IOC Report
SW3uxM7BXI.exe

loading gif

Files

File Path
Type
Category
Malicious
SW3uxM7BXI.exe
PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\SW3uxM7BXI.exe.log
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\tmp2D96.tmp
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\tmp2DA7.tmp
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\tmp2DB8.tmp
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\tmp2DB9.tmp
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\tmp2DC9.tmp
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\tmp2DCA.tmp
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\tmp2DCB.tmp
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\tmp2DDC.tmp
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\tmp2DDD.tmp
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\tmp2DEE.tmp
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\tmp2DFE.tmp
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\tmp2DFF.tmp
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\tmp5FBF.tmp
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\tmp5FCF.tmp
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\tmp5FD0.tmp
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\tmp5FE1.tmp
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\tmp5FF1.tmp
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\tmp5FF2.tmp
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\tmp6003.tmp
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\tmp6014.tmp
SQLite 3.x database, user version 12, last written using SQLite version 3042000, page size 32768, writer version 2, read version 2, file counter 3, database pages 3, cookie 0x1, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\tmp6024.tmp
SQLite 3.x database, user version 12, last written using SQLite version 3042000, page size 32768, writer version 2, read version 2, file counter 3, database pages 3, cookie 0x1, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\tmp6035.tmp
ASCII text, with very long lines (1024), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\tmp6036.tmp
ASCII text, with very long lines (1024), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\tmp9169.tmp
ASCII text, with very long lines (1024), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\tmp916A.tmp
ASCII text, with very long lines (1024), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\tmp916B.tmp
ASCII text, with very long lines (1024), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\tmp916C.tmp
ASCII text, with very long lines (1024), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\tmp9491.tmp
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\tmpC7E7.tmp
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\tmpC826.tmp
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\tmpC827.tmp
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\tmpC838.tmp
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\tmpC839.tmp
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\tmpC84A.tmp
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\tmpFAF3.tmp
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\tmpFB04.tmp
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\tmpFB15.tmp
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\tmpFB25.tmp
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\tmpFB36.tmp
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\tmpFB37.tmp
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\tmpFB47.tmp
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\tmpFB58.tmp
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\tmpFB69.tmp
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\tmpFB6A.tmp
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
Chrome Cache Entry: 93
ASCII text, with very long lines (2294)
downloaded
Chrome Cache Entry: 94
ASCII text, with very long lines (2536)
downloaded
Chrome Cache Entry: 95
ASCII text
downloaded
Chrome Cache Entry: 96
ASCII text, with very long lines (3572), with no line terminators
downloaded
Chrome Cache Entry: 97
ASCII text, with very long lines (65531)
downloaded
Chrome Cache Entry: 98
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 99
ASCII text, with very long lines (2124)
downloaded
There are 43 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\SW3uxM7BXI.exe
"C:\Users\user\Desktop\SW3uxM7BXI.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://%3cfnc1%3e(%08)192207080962112986271363245700090061668218406782359533476819003707/
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2044 --field-trial-handle=2000,i,10893976321763395982,15945396058884010625,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8

