heap
page read and write
811000
heap
page read and write
3B5000
unkown
page read and write
37E3000
direct allocation
page read and write
811000
heap
page read and write
811000
heap
page read and write
3939000
direct allocation
page read and write
D54000
heap
page read and write
811000
heap
page read and write
E28000
heap
page read and write
39AE000
direct allocation
page read and write
380000
unkown
page readonly
65C000
heap
page read and write
811000
heap
page read and write
811000
heap
page read and write
3013000
heap
page read and write
3A0000
unkown
page readonly
2A60000
unkown
page readonly
3013000
heap
page read and write
2DDE000
direct allocation
page execute and read and write
2904000
heap
page read and write
15A2000
heap
page read and write
2F11000
direct allocation
page execute and read and write
13A0000
unkown
page readonly
33B6000
unkown
page read and write
360F000
stack
page read and write
6C3000
heap
page read and write
811000
heap
page read and write
811000
heap
page read and write
3200000
heap
page read and write
1020000
unkown
page read and write
3939000
direct allocation
page read and write
3A29000
direct allocation
page execute and read and write
13F52000
system
page read and write
4D4000
heap
page read and write
811000
heap
page read and write
600000
heap
page read and write
811000
heap
page read and write
811000
heap
page read and write
811000
heap
page read and write
1588000
heap
page read and write
811000
heap
page read and write
BEF000
stack
page read and write
A11000
unkown
page read and write
DB0000
unkown
page readonly
811000
heap
page read and write
811000
heap
page read and write
743C000
heap
page read and write
350E000
stack
page read and write
3290000
unkown
page execute and read and write
811000
heap
page read and write
811000
heap
page read and write
811000
heap
page read and write
811000
heap
page read and write
2B62000
unkown
page read and write
7442000
heap
page read and write
811000
heap
page read and write
811000
heap
page read and write
FE0000
unkown
page readonly
EB0000
unkown
page read and write
3670000
direct allocation
page read and write
811000
heap
page read and write
3A0000
unkown
page readonly
9F0000
unkown
page readonly
3750000
direct allocation
page read and write
811000
heap
page read and write
74E9000
heap
page read and write
EC0000
heap
page read and write
811000
heap
page read and write
5F6000
heap
page read and write
3013000
heap
page read and write
61A000
heap
page read and write
2F40000
unkown
page read and write
1056000
heap
page read and write
39AE000
direct allocation
page read and write
389E000
heap
page read and write
811000
heap
page read and write
811000
heap
page read and write
7438000
heap
page read and write
7B0000
trusted library allocation
page read and write
66E000
heap
page read and write
4608000
unclassified section
page read and write
1011000
unkown
page readonly
3224000
unkown
page read and write
EE3000
heap
page read and write
811000
heap
page read and write
811000
heap
page read and write
3013000
heap
page read and write
3013000
heap
page read and write
811000
heap
page read and write
2E3C000
unkown
page read and write
39FE000
direct allocation
page read and write
4476000
unclassified section
page read and write
1511000
unkown
page readonly
3654000
unclassified section
page read and write
3301000
heap
page read and write
811000
heap
page read and write
C9C000
stack
page read and write
E5C000
heap
page read and write
6CE000
heap
page read and write
DD0000
heap
page read and write
811000
heap
page read and write
811000
heap
page read and write
934000
heap
page read and write
811000
heap
page read and write
811000
heap
page read and write
1780000
unkown
page readonly
141E000
stack
page read and write
EF5000
heap
page read and write
3900000
direct allocation
page execute and read and write
601000
heap
page read and write
454000
unkown
page readonly
364E000
stack
page read and write
691000
heap
page read and write
72F000
stack
page read and write
2D90000
direct allocation
page read and write
811000
heap
page read and write
3194000
heap
page read and write
3000000
heap
page read and write
DE94FFE000
stack
page read and write
BFF000
stack
page read and write
811000
heap
page read and write
811000
heap
page read and write
7447000
heap
page read and write
13C0000
unkown
page readonly
1580000
heap
page read and write
5A93000
unkown
page execute and read and write
3212000
heap
page read and write
