Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
BaGkRDSifo.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
initial sample
|
||
C:\Users\user\Desktop\STHealthUpdate.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
modified
|
||
C:\Users\user\Desktop\Update\server.txt
|
ASCII text, with no line terminators
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\BaGkRDSifo.exe
|
"C:\Users\user\Desktop\BaGkRDSifo.exe"
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://www.adicon.com.cn/GetJSONReportItemListByCustomerBarocdeT
|
unknown
|
||
http://tempuri.org/QueryReport_PKIT
|
unknown
|
||
http://www.adicon.com.cn/GetSearchByteSampleT
|
unknown
|
||
http://www.adicon.com.cn/GetAllSampleListT
|
unknown
|
||
http://www.adicon.com.cn/GetSearchByteSampleToStringT
|
unknown
|
||
http://11.65.9.11:9082/jkda/webservice/DPService#
|
unknown
|
||
http://www.adicon.com.cn/ExistsByYYtmT
|
unknown
|
||
http://tempuri.org/rm_RegionTransT
|
unknown
|
||
http://tempuri.org/DownloadBarCodeFlagT
|
unknown
|
||
http://www.adicon.com.cn/GetReportItemListByCustomerBarocdeT
|
unknown
|
||
http://www.adicon.com.cn/AppItemDownT
|
unknown
|
||
http://tempuri.org/UpLoadReportFromBytesNewT
|
unknown
|
||
http://www.adicon.com.cn/GetTsscInfoT
|
unknown
|
||
http://www.adicon.com.cn/GetJSONReportItemListByOtherCodeT
|
unknown
|
||
http://tempuri.org/DownloadReportT
|
unknown
|
||
http://www.adicon.com.cn/ExistsReportByYYtmT
|
unknown
|
||
http://www.adicon.com.cn/UpdateMeiNianZuTaoT
|
unknown
|
||
http://www.adicon.com.cn/GetReportListT
|
unknown
|
||
http://www.adicon.com.cn/GetSearchByteSampleByOtherT
|
unknown
|
||
http://www.adicon.com.cn/GetBLTCTPicByYYTMT
|
unknown
|
||
http://www.adicon.com.cn/AppUpdateInfoT
|
unknown
|
||
http://www.adicon.com.cn/GetTsscInfoByAdiconBarcodeT
|
unknown
|
||
http://www.adicon.com.cn/GetReportItemListByCustomerBarocde_MeiNianT
|
unknown
|
||
http://www.adicon.com.cn/AppBarcodeStateT
|
unknown
|
||
http://tempuri.org/addInspectReqT
|
unknown
|
||
http://www.adicon.com.cn/SetSampleDownFlagByAdiconBarocdeT
|
unknown
|
||
http://www.adicon.com.cn/ValiUserT
|
unknown
|
||
http://www.adicon.com.cn/GetSearchStringSampleByAdiconCodeT
|
unknown
|
||
http://tempuri.org/DownloadReportFormIDListByClientBarcodeNoT
|
unknown
|
||
http://www.adicon.com.cn/GetTsscPicByAdiconBarcodeT
|
unknown
|
||
http://com.wondersgroup.jkda.application.modules.webservice
|
unknown
|
||
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
|
unknown
|
||
http://tempuri.org/DownloadReportFormIDListByBarcodeNoT
|
unknown
|
||
http://www.adicon.com.cn/ReportDetailForHzqbT
|
unknown
|
||
http://www.adicon.com.cn/UpLoadXmlT
|
unknown
|
||
http://tempuri.org/UpgradeRequestFormT
|
unknown
|
||
http://www.adicon.com.cn/GetXmmcListT
|
unknown
|
||
http://tempuri.org/GetReportUriT
|
unknown
|
||
http://www.adicon.com.cn/GetReportItemListByAdiconBarocde_MeiNianT
|
unknown
|
||
http://47.104.173.216:
|
unknown
|
||
http://47.104.173.216:9876
|
unknown
|
||
http://tempuri.org/HelloWorldT
|
unknown
|
||
http://www.adicon.com.cn/GetSearchStringSampleByCustomerCodeToByteT
|
unknown
|
||
http://www.adicon.com.cn/T
|
unknown
|
||
http://www.adicon.com.cn/GetSampleCountT
|
unknown
|
||
http://www.adicon.com.cn/LoginT
|
unknown
|
||
http://11.65.9.11:9082/jkda/webservice/DPService
|
unknown
|
||
http://tempuri.org/getPatResultNoXmlT
|
unknown
|
||
http://www.adicon.com.cn/GetByteReportT
|
unknown
|
||
http://www.adicon.com.cn/GetReportListV1T
|
unknown
|
||
http://com.wondersgroup.jkda.application.modules.webserviceTU
|
unknown
|
||
http://www.adicon.com.cn/ExistsReportOtherT
|
unknown
|
||
http://www.adicon.com.cn/GetInputXmmcListT
|
unknown
|
||
http://www.adicon.com.cn/GetReportBaseInfoT
|
unknown
|
||
http://www.adicon.com.cn/GetSearchSampleT
|
unknown
|
||
http://tempuri.org/CheckUpLoadReportFromBytesT
|
unknown
|
||
http://www.adicon.com.cn/GetBLTCTPicByKeyIdT
|
unknown
|
||
http://www.adicon.com.cn/UpLoadOrDownLoadByXmlT
|
unknown
|
||
http://www.adicon.com.cn/DetailListT
|
unknown
|
||