URLs

Name
IP
Malicious
https://api.ipify.orgcookies//settinString.Removeg
unknown
malicious
http://185.223.28.15:4483/
185.223.28.15
malicious
185.223.28.15:4483
malicious
https://duckduckgo.com/chrome_newtab
unknown
https://duckduckgo.com/ac/?q=
unknown
http://www.broofa.com
unknown
http://schemas.xmlsoap.org/ws/2004/08/addressing/faultX
unknown
http://tempuri.org/Endpoint/EnvironmentSettings
unknown
https://api.ip.sb/geoip
unknown
http://schemas.xmlsoap.org/soap/envelope/
unknown
http://tempuri.org/
unknown
https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
unknown
http://tempuri.org/Endpoint/VerifyUpdateResponse
unknown
https://workspace.google.com/:session_prefix:marketplace/appfinder?usegapi=1
unknown
http://tempuri.org/Endpoint/SetEnvironment
unknown
http://tempuri.org/Endpoint/SetEnvironmentResponse
unknown
http://tempuri.org/Endpoint/GetUpdates
unknown
https://csp.withgoogle.com/csp/lcreport/
unknown
https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search
unknown
http://tempuri.org/Endpoint/VerifyUpdate
unknown
http://tempuri.org/0
unknown
https://www.google.com/async/newtab_ogb?hl=en-US&async=fixed:0
142.250.68.4
https://apis.google.com
unknown
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
unknown
https://domains.google.com/suggest/flow
unknown
https://ipinfo.io/ip%appdata%
unknown
https://www.google.com/images/branding/product/ico/googleg_lodp.ico
unknown
http://185.223.28.15
unknown
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous
unknown
http://tempuri.org/Endpoint/CheckConnectResponse
unknown
http://schemas.datacontract.org/2004/07/
unknown
https://api.ip.sb/geoip%USERPEnvironmentROFILE%
unknown
https://api.ip.sb
unknown
https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
unknown
https://www.google.com/async/newtab_promos
142.250.68.4
http://tempuri.org/Endpoint/CheckConnect
unknown
https://www.ecosia.org/newtab/
unknown
http://tempuri.org/Endpoint/SetEnviron
unknown
https://plus.google.com
unknown
https://ac.ecosia.org/autocomplete?q=
unknown
https://www.google.com/async/ddljson?async=ntp:2
142.250.68.4
https://play.google.com/log?format=json&hasfast=true
unknown
https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=1&pgcl=20&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw
142.250.68.4
http://schemas.xmlsoap.org/ws/2004/08/addressing
unknown
http://185.223.28.15:4483t-
unknown
http://tempuri.org/Endpoint/GetUpdatesResponse
unknown
https://apis.google.com/_/scs/abc-static/_/js/k=gapi.gapi.en.SCWmpDDGjPk.O/m=gapi_iframes,googleapis_client/rt=j/sv=1/d=1/ed=1/am=AAAC/rs=AHpOoo_Pl64J0IIHlj2zBtEJ3ZwdaJC3HA/cb=gapi.loaded_0
142.250.72.238
http://tempuri.org/Endpoint/EnvironmentSettingsResponse
unknown
http://185.223.28.15:4483
unknown
https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
unknown
http://schemas.xmlsoap.org/soap/actor/next
unknown
https://clients6.google.com
unknown
There are 42 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
api.ip.sb
unknown
malicious
plus.l.google.com
142.250.72.238
www.google.com
142.250.68.4
apis.google.com
unknown

IPs

IP
Domain
Country
Malicious
185.223.28.15
unknown
Germany
malicious
142.250.68.4
www.google.com
United States
142.250.72.238
plus.l.google.com
United States
192.168.2.4
unknown
unknown
239.255.255.250
unknown
Reserved