811000
heap
page read and write
30AC000
unclassified section
page read and write
C6A000
stack
page read and write
811000
heap
page read and write
681000
heap
page read and write
F08000
heap
page read and write
C6A000
stack
page read and write
D70000
direct allocation
page execute and read and write
3C9C000
unclassified section
page read and write
2D90000
direct allocation
page read and write
811000
heap
page read and write
3989000
direct allocation
page read and write
743A000
heap
page read and write
31A0000
unkown
page readonly
2F40000
unkown
page read and write
7441000
heap
page read and write
7450000
heap
page read and write
13D0000
heap
page read and write
2900000
heap
page read and write
811000
heap
page read and write
811000
heap
page read and write
811000
heap
page read and write
811000
heap
page read and write
811000
heap
page read and write
811000
heap
page read and write
811000
heap
page read and write
1500000
unkown
page read and write
14C1000
unkown
page readonly
3217000
heap
page read and write
436A000
unkown
page read and write
811000
heap
page read and write
2910000
heap
page read and write
811000
heap
page read and write
3E2E000
unclassified section
page read and write
2D20000
heap
page read and write
811000
heap
page read and write
811000
heap
page read and write
2F92000
unclassified section
page read and write
4B0000
heap
page read and write
811000
heap
page read and write
3978000
unclassified section
page read and write
4D0000
heap
page read and write
811000
heap
page read and write
3860000
direct allocation
page read and write
7435000
heap
page read and write
2F20000
unkown
page readonly
6AE000
heap
page read and write
811000
heap
page read and write
13C0000
unkown
page readonly
811000
heap
page read and write
398D000
direct allocation
page read and write
811000
heap
page read and write
5024000
unkown
page execute and read and write
5093000
unkown
page execute and read and write
3013000
heap
page read and write
811000
heap
page read and write
1200000
unkown
page readonly
811000
heap
page read and write
3190000
heap
page read and write
3989000
direct allocation
page read and write
2910000
heap
page read and write
1011000
unkown
page readonly
3013000
heap
page read and write
811000
heap
page read and write
1511000
unkown
page readonly
14C0000
unkown
page readonly
398D000
direct allocation
page read and write
3AE000
unkown
page readonly
811000
heap
page read and write
442000
unkown
page readonly
3810000
direct allocation
page read and write
811000
heap
page read and write
530D000
system
page execute and read and write
3B7000
unkown
page readonly
41C000
unkown
page readonly
3A0000
unkown
page readonly
1130000
unkown
page readonly
DD0000
heap
page read and write
811000
heap
page read and write
811000
heap
page read and write
177F000
stack
page read and write
3013000
heap
page read and write
811000
heap
page read and write
39FE000
direct allocation
page read and write
374F000
stack
page read and write
393D000
direct allocation
page read and write
4152000
unclassified section
page read and write
EF6000
heap
page read and write
811000
heap
page read and write
811000
heap
page read and write
13B0000
unkown
page readonly
66E000
heap
page read and write
811000
heap
page read and write
DB0000
unkown
page readonly
3002000
heap
page read and write
E54000
heap
page read and write
674000
heap
page read and write
773E000
stack
page read and write
811000
heap
page read and write
2A5F000
stack
page read and write
100F000
stack
page read and write
382D000
heap
page read and write
107D000
heap
page read and write
381000
unkown
page execute read
743E000
heap
page read and write
811000
heap
page read and write
3B0A000
unclassified section
page read and write
811000
heap
page read and write
811000
heap
page read and write
811000
heap
page read and write
3190000
heap
page read and write
13D0000
heap
page read and write
811000
heap
page read and write
1020000
unkown
page read and write
2C7C000
unkown
page read and write
699000
heap
page read and write
2FD0000
heap
page read and write
811000
heap
page read and write
1AB000
stack
page read and write
811000
heap
page read and write
E52000
heap
page read and write
36DA000
unkown
page read and write
1580000
heap
page read and write
157E000
stack
page read and write
811000
heap
page read and write
1588000
heap
page read and write
811000
heap
page read and write
7448000
heap
page read and write
3829000
heap
page read and write