http://www.adicon.com.cn/GetReportUserItemByYYTMT
|
unknown
|
||
http://www.adicon.com.cn/GetReportUserItemT
|
unknown
|
||
http://www.adicon.com.cn/AppUpLoadXmlT
|
unknown
|
||
http://www.adicon.com.cn/GetAllSampleList_MeiNianT
|
unknown
|
||
http://tempuri.org/AppliyUpLoadT
|
unknown
|
||
http://tempuri.org/GetReportFormColumnT
|
unknown
|
||
http://tempuri.org/retrieveDocumentViewInfoT
|
unknown
|
||
http://www.adicon.com.cn/GetReportItemListByAdiconBarocdeT
|
unknown
|
||
http://tempuri.org/UpLoadRequestFormClientT
|
unknown
|
||
http://www.adicon.com.cn/GetReportItemListByAdiconRepnoT
|
unknown
|
||
http://tempuri.org/ChangestatusT
|
unknown
|
||
http://tempuri.org/DownloadReportByReportFormIDT
|
unknown
|
||
http://www.adicon.com.cn/GetSearchStringSampleByAdiconCodeToByteT
|
unknown
|
||
http://www.adicon.com.cn/SetSampleDownFlagByByAdiconRepnoT
|
unknown
|
||
http://www.adicon.com.cn/
|
unknown
|
||
http://www.adicon.com.cn/MeiNianOriginalDataXmlUpLoadT
|
unknown
|
||
http://tempuri.org/UpLoadReportFromBytes_ImageListT
|
unknown
|
||
http://www.adicon.com.cn/SetSampleDownFlagByCustomerBarocdeT
|
unknown
|
||
http://www.adicon.com.cn/DeleteGPGFileT
|
unknown
|
||
http://47.104.173.216:9876/server.txt
|
47.104.173.216
|
||
http://tempuri.org/addInspectReqNoXmlT
|
unknown
|
||
http://tempuri.org/getPatResultT
|
unknown
|
||
http://com.wondersgroup.jkda.application.modules.webserviceT
|
unknown
|
||
http://tempuri.org/DownloadReportByPersonIDT
|
unknown
|
||
http://www.adicon.com.cn/GetSearchByteSampleAiT
|
unknown
|
||
http://www.adicon.com.cn/ReportDetailT
|
unknown
|
||
http://tempuri.org/DownloadBarCodeCancelT
|
unknown
|
||
http://tempuri.org/DownLoadReportFormPDFByAccountPassWordT
|
unknown
|
||
http://tempuri.org/DownloadReportByBarcodeNoT
|
unknown
|
||
http://tempuri.org/DownLoadReportForm_PKIT
|
unknown
|
||
http://www.adicon.com.cn/GetBLTCTPicT
|
unknown
|
||
http://www.adicon.com.cn/GetJSONReportItemListByAdiconBarocdeT
|
unknown
|
||
http://tempuri.org/UpLoadReportFromBytesT
|
unknown
|
||
http://www.adicon.com.cn/AppTrackDownT
|
unknown
|
||
http://tempuri.org/$
|
unknown
|
||
http://www.adicon.com.cn/GetReportDetailByXmlDocumentT
|
unknown
|
||
http://www.adicon.com.cn/UpdatesSetDownT
|
unknown
|
||
http://www.adicon.com.cn/AppUpLoadDeleteT
|
unknown
|
||
http://tempuri.org/DownLoadReportFormIDT
|
unknown
|
||
http://47.104.173.216:9876/STHealthUpdate.exe
|
47.104.173.216
|
||
http://www.adicon.com.cn/GetByteReportByYYtmT
|
unknown
|
There are 90 hidden URLs, click here to show them.
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
47.104.173.216
|
unknown
|
China
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing
|
EnableConsoleTracing
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BaGkRDSifo_RASAPI32
|
EnableFileTracing
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BaGkRDSifo_RASAPI32
|
EnableAutoFileTracing
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BaGkRDSifo_RASAPI32
|
EnableConsoleTracing
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BaGkRDSifo_RASAPI32
|
FileTracingMask
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BaGkRDSifo_RASAPI32
|
ConsoleTracingMask
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BaGkRDSifo_RASAPI32
|
MaxFileSize
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BaGkRDSifo_RASAPI32
|
FileDirectory
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BaGkRDSifo_RASMANCS
|
EnableFileTracing
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BaGkRDSifo_RASMANCS
|
EnableAutoFileTracing
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BaGkRDSifo_RASMANCS
|
EnableConsoleTracing
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BaGkRDSifo_RASMANCS
|
FileTracingMask
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BaGkRDSifo_RASMANCS
|
ConsoleTracingMask
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BaGkRDSifo_RASMANCS
|
MaxFileSize
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\BaGkRDSifo_RASMANCS
|
FileDirectory
|
There are 5 hidden registries, click here to show them.