Registry

Path
Value
Malicious
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing
EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\SW3uxM7BXI_RASAPI32
EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\SW3uxM7BXI_RASAPI32
EnableAutoFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\SW3uxM7BXI_RASAPI32
EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\SW3uxM7BXI_RASAPI32
FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\SW3uxM7BXI_RASAPI32
ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\SW3uxM7BXI_RASAPI32
MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\SW3uxM7BXI_RASAPI32
FileDirectory
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\SW3uxM7BXI_RASMANCS
EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\SW3uxM7BXI_RASMANCS
EnableAutoFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\SW3uxM7BXI_RASMANCS
EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\SW3uxM7BXI_RASMANCS
FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\SW3uxM7BXI_RASMANCS
ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\SW3uxM7BXI_RASMANCS
MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\SW3uxM7BXI_RASMANCS
FileDirectory
There are 5 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
3A2000
unkown
page readonly
malicious
364E000
trusted library allocation
page read and write
6934000
trusted library allocation
page read and write
4C9E000
stack
page read and write
5F7B000
heap
page read and write
4F90000
trusted library allocation
page read and write
8C5000
heap
page read and write
2641000
trusted library allocation
page read and write
5EC0000
heap
page read and write
4F30000
trusted library allocation
page read and write
66CE000
stack
page read and write
6240000
trusted library allocation
page execute and read and write
5F84000
heap
page read and write
6250000
trusted library allocation
page read and write
36B9000
trusted library allocation
page read and write
263F000
stack
page read and write
6941000
trusted library allocation
page read and write
3A0000
unkown
page readonly
69A6000
trusted library allocation
page read and write
6955000
trusted library allocation
page read and write
7C1E000
stack
page read and write
6160000
trusted library allocation
page read and write
6F9B000
stack
page read and write
67AB000
heap
page read and write
670E000
stack
page read and write
4DEE000
stack
page read and write
50BA000
trusted library allocation
page read and write
672D000
heap
page read and write
4F5E000
trusted library allocation
page read and write
5C6F000
stack
page read and write
551D000
stack
page read and write
975000
trusted library allocation
page execute and read and write
6774000
heap
page read and write
947000
heap
page read and write
966000
trusted library allocation
page execute and read and write
930000
trusted library allocation
page read and write
6F40000
trusted library allocation
page read and write
69E0000
trusted library allocation
page read and write
9B4000
heap
page read and write
6130000
trusted library allocation
page read and write
5FA1000
heap
page read and write
4F46000
trusted library allocation
page read and write
27F9000
trusted library allocation
page read and write
65B000
stack
page read and write
4F61000
trusted library allocation
page read and write
528B000
trusted library allocation
page read and write
612F000
stack
page read and write
4FA1000
trusted library allocation
page read and write
69A0000
trusted library allocation
page read and write
471C000
stack
page read and write
CFB000
heap
page read and write
95D000
trusted library allocation
page execute and read and write
4F7A000
trusted library allocation
page read and write
890000
heap
page read and write
62FE000
stack
page read and write
6FA0000
trusted library allocation
page read and write
614F000
trusted library allocation
page read and write
4F41000
trusted library allocation
page read and write
629E000
stack
page read and write
692C000
trusted library allocation
page read and write
6926000
trusted library allocation
page read and write
93D000
trusted library allocation
page execute and read and write
6952000
trusted library allocation
page read and write
7BDE000
stack
page read and write
2803000
trusted library allocation
page read and write
26D3000
trusted library allocation
page read and write
528E000
trusted library allocation
page read and write
5280000
trusted library allocation
page read and write
90E000
stack
page read and write
6710000
heap
page read and write
4F70000
trusted library allocation
page read and write
988000
heap
page read and write
73D0000
heap
page read and write
972000
trusted library allocation
page read and write
4CE0000
heap
page execute and read and write
39D4000
trusted library allocation
page read and write
4FC0000
trusted library allocation
page read and write
4FE0000
trusted library allocation
page read and write
6175000
trusted library allocation
page read and write
37B9000
trusted library allocation
page read and write
73E6000
heap
page read and write
7F2D0000
trusted library allocation
page execute and read and write
512D000
stack
page read and write
692F000
trusted library allocation
page read and write
6139000
trusted library allocation
page read and write
6172000
trusted library allocation
page read and write
980000
heap
page read and write
B7F000
stack
page read and write
614A000
trusted library allocation
page read and write
6726000
heap
page read and write
24A0000
heap
page read and write
64D0000
heap
page read and write
6769000
heap
page read and write
694D000
trusted library allocation
page read and write
516E000
stack
page read and write
5010000
trusted library allocation
page execute and read and write
5FC2000
trusted library allocation
page read and write
24E0000
trusted library allocation
page read and write
933000
trusted library allocation