811000
heap
page read and write
6C9000
heap
page read and write
FC4000
heap
page read and write
811000
heap
page read and write
E20000
heap
page read and write
7445000
heap
page read and write
EB0000
unkown
page read and write
14012000
system
page read and write
3989000
direct allocation
page read and write
1073000
heap
page read and write
742B000
heap
page read and write
E79000
heap
page read and write
2D70000
heap
page read and write
73DB000
heap
page read and write
D6D000
stack
page read and write
531D000
system
page execute and read and write
7ADF000
stack
page read and write
811000
heap
page read and write
811000
heap
page read and write
3939000
direct allocation
page read and write
811000
heap
page read and write
1059000
heap
page read and write
811000
heap
page read and write
DA0000
heap
page read and write
4046000
unkown
page read and write
5F8000
heap
page read and write
811000
heap
page read and write
393D000
direct allocation
page read and write
650000
heap
page read and write
36C0000
direct allocation
page read and write
41D8000
unkown
page read and write
601000
heap
page read and write
DA0000
unkown
page readonly
2BC0000
heap
page read and write
3052000
unclassified section
page read and write
442000
unkown
page readonly
811000
heap
page read and write
126A000
stack
page read and write
DB0000
direct allocation
page read and write
39FE000
direct allocation
page read and write
811000
heap
page read and write
811000
heap
page read and write
1200000
unkown
page readonly
3013000
heap
page read and write
BDB000
stack
page read and write
2D6D000
direct allocation
page execute and read and write
3B90000
unkown
page read and write
5EE000
stack
page read and write
811000
heap
page read and write
5329000
system
page execute and read and write
800000
heap
page read and write
1420000
heap
page read and write
65C000
heap
page read and write
D6D000
stack
page read and write
811000
heap
page read and write
811000
heap
page read and write
2A90000
trusted library allocation
page execute and read and write
468E000
unkown
page read and write
14614000
system
page read and write
811000
heap
page read and write
E6B000
heap
page read and write
811000
heap
page read and write
811000
heap
page read and write
398D000
direct allocation
page read and write
CDB000
stack
page read and write
811000
heap
page read and write
811000
heap
page read and write
450000
unkown
page write copy
161F000
stack
page read and write
EF7000
heap
page read and write
7432000
heap
page read and write
811000
heap
page read and write
3B7000
unkown
page readonly
811000
heap
page read and write
661000
heap
page read and write
C00000
unkown
page readonly
811000
heap
page read and write
811000
heap
page read and write
3BD1000
direct allocation
page execute and read and write
103A000
heap
page read and write
FF0000
unkown
page readonly
811000
heap
page read and write
5F6000
heap
page read and write
811000
heap
page read and write
44C000
unkown
page write copy
2D80000
heap
page read and write
811000
heap
page read and write
811000
heap
page read and write
811000
heap
page read and write
601000
heap
page read and write
E5C000
heap
page read and write
2A97000
heap
page read and write
3D22000
unkown
page read and write
295E000
stack
page read and write
3AE000
unkown
page readonly
73D3000
heap
page read and write
FE0000
unkown
page readonly
811000
heap
page read and write
1B11000
unkown
page readonly
811000
heap
page read and write
3B7000
unkown
page readonly
811000
heap
page read and write
2BC4000
heap
page read and write
EC0000
heap
page read and write
811000
heap
page read and write
28E0000
unkown
page readonly
811000
heap
page read and write
811000
heap
page read and write
DC0000
unkown
page readonly
811000
heap
page read and write
810000
heap
page read and write
811000
heap
page read and write
44C000
unkown
page read and write
DC0000
unkown
page readonly
3A9E000
direct allocation
page execute and read and write
811000
heap
page read and write
3205000
heap
page read and write
A7E000
stack
page read and write
37E3000
direct allocation
page read and write
811000
heap
page read and write
811000
heap
page read and write
A00000
trusted library allocation
page read and write
1F7942C0000
heap
page read and write
66B000
heap
page read and write
811000
heap
page read and write
3750000
direct allocation
page read and write
2F0D000
direct allocation
page execute and read and write
811000
heap
page read and write