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
5B80000
|
trusted library section
|
page read and write
|
||
6580000
|
trusted library section
|
page read and write
|
||
3528000
|
trusted library allocation
|
page read and write
|
||
5888000
|
trusted library allocation
|
page read and write
|
||
BB90000
|
trusted library allocation
|
page read and write
|
||
972000
|
heap
|
page read and write
|
||
58B0000
|
trusted library allocation
|
page read and write
|
||
A380000
|
trusted library allocation
|
page read and write
|
||
B1AE000
|
stack
|
page read and write
|
||
5842000
|
heap
|
page read and write
|
||
B2E0000
|
trusted library allocation
|
page read and write
|
||
41B000
|
unkown
|
page readonly
|
||
6AFB000
|
trusted library allocation
|
page read and write
|
||
350F000
|
trusted library allocation
|
page read and write
|
||
6B00000
|
trusted library allocation
|
page read and write
|
||
5A00000
|
trusted library allocation
|
page read and write
|
||
25A0000
|
heap
|
page read and write
|
||
5A20000
|
trusted library allocation
|
page read and write
|
||
B390000
|
trusted library allocation
|
page read and write
|
||
B340000
|
trusted library allocation
|
page read and write
|
||
58B3000
|
heap
|
page read and write
|
||
352A000
|
trusted library allocation
|
page read and write
|
||
31F9000
|
trusted library allocation
|
page read and write
|
||
6C60000
|
heap
|
page read and write
|
||
422000
|
unkown
|
page read and write
|
||
5AB0000
|
trusted library allocation
|
page read and write
|
||
B2D0000
|
trusted library allocation
|
page read and write
|
||
6EE06000
|
unkown
|
page readonly
|
||
6B10000
|
trusted library allocation
|
page read and write
|
||
3101000
|
trusted library allocation
|
page read and write
|
||
2480000
|
trusted library allocation
|
page read and write
|
||
4563000
|
trusted library allocation
|
page read and write
|
||
5842000
|
heap
|
page read and write
|
||
6AD0000
|
trusted library allocation
|
page read and write
|
||
9BF000
|
heap
|
page read and write
|
||
9F2000
|
heap
|
page read and write
|
||
3560000
|
trusted library allocation
|
page read and write
|
||
5B70000
|
trusted library allocation
|
page read and write
|
||
B2D0000
|
trusted library allocation
|
page read and write
|
||
5895000
|
heap
|
page read and write
|
||
26E3000
|
heap
|
page read and write
|
||
6AF0000
|
trusted library allocation
|
page read and write
|
||
36B6000
|
trusted library allocation
|
page read and write
|
||
5980000
|
trusted library allocation
|
page read and write
|
||
B36F000
|
trusted library allocation
|
page read and write
|
||
35DB000
|
trusted library allocation
|
page read and write
|
||
6AF0000
|
trusted library allocation
|
page read and write
|
||
5A70000
|
trusted library section
|
page readonly
|
||
5A30000
|
trusted library allocation
|
page execute and read and write
|
||
990000
|
heap
|
page read and write
|
||
320C000
|
trusted library allocation
|
page read and write
|
||
B360000
|
trusted library allocation
|
page read and write
|
||
B340000
|
trusted library allocation
|
page read and write
|
||
3568000
|
trusted library allocation
|
page read and write
|
||
36CC000
|
trusted library allocation
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
984000
|
heap
|
page read and write
|
||
59D0000
|
trusted library allocation
|
page read and write
|
||
24F0000
|
trusted library allocation
|
page read and write
|
||
90E000
|
heap
|
page read and write
|
||
A13E000
|
stack
|
page read and write
|
||
B340000
|
trusted library allocation
|
page read and write
|
||
2456000
|
trusted library allocation
|
page execute and read and write
|
||
988000
|
heap
|
page read and write
|
||
2AA1000
|
heap
|
page read and write
|
||
6AF0000
|
trusted library allocation
|
page read and write
|
||
5900000
|
trusted library allocation
|
page read and write
|
||
B350000
|
trusted library allocation
|
page read and write
|
||
5B70000
|
trusted library allocation
|
page read and write
|
||
320A000
|
trusted library allocation
|
page read and write
|
||
7D60000
|
heap
|
page read and write
|
||
B2D0000
|
trusted library allocation
|
page read and write
|
||
7F5E000
|
stack
|
page read and write
|
||
B365000
|
trusted library allocation
|
page read and write
|
||
B2D0000
|
trusted library allocation
|
page read and write
|
||
6B10000
|
trusted library allocation
|
page read and write
|
||
B2C1000
|
trusted library allocation
|
page read and write
|
||
5A98000
|
trusted library allocation
|
page read and write
|
||
B2E0000
|
trusted library allocation
|
page read and write
|
||
B340000
|
trusted library allocation
|
page read and write
|
||
975000
|
heap
|
page read and write
|
||
3530000
|
trusted library allocation
|
page read and write
|
||
6AE1000
|
trusted library allocation
|
page read and write
|
||
5830000
|
heap
|
page read and write
|
||
6C70000
|
heap
|
page read and write
|
||
5848000
|
heap
|
page read and write
|
||
B340000
|
trusted library allocation
|
page read and write
|
||
6AF0000
|
trusted library allocation
|
page read and write
|
||
5A20000
|
trusted library allocation
|
page read and write
|
||
3218000
|
trusted library allocation
|
page read and write
|
||
2433000
|
trusted library allocation
|
page execute and read and write
|
||
A3A0000
|
trusted library allocation
|
page read and write
|
||
BBF000
|
stack
|
page read and write
|
||
30FE000
|
trusted library allocation
|
page read and write
|
||
B2B0000
|
trusted library allocation
|
page read and write
|
||
35ED000
|
trusted library allocation
|