page execute and read and write
934000
trusted library allocation
page read and write
6FC0000
trusted library allocation
page execute and read and write
69EB000
trusted library allocation
page read and write
6960000
trusted library allocation
page read and write
7D20000
heap
page read and write
CF7000
heap
page read and write
3641000
trusted library allocation
page read and write
5170000
trusted library allocation
page execute and read and write
73B0000
trusted library allocation
page execute and read and write
5F98000
heap
page read and write
5F5B000
heap
page read and write
6155000
trusted library allocation
page read and write
5D6E000
stack
page read and write
98E000
heap
page read and write
4F52000
trusted library allocation
page read and write
7D1F000
stack
page read and write
4F3B000
trusted library allocation
page read and write
7390000
trusted library allocation
page read and write
5040000
trusted library allocation
page execute and read and write
693E000
trusted library allocation
page read and write
6020000
trusted library allocation
page execute and read and write
6922000
trusted library allocation
page read and write
73EA000
heap
page read and write
7A90000
trusted library allocation
page execute and read and write
50E0000
trusted library allocation
page execute and read and write
5FD0000
trusted library allocation
page execute and read and write
24C0000
trusted library allocation
page read and write
601E000
stack
page read and write
26D7000
trusted library allocation
page read and write
64E0000
heap
page read and write
5ECC000
heap
page read and write
4648000
trusted library allocation
page read and write
4E2E000
stack
page read and write
50A0000
trusted library allocation
page read and write
61EE000
stack
page read and write
7210000
heap
page read and write
50C0000
trusted library allocation
page read and write
3931000
trusted library allocation
page read and write
527E000
stack
page read and write
5540000
trusted library allocation
page read and write
757000
stack
page read and write
7D30000
trusted library allocation
page read and write
4F80000
trusted library allocation
page read and write
4FD0000
trusted library allocation
page read and write
970000
trusted library allocation
page read and write
73A0000
trusted library allocation
page read and write
71F0000
trusted library allocation
page read and write
5F94000
heap
page read and write
5EAE000
stack
page read and write
977000
trusted library allocation
page execute and read and write
2691000
trusted library allocation
page read and write
5F76000
heap
page read and write
6FB0000
trusted library allocation
page read and write
7ADE000
stack
page read and write
8C0000
heap
page read and write
6720000
heap
page read and write
6135000
trusted library allocation
page read and write
6170000
trusted library allocation
page read and write
6F50000
heap
page read and write
97B000
trusted library allocation
page execute and read and write
6180000
trusted library allocation
page read and write
5F7E000
heap
page read and write
6946000
trusted library allocation
page read and write
960000
trusted library allocation
page read and write
3652000
trusted library allocation
page read and write
6924000
trusted library allocation
page read and write
3672000
trusted library allocation
page read and write
69B0000
trusted library allocation
page read and write
4F74000
trusted library allocation
page read and write
71EE000
stack
page read and write
3873000
trusted library allocation
page read and write
615F000
trusted library allocation
page read and write
6164000
trusted library allocation
page read and write
6970000
trusted library allocation
page read and write
7B0000
heap
page read and write
24D0000
heap
page execute and read and write
6132000
trusted library allocation
page read and write
5F8A000
heap
page read and write
26A5000
trusted library allocation
page read and write
6938000
trusted library allocation
page read and write
4B9E000
stack
page read and write
CE0000
trusted library allocation
page execute and read and write
962000
trusted library allocation
page read and write
CD0000
trusted library allocation
page read and write
26C6000
trusted library allocation
page read and write
6148000
trusted library allocation
page read and write
940000
heap
page read and write
5FC0000
trusted library allocation
page read and write
950000
trusted library allocation
page read and write
7200000
trusted library allocation
page read and write
73C0000
trusted library allocation
page execute and read and write
4CDE000
stack
page read and write
5F9E000
heap
page read and write
CF0000
heap
page read and write
7380000
trusted library allocation
page execute and read and write
50D0000
trusted library allocation
page read and write
6763000
heap
page read and write
5EF2000
heap
page read and write
5090000
trusted library allocation
page read and write
69C0000
trusted library allocation
page read and write
2985000
trusted library allocation
page read and write
5020000
trusted library allocation
page read and write
CBF000
stack
page read and write
253E000
stack
page read and write
6948000
trusted library allocation
page read and write
920000
trusted library allocation
page read and write
622E000
stack
page read and write
4F2E000
stack
page read and write
69D0000
trusted library allocation
page execute and read and write
675A000
heap
page read and write
50BD000
trusted library allocation
page read and write
5030000
trusted library allocation
page read and write
9C2000
heap
page read and write
615A000
trusted library allocation
page read and write
BBE000
stack
page read and write
5F6E000
heap
page read and write
5EB0000
heap
page read and write
24F0000
heap
page read and write
5DAE000
stack
page read and write
481D000
stack
page read and write
There are 209 hidden memdumps, click here to show them.