3793000
direct allocation
page read and write
811000
heap
page read and write
811000
heap
page read and write
2FD0000
heap
page read and write
537F000
system
page execute and read and write
681000
heap
page read and write
1036000
heap
page read and write
A00000
trusted library allocation
page read and write
811000
heap
page read and write
1420000
heap
page read and write
811000
heap
page read and write
3205000
heap
page read and write
103E000
heap
page read and write
601000
heap
page read and write
811000
heap
page read and write
3793000
direct allocation
page read and write
2A60000
unkown
page readonly
811000
heap
page read and write
381000
unkown
page execute read
811000
heap
page read and write
5F0000
heap
page read and write
811000
heap
page read and write
811000
heap
page read and write
74D0000
trusted library allocation
page read and write
811000
heap
page read and write
F5A000
heap
page read and write
811000
heap
page read and write
3013000
heap
page read and write
2B50000
unkown
page read and write
1030000
heap
page read and write
4A0000
heap
page read and write
100F000
stack
page read and write
2C35000
heap
page read and write
811000
heap
page read and write
811000
heap
page read and write
4D4000
heap
page read and write
811000
heap
page read and write
1F793FC0000
system
page execute and read and write
811000
heap
page read and write
10BE000
heap
page read and write
1780000
unkown
page readonly
3AE000
unkown
page readonly
9E0000
unkown
page readonly
811000
heap
page read and write
811000
heap
page read and write
479A000
unclassified section
page read and write
2B7E000
stack
page read and write
811000
heap
page read and write
1030000
heap
page read and write
811000
heap
page read and write
36C0000
direct allocation
page read and write
950000
trusted library allocation
page read and write
5CE000
stack
page read and write
3B5000
unkown
page read and write
FEA000
heap
page read and write
744A000
heap
page read and write
D90000
heap
page read and write
136C000
stack
page read and write
454000
unkown
page readonly
380000
unkown
page readonly
31A0000
unkown
page readonly
7750000
heap
page read and write
811000
heap
page read and write
3A0000
unkown
page readonly
811000
heap
page read and write
E6A000
heap
page read and write
811000
heap
page read and write
2C40000
direct allocation
page execute and read and write
393D000
direct allocation
page read and write
D50000
heap
page read and write
74C0000
trusted library allocation
page read and write
BCF000
stack
page read and write
3810000
direct allocation
page read and write
EF6000
heap
page read and write
326C000
unclassified section
page read and write
811000
heap
page read and write
811000
heap
page read and write
44FC000
unkown
page read and write
811000
heap
page read and write
811000
heap
page read and write
811000
heap
page read and write
1E8000
stack
page read and write
3FC0000
unclassified section
page read and write
811000
heap
page read and write
36C0000
direct allocation
page read and write
2C22000
unkown
page read and write
3B5000
unkown
page read and write
811000
heap
page read and write
7423000
heap
page read and write
3C90000
unkown
page execute and read and write
811000
heap
page read and write
3860000
direct allocation
page read and write
811000
heap
page read and write
3A1000
unkown
page execute read
3E01000
heap
page read and write
3670000
direct allocation
page read and write
811000
heap
page read and write
3B7000
unkown
page readonly
3A2D000
direct allocation
page execute and read and write
321E000
heap
page read and write
BBF000
stack
page read and write
C00000
unkown
page readonly
3A1000
unkown
page execute read
490000
heap
page read and write
3194000
heap
page read and write
3013000
heap
page read and write
811000
heap
page read and write
4000000
unclassified section
page execute and read and write
37E6000
unclassified section
page read and write
3670000
direct allocation
page read and write
811000
heap
page read and write
2E3C000
unkown
page read and write
811000
heap
page read and write
28E0000
unkown
page readonly
492C000
unclassified section
page read and write
F0E000
stack
page read and write
7409000
heap
page read and write
E5C000
heap
page read and write
3013000
heap
page read and write
3B5000
unkown
page read and write
102C000
heap
page read and write
31BF000
stack
page read and write
811000
heap
page read and write
519000
stack
page read and write
73E5000
heap
page read and write