page read and write
|
||
59A0000
|
trusted library allocation
|
page read and write
|
||
31FB000
|
trusted library allocation
|
page read and write
|
||
422000
|
unkown
|
page write copy
|
||
9EB000
|
heap
|
page read and write
|
||
2497000
|
heap
|
page read and write
|
||
6B10000
|
trusted library allocation
|
page read and write
|
||
B330000
|
trusted library allocation
|
page execute and read and write
|
||
5897000
|
heap
|
page read and write
|
||
B360000
|
trusted library allocation
|
page read and write
|
||
24E0000
|
trusted library allocation
|
page execute and read and write
|
||
B340000
|
trusted library allocation
|
page read and write
|
||
B370000
|
trusted library allocation
|
page read and write
|
||
6EDF0000
|
unkown
|
page readonly
|
||
31BB000
|
trusted library allocation
|
page read and write
|
||
52AE000
|
stack
|
page read and write
|
||
6AE0000
|
trusted library allocation
|
page read and write
|
||
59D0000
|
trusted library allocation
|
page read and write
|
||
5A20000
|
trusted library allocation
|
page read and write
|
||
968000
|
heap
|
page read and write
|
||
B330000
|
trusted library allocation
|
page read and write
|
||
596E000
|
trusted library allocation
|
page read and write
|
||
3547000
|
trusted library allocation
|
page read and write
|
||
6AF0000
|
trusted library allocation
|
page read and write
|
||
979000
|
heap
|
page read and write
|
||
2490000
|
heap
|
page read and write
|
||
5897000
|
heap
|
page read and write
|
||
9E3000
|
heap
|
page read and write
|
||
56F0000
|
trusted library allocation
|
page read and write
|
||
6AD0000
|
trusted library allocation
|
page read and write
|
||
946000
|
heap
|
page read and write
|
||
5A40000
|
trusted library allocation
|
page read and write
|
||
9FD000
|
heap
|
page read and write
|
||
3190000
|
trusted library allocation
|
page read and write
|
||
6AD0000
|
trusted library allocation
|
page read and write
|
||
9C4000
|
heap
|
page read and write
|
||
2FD0000
|
heap
|
page read and write
|
||
5831000
|
heap
|
page read and write
|
||
6AE0000
|
trusted library allocation
|
page read and write
|
||
31C3000
|
trusted library allocation
|
page read and write
|
||
B360000
|
trusted library allocation
|
page read and write
|
||
5B70000
|
trusted library allocation
|
page read and write
|
||
5710000
|
trusted library allocation
|
page read and write
|
||
5B70000
|
trusted library allocation
|
page read and write
|
||
6AF0000
|
trusted library allocation
|
page read and write
|
||
A3E000
|
stack
|
page read and write
|
||
2420000
|
trusted library allocation
|
page read and write
|
||
6AD0000
|
trusted library allocation
|
page execute and read and write
|
||
6B10000
|
trusted library allocation
|
page read and write
|
||
B350000
|
trusted library allocation
|
page read and write
|
||
59F0000
|
trusted library allocation
|
page read and write
|
||
B360000
|
trusted library allocation
|
page read and write
|
||
5A50000
|
trusted library allocation
|
page read and write
|
||
2FDA000
|
heap
|
page read and write
|
||
6AC0000
|
trusted library allocation
|
page execute and read and write
|
||
82DE000
|
stack
|
page read and write
|
||
6B10000
|
trusted library allocation
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
6B00000
|
trusted library allocation
|
page read and write
|
||
5858000
|
trusted library allocation
|
page read and write
|
||
5AA0000
|
trusted library allocation
|
page execute and read and write
|
||
B320000
|
trusted library allocation
|
page read and write
|
||
58CD000
|
trusted library allocation
|
page read and write
|
||
9A5000
|
heap
|
page read and write
|
||
5A90000
|
trusted library allocation
|
page read and write
|
||
41B000
|
unkown
|
page readonly
|
||
2430000
|
trusted library allocation
|
page read and write
|
||
5875000
|
heap
|
page read and write
|
||
6B00000
|
trusted library allocation
|
page read and write
|
||
6B00000
|
trusted library allocation
|
page read and write
|
||
58A0000
|
trusted library allocation
|
page read and write
|
||
26CE000
|
trusted library allocation
|
page read and write
|
||
96BF000
|
stack
|
page read and write
|
||
B384000
|
trusted library allocation
|
page read and write
|
||
A2BE000
|
stack
|
page read and write
|
||
B340000
|
trusted library allocation
|
page read and write
|
||
970000
|
heap
|
page read and write
|
||
31A0000
|
heap
|
page execute and read and write
|
||
5A72000
|
trusted library allocation
|
page read and write
|
||
246B000
|
trusted library allocation
|
page execute and read and write
|
||
B2C0000
|
trusted library allocation
|
page read and write
|
||
5A20000
|
trusted library allocation
|
page read and write
|
||
6EE0D000
|
unkown
|
page read and write
|
||
5A90000
|
heap
|
page read and write
|
||
30EB000
|
trusted library allocation
|
page read and write
|
||
5B70000
|
trusted library allocation
|
page read and write
|
||
320E000
|
trusted library allocation
|
page read and write
|
||
5A20000
|
trusted library allocation
|
page read and write
|
||
A490000
|
trusted library allocation
|
page read and write
|
||
B340000
|
trusted library allocation
|
page read and write
|
||
B330000
|
trusted library allocation
|
page read and write
|
||
A380000
|
heap
|
page read and write
|
||
1E7000
|
heap
|
page read and write
|
||
31DE000
|
trusted library allocation
|
page read and write
|
||
96A000
|
heap
|
page read and write
|
||
9D9000
|
heap
|
page read and write
|
||
6B30000
|
heap
|
page read and write
|
||
9F7000
|
heap
|
page read and write
|
||
81DE000
|
stack
|
page read and write
|
||
9D9000
|
heap
|
page read and write
|
||
9D41000
|
heap
|
page read and write
|
||
9C4000
|
heap
|
page read and write
|
||
5B70000
|
trusted library allocation
|
page read and write
|
||
6AE0000
|
trusted library allocation
|
page read and write
|
||
2EF8000
|
trusted library allocation
|
page read and write
|
||
58D3000
|
trusted library allocation
|
page read and write
|
||
6B10000
|
trusted library allocation
|
page read and write
|
||
58E0000
|
trusted library allocation
|
page read and write
|
||
900000
|
heap
|
page read and write
|
||
B31E000
|
stack
|
page read and write
|
||
2590000
|
trusted library allocation
|
page read and write
|
||
B380000
|
trusted library allocation
|
page read and write
|
||
976000
|
heap
|
page read and write
|
||
5B70000
|
trusted library allocation
|
page read and write
|
||
35EA000
|
trusted library allocation
|
page read and write
|
||
5B70000
|
trusted library allocation
|
page read and write
|
||
6AE9000
|
trusted library allocation
|
page read and write
|
||
835E000
|
stack
|
page read and write
|
||
3535000
|
trusted library allocation
|
page read and write
|
||
3214000
|
trusted library allocation
|
page read and write
|
||
B360000
|
trusted library allocation
|
page read and write
|
||
6AD0000
|
trusted library allocation
|
page read and write
|
||
5A50000
|
trusted library allocation
|
page read and write
|
||
3170000
|
trusted library allocation
|
page read and write
|
||
31D6000
|
trusted library allocation
|
page read and write
|
||
6AD0000
|
trusted library allocation
|
page read and write
|
||
2580000
|
trusted library allocation
|
page read and write
|
||
6AF0000
|
trusted library allocation
|
page read and write
|
||
A300000
|
trusted library allocation
|
page execute and read and write
|
||
B380000
|
trusted library allocation
|
page read and write
|
||
2560000
|
heap
|
page read and write
|
||
B380000
|
trusted library allocation
|
page read and write
|
||
3511000
|
trusted library allocation
|
page read and write
|
||
9DB000
|
heap
|
page read and write
|
||
B2AF000
|
stack
|
page read and write
|
||
6AF0000
|
trusted library allocation
|
page read and write
|
||
6AF0000
|
trusted library allocation
|
page read and write
|
||
26C0000
|
trusted library allocation
|
page read and write
|
||
A3B0000
|
trusted library allocation
|
page read and write
|
||
3180000
|
trusted library allocation
|
page read and write
|
||
B380000
|
trusted library allocation
|
page read and write
|
||
6AD0000
|
trusted library allocation
|
page read and write
|
||
B350000
|
trusted library allocation
|
page read and write
|
||
56EF000
|
stack
|
page read and write
|
||
5836000
|
heap
|
page read and write
|
||
3515000
|
trusted library allocation
|
page read and write
|
||
6AD0000
|
trusted library allocation
|
page read and write
|
||
26C9000
|
trusted library allocation
|
page read and write
|
||
2443000
|
trusted library allocation
|
page read and write
|
||
5B70000
|
trusted library allocation
|
page read and write
|
||
6EDF1000
|
unkown
|
page execute read
|
||
30DF000
|
stack
|
page read and write
|
||
5A60000
|
trusted library allocation
|
page read and write
|
||
583E000
|
heap
|
page read and write
|
||
3212000
|
trusted library allocation
|
page read and write
|
||
3160000
|
trusted library allocation
|
page read and write
|
||
B2D0000
|
trusted library allocation
|
page read and write
|
||
A390000
|
trusted library allocation
|
page read and write
|
||
B2B0000
|
trusted library allocation
|
page read and write
|
||
5875000
|
heap
|
page read and write
|
||
59E0000
|
trusted library allocation
|
page read and write
|
||
B2D0000
|
trusted library allocation
|
page read and write
|
||
9F2000
|
heap
|
page read and write
|
||
9C2000
|
heap
|
page read and write
|
||
9F8000
|
heap
|
page read and write
|
||
6AD0000
|
trusted library allocation
|
page read and write
|
||
5701000
|
trusted library allocation
|
page read and write
|
||
6AF0000
|
trusted library allocation
|
page read and write
|
||
5A60000
|
trusted library allocation
|
page read and write
|
||
BE4E000
|
stack
|
page read and write
|
||
2510000
|
heap
|
page read and write
|
||
5A60000
|
trusted library allocation
|
page read and write
|
||
6AE0000
|
trusted library allocation
|
page read and write
|
||
B2D0000
|
trusted library allocation
|
page read and write
|
||
B320000
|
trusted library allocation
|
page read and write
|
||
B320000
|
trusted library allocation
|
page read and write
|
||
5990000
|
trusted library allocation
|
page read and write
|
||
B350000
|
trusted library allocation
|
page read and write
|
||
350B000
|
trusted library allocation
|
page read and write
|
||
9D9000
|
heap
|
page read and write
|
||
A2FF000
|
stack
|
page read and write
|
||
5A10000
|
heap
|
page read and write
|
||
5940000
|
trusted library allocation
|
page read and write
|
||
B360000
|
trusted library allocation
|
page read and write
|
||
2460000
|
trusted library allocation
|
page read and write
|
||
B360000
|
trusted library allocation
|
page read and write
|
||
26D1000
|
trusted library allocation
|
page read and write
|
||
355C000
|
trusted library allocation
|
page read and write
|
||
5950000
|
trusted library allocation
|
page read and write
|
||
A7F000
|
stack
|
page read and write
|
||
9F7000
|
heap
|
page read and write
|
||
B330000
|
trusted library allocation
|
page read and write
|
||
B390000
|
trusted library allocation
|
page read and write
|
||
B320000
|
trusted library allocation
|
page read and write
|
||
5A60000
|