3BCD000
direct allocation
page execute and read and write
811000
heap
page read and write
386C000
unkown
page read and write
811000
heap
page read and write
811000
heap
page read and write
E5B000
heap
page read and write
3013000
heap
page read and write
740E000
heap
page read and write
53DC000
unkown
page read and write
2D69000
direct allocation
page execute and read and write
811000
heap
page read and write
6D4000
heap
page read and write
811000
heap
page read and write
811000
heap
page read and write
5D94000
unclassified section
page execute and read and write
30DF000
stack
page read and write
4D4000
heap
page read and write
4A00000
unclassified section
page execute and read and write
59A0000
trusted library allocation
page read and write
103A000
heap
page read and write
73EA000
heap
page read and write
811000
heap
page read and write
811000
heap
page read and write
68B000
heap
page read and write
811000
heap
page read and write
811000
heap
page read and write
811000
heap
page read and write
811000
heap
page read and write
73C1000
heap
page read and write
FF0000
unkown
page readonly
811000
heap
page read and write
126A000
stack
page read and write
580000
heap
page read and write
811000
heap
page read and write
3013000
heap
page read and write
9E0000
unkown
page readonly
54DC000
unkown
page read and write
1422C000
system
page read and write
811000
heap
page read and write
811000
heap
page read and write
674000
heap
page read and write
2B62000
unkown
page read and write
607000
heap
page read and write
811000
heap
page read and write
811000
heap
page read and write
42E4000
unclassified section
page read and write
811000
heap
page read and write
811000
heap
page read and write
9F0000
unkown
page readonly
3860000
direct allocation
page read and write
811000
heap
page read and write
811000
heap
page read and write
41C000
unkown
page readonly
661000
heap
page read and write
811000
heap
page read and write
37E3000
direct allocation
page read and write
811000
heap
page read and write
136C000
stack
page read and write
3623000
heap
page read and write
811000
heap
page read and write
A00000
trusted library allocation
page read and write
FA9000
heap
page read and write
2B50000
unkown
page read and write
D0E000
stack
page read and write
607000
heap
page read and write
811000
heap
page read and write
811000
heap
page read and write
3750000
direct allocation
page read and write
2F82000
direct allocation
page execute and read and write
811000
heap
page read and write
811000
heap
page read and write
7405000
heap
page read and write
66B000
heap
page read and write
3C42000
direct allocation
page execute and read and write
811000
heap
page read and write
5E03000
unclassified section
page execute and read and write
5FE000
heap
page read and write
1130000
unkown
page readonly
611000
heap
page read and write
4ABE000
unclassified section
page read and write
13B0000
unkown
page readonly
1520000
unkown
page read and write
811000
heap
page read and write
2900000
heap
page read and write
5302000
system
page execute and read and write
F27000
heap
page read and write
811000
heap
page read and write
811000
heap
page read and write
39FE000
unkown
page read and write
EC4000
heap
page read and write
5390000
unkown
page read and write
5D0000
heap
page read and write
2F20000
unkown
page readonly
3A1000
unkown
page execute read
39AE000
direct allocation
page read and write
3013000
heap
page read and write
811000
heap
page read and write
1500000
unkown
page read and write
811000
heap
page read and write
6803000
unclassified section
page execute and read and write
3AE000
unkown
page readonly
811000
heap
page read and write
811000
heap
page read and write
3217000
heap
page read and write
811000
heap
page read and write
3810000
direct allocation
page read and write
7425000
heap
page read and write
3EB4000
unkown
page read and write
811000
heap
page read and write
811000
heap
page read and write
DA0000
unkown
page readonly
73FF000
heap
page read and write
103E000
heap
page read and write
69D000
heap
page read and write
811000
heap
page read and write
811000
heap
page read and write
811000
heap
page read and write
2904000
heap
page read and write
D60000
heap
page read and write
811000
heap
page read and write
3793000
direct allocation
page read and write
3500000
heap
page read and write
2D40000
heap
page read and write
F0E000
stack
page read and write
There are 644 hidden memdumps, click here to show them.