trusted library allocation
|
page read and write
|
||
6AE5000
|
trusted library allocation
|
page read and write
|
||
2450000
|
trusted library allocation
|
page read and write
|
||
5B70000
|
trusted library allocation
|
page read and write
|
||
2462000
|
trusted library allocation
|
page read and write
|
||
6AD0000
|
trusted library allocation
|
page read and write
|
||
59F3000
|
trusted library allocation
|
page read and write
|
||
3216000
|
trusted library allocation
|
page read and write
|
||
96D000
|
heap
|
page read and write
|
||
5710000
|
trusted library allocation
|
page read and write
|
||
5A30000
|
trusted library allocation
|
page read and write
|
||
5700000
|
trusted library allocation
|
page read and write
|
||
819F000
|
stack
|
page read and write
|
||
6AE0000
|
trusted library allocation
|
page read and write
|
||
3545000
|
trusted library allocation
|
page read and write
|
||
5865000
|
heap
|
page read and write
|
||
42A000
|
unkown
|
page read and write
|
||
5884000
|
trusted library allocation
|
page read and write
|
||
5B70000
|
trusted library allocation
|
page read and write
|
||
350D000
|
trusted library allocation
|
page read and write
|
||
3543000
|
trusted library allocation
|
page read and write
|
||
5862000
|
heap
|
page read and write
|
||
5A20000
|
trusted library allocation
|
page read and write
|
||
7CD000
|
unkown
|
page read and write
|
||
A280000
|
trusted library allocation
|
page read and write
|
||
6B10000
|
trusted library allocation
|
page read and write
|
||
58C2000
|
heap
|
page read and write
|
||
B350000
|
trusted library allocation
|
page read and write
|
||
3513000
|
trusted library allocation
|
page read and write
|
||
A03C000
|
stack
|
page read and write
|
||
B370000
|
trusted library allocation
|
page read and write
|
||
B340000
|
trusted library allocation
|
page read and write
|
||
B370000
|
trusted library allocation
|
page read and write
|
||
426000
|
unkown
|
page readonly
|
||
9D40000
|
heap
|
page read and write
|
||
5830000
|
trusted library allocation
|
page read and write
|
||
B2D0000
|
trusted library allocation
|
page read and write
|
||
31BD000
|
trusted library allocation
|
page read and write
|
||
354D000
|
trusted library allocation
|
page read and write
|
||
588D000
|
trusted library allocation
|
page read and write
|
||
5831000
|
heap
|
page read and write
|
||
3210000
|
trusted library allocation
|
page read and write
|
||
6C50000
|
heap
|
page read and write
|
||
BB70000
|
trusted library allocation
|
page read and write
|
||
B340000
|
trusted library allocation
|
page read and write
|
||
90A000
|
heap
|
page read and write
|
||
583E000
|
heap
|
page read and write
|
||
255C000
|
stack
|
page read and write
|
||
9C9000
|
heap
|
page read and write
|
||
9F8000
|
heap
|
page read and write
|
||
5A20000
|
trusted library allocation
|
page read and write
|
||
36A6000
|
trusted library allocation
|
page read and write
|
||
5831000
|
heap
|
page read and write
|
||
6B40000
|
heap
|
page read and write
|
||
5734000
|
heap
|
page read and write
|
||
3106000
|
trusted library allocation
|
page read and write
|
||
35E7000
|
trusted library allocation
|
page read and write
|
||
B350000
|
trusted library allocation
|
page read and write
|
||
583E000
|
heap
|
page read and write
|
||
3549000
|
trusted library allocation
|
page read and write
|
||
3657000
|
trusted library allocation
|
page read and write
|
||
6AD0000
|
trusted library allocation
|
page read and write
|
||
9B7E000
|
stack
|
page read and write
|
||
B320000
|
trusted library allocation
|
page read and write
|
||
35E1000
|
trusted library allocation
|
page read and write
|
||
6AE0000
|
trusted library allocation
|
page read and write
|
||
5A40000
|
trusted library allocation
|
page read and write
|
||
B360000
|
trusted library allocation
|
page read and write
|
||
5840000
|
trusted library allocation
|
page read and write
|
||
5A20000
|
trusted library allocation
|
page read and write
|
||
584F000
|
heap
|
page read and write
|
||
5B70000
|
trusted library allocation
|
page read and write
|
||
5836000
|
heap
|
page read and write
|
||
3562000
|
trusted library allocation
|
page read and write
|
||
9C3E000
|
stack
|
page read and write
|
||
6C84000
|
heap
|
page read and write
|
||
59F0000
|
trusted library allocation
|
page read and write
|
||
5B70000
|
trusted library allocation
|
page read and write
|
||
5A20000
|
trusted library allocation
|
page read and write
|
||
6AD0000
|
trusted library allocation
|
page read and write
|
||
5897000
|
heap
|
page read and write
|
||
5A40000
|
trusted library allocation
|
page read and write
|
||
B360000
|
trusted library allocation
|
page read and write
|
||
6B10000
|
trusted library allocation
|
page read and write
|
||
31C1000
|
trusted library allocation
|
page read and write
|
||
2434000
|
trusted library allocation
|
page read and write
|
||
9A7E000
|
stack
|
page read and write
|
||
9EE000
|
heap
|
page read and write
|
||
6B10000
|
trusted library allocation
|
page read and write
|
||
6AE0000
|
trusted library allocation
|
page read and write
|
||
B2D0000
|
trusted library allocation
|
page read and write
|
||
5A80000
|
heap
|
page read and write
|
||
5836000
|
heap
|
page read and write
|
||
B360000
|
trusted library allocation
|
page read and write
|
||
B390000
|
trusted library allocation
|
page read and write
|
||
B380000
|
trusted library allocation
|
page read and write
|
||
31E2000
|
trusted library allocation
|
page read and write
|
||
58F0000
|
trusted library allocation
|
page read and write
|
||
9D1000
|
heap
|
page read and write
|
||
2440000
|
trusted library allocation
|
page read and write
|
||
B2E0000
|
trusted library allocation
|
page read and write
|
||
5A40000
|
trusted library allocation
|
page read and write
|
||
A310000
|
trusted library allocation
|
page read and write
|
||
5A30000
|
trusted library allocation
|
page read and write
|
||
26C7000
|
trusted library allocation
|
page read and write
|
||
6AF0000
|
trusted library allocation
|
page read and write
|
||
5910000
|
trusted library allocation
|
page read and write
|
||
7E0000
|
heap
|
page read and write
|
||
B2B0000
|
trusted library allocation
|
page read and write
|
||
3517000
|
trusted library allocation
|
page read and write
|
||
35FA000
|
trusted library allocation
|
page read and write
|
||
97000
|
stack
|
page read and write
|
||
B370000
|
trusted library allocation
|
page read and write
|
||
5970000
|
trusted library allocation
|
page read and write
|
||
B380000
|
trusted library allocation
|
page read and write
|
||
B350000
|
trusted library allocation
|
page read and write
|
||
98A000
|
heap
|
page read and write
|
||
5A50000
|
trusted library allocation
|
page read and write
|
||
B350000
|
trusted library allocation
|
page read and write
|
||
59E0000
|
trusted library allocation
|
page read and write
|
||
198000
|
stack
|
page read and write
|
||
9BBE000
|
stack
|
page read and write
|
||
5920000
|
trusted library allocation
|
page read and write
|
||
41B9000
|
trusted library allocation
|
page read and write
|
||
6AE0000
|
trusted library allocation
|
page read and write
|
||
9DF000
|
heap
|
page read and write
|
||
5B70000
|
trusted library allocation
|
page read and write
|
||
6AD0000
|
trusted library allocation
|
page read and write
|
||
58C4000
|
trusted library allocation
|
page read and write
|
||
B320000
|
trusted library allocation
|
page read and write
|
||
939000
|
heap
|
page read and write
|
||
5A00000
|
trusted library allocation
|
page read and write
|
||
2452000
|
trusted library allocation
|
page read and write
|
||
6EE0F000
|
unkown
|
page readonly
|
||
6AF0000
|
trusted library allocation
|
page read and write
|
||
31F7000
|
trusted library allocation
|
page read and write
|
||
1E0000
|
heap
|
page read and write
|
||
5895000
|
heap
|
page read and write
|
||
8E0000
|
trusted library section
|
page read and write
|
||
6B00000
|
trusted library allocation
|
page read and write
|
||
31BF000
|
trusted library allocation
|
page read and write
|
||
5849000
|
heap
|
page read and write
|
||
831E000
|
stack
|
page read and write
|
||
BB80000
|
trusted library allocation
|
page execute and read and write
|
||
9F7000
|
heap
|
page read and write
|
||
2518000
|
heap
|
page read and write
|
||
31DC000
|
trusted library allocation
|
page read and write
|
||
5A20000
|
trusted library allocation
|
page read and write
|
||
59F1000
|
trusted library allocation
|
page read and write
|
||
5A50000
|
trusted library allocation
|
page read and write
|
||
809E000
|
stack
|
page read and write
|
||
B370000
|
trusted library allocation
|
page read and write
|
||
9FB000
|
heap
|
page read and write
|
||
58C8000
|
trusted library allocation
|
page read and write
|
||
9BF000
|
heap
|
page read and write
|
||
5A20000
|
trusted library allocation
|
page read and write
|
||
5A60000
|
trusted library allocation
|
page read and write
|
||
59E0000
|
trusted library allocation
|
page read and write
|
||
3519000
|
trusted library allocation
|
page read and write
|
||
3566000
|
trusted library allocation
|
page read and write
|
||
5AEC000
|
stack
|
page read and write
|
||
5A80000
|
trusted library allocation
|
page read and write
|
||
31FE000
|
trusted library allocation
|
page read and write
|
||
3654000
|
trusted library allocation
|
page read and write
|
||
6AF1000
|
trusted library allocation
|
page read and write
|
||
41B1000
|
trusted library allocation
|
page read and write
|
||
9F7000
|
heap
|
page read and write
|
||
5710000
|
trusted library allocation
|
page read and write
|
||
26B0000
|
trusted library allocation
|
page read and write
|
||
5865000
|
heap
|
page read and write
|
||
6AF0000
|
trusted library allocation
|
page read and write
|
||
244D000
|
trusted library allocation
|
page execute and read and write
|
||
5A30000
|
trusted library allocation
|
page read and write
|
||
969000
|
heap
|
page read and write
|
||
6AE0000
|
trusted library allocation
|
page read and write
|
||
245A000
|
trusted library allocation
|
page execute and read and write
|
||
5A20000
|
trusted library allocation
|
page read and write
|
||
2467000
|
trusted library allocation
|
page execute and read and write
|
||
B370000
|
trusted library allocation
|
page read and write
|
||
3190000
|
trusted library allocation
|
page read and write
|
||
6AE0000
|
trusted library allocation
|
page read and write
|
||
3564000
|
trusted library allocation
|
page read and write
|
||
995000
|
heap
|
page read and write
|
||
6AE0000
|
trusted library allocation
|
page read and write
|
||
B360000
|
trusted library allocation
|
page read and write
|
||
59D0000
|
trusted library allocation
|
page read and write
|
||
3532000
|
trusted library allocation
|
page read and write
|
||
6AF0000
|
trusted library allocation
|
page read and write
|
||
6AD0000
|
trusted library allocation
|
page read and write
|
||
5A80000
|
trusted library allocation
|
page read and write
|
||
B2D0000
|
trusted library allocation
|
page read and write
|
||
6AF0000
|
trusted library allocation
|
page read and write
|
||
355E000
|
trusted library allocation
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
6C4E000
|
stack
|
page read and write
|
||
B2B0000
|
trusted library allocation
|
page read and write
|
||
6AF0000
|
trusted library allocation
|
page read and write
|
||
45A4000
|
trusted library allocation
|
page read and write
|
||
987000
|
heap
|
page read and write
|
||
35CC000
|
trusted library allocation
|
page read and write
|
||
6AD0000
|
trusted library allocation
|
page read and write
|
||
56F0000
|
trusted library allocation
|
page read and write
|
||
9C7000
|
heap
|
page read and write
|
||
5A20000
|
trusted library allocation
|
page read and write
|
||
B350000
|
trusted library allocation
|
page read and write
|
||
5842000
|
heap
|
page read and write
|
||
5A10000
|
trusted library allocation
|
page read and write
|
||
2590000
|
trusted library allocation
|
page read and write
|
||
5727000
|
heap
|
page execute and read and write
|
||
B340000
|
trusted library allocation
|
page read and write
|
||
5A12000
|
trusted library allocation
|
page read and write
|
||
ACB2000
|
trusted library allocation
|
page read and write
|
||
B360000
|
trusted library allocation
|
page read and write
|
||
584F000
|
heap
|
page read and write
|
||
9F2000
|
heap
|
page read and write
|
||
31B1000
|
trusted library allocation
|
page read and write
|
||
B350000
|
trusted library allocation
|
page read and write
|
||
8C0000
|
heap
|
page read and write
|
||
5870000
|
trusted library allocation
|
page read and write
|
||
5B71000
|
trusted library allocation
|
page read and write
|
||
B2C0000
|
trusted library allocation
|
page read and write
|
||
5A20000
|
trusted library allocation
|
page read and write
|
||
24DE000
|
stack
|
page read and write
|
||
30E0000
|
trusted library allocation
|
page read and write
|
||
5875000
|
heap
|
page read and write
|
||
B360000
|
trusted library allocation
|
page read and write
|
||
585B000
|
heap
|
page read and write
|
||
6B00000
|
trusted library allocation
|
page read and write
|
||
5890000
|
trusted library allocation
|
page read and write
|
||
6AD0000
|
trusted library allocation
|
page read and write
|
||
5B70000
|
trusted library allocation
|
page read and write
|
||
31F5000
|
trusted library allocation
|
page read and write
|
||
352E000
|
trusted library allocation
|
page read and write
|
||
6AF0000
|
trusted library allocation
|
page read and write
|
||
B360000
|
trusted library allocation
|
page read and write
|
||
6AF0000
|
trusted library allocation
|
page read and write
|
||
6AE0000
|
trusted library allocation
|
page read and write
|
||
26E0000
|
heap
|
page read and write
|
||
5A90000
|
trusted library allocation
|
page read and write
|
||
1E5000
|
heap
|
page read and write
|
||
5854000
|
trusted library allocation
|
page read and write
|
||
5A40000
|
trusted library allocation
|
page read and write
|
||
310D000
|
trusted library allocation
|
page read and write
|
||
5720000
|
heap
|
page execute and read and write
|
||
26C0000
|
trusted library allocation
|
page read and write
|
||
6AF0000
|
trusted library allocation
|
page read and write
|
||
6AE0000
|
trusted library allocation
|
page read and write
|
||
6AF0000
|
heap
|
page execute and read and write
|
||
5B70000
|
trusted library allocation
|
page read and write
|
||
583A000
|
heap
|
page read and write
|
||
B363000
|
trusted library allocation
|
page read and write
|
||
6AD0000
|
trusted library allocation
|
page read and write
|
||
584F000
|
heap
|
page read and write
|
||
B2D0000
|
trusted library allocation
|
page read and write
|
||
B360000
|
trusted library allocation
|
page read and write
|
||
426000
|
unkown
|
page readonly
|
||
5930000
|
trusted library allocation
|
page read and write
|
||
9D7000
|
heap
|
page read and write
|
||
58B3000
|
heap
|
page read and write
|
||
6AD0000
|
trusted library allocation
|
page read and write
|
||
6AE0000
|
trusted library allocation
|
page read and write
|
||
98FF000
|
stack
|
page read and write
|
||
ABE000
|
stack
|
page read and write
|
||
3600000
|
trusted library allocation
|
page read and write
|
||
B370000
|
trusted library allocation
|
page read and write
|
||
9BFF000
|
stack
|
page read and write
|
||
5895000
|
heap
|
page read and write
|
||
5B70000
|
trusted library allocation
|
page read and write
|
||
8F0000
|
trusted library section
|
page read and write
|
||
2FCE000
|
stack
|
page read and write
|
||
31D8000
|
trusted library allocation
|
page read and write
|
||
B380000
|
trusted library allocation
|
page read and write
|
||
3736000
|
trusted library allocation
|
page read and write
|
||
805F000
|
stack
|
page read and write
|
||
6C55000
|
heap
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
5860000
|
trusted library allocation
|
page read and write
|
||
9D3F000
|
stack
|
page read and write
|
||
31DA000
|
trusted library allocation
|
page read and write
|
||
B2B0000
|
trusted library allocation
|
page read and write
|
||
35DE000
|
trusted library allocation
|
page read and write
|
||
5A30000
|
trusted library allocation
|
page read and write
|
||
5A70000
|
trusted library allocation
|
page read and write
|
||
243D000
|
trusted library allocation
|
page execute and read and write
|
||
31C6000
|
trusted library allocation
|
page read and write
|
||
B2D0000
|
trusted library allocation
|
page read and write
|
||
5831000
|
heap
|
page read and write
|
||
25B0000
|
heap
|
page read and write
|
||
A390000
|
heap
|
page read and write
|
There are 568 hidden memdumps, click here to show them.