IOC Report
dqwdq

loading gifFilesProcessesMemdumps5040302010010010Label

Files

File Path
Type
Category
Malicious
Download
dqwdq.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
initial sample
malicious
C:
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2107.4-0\DefenderCSP.dll
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2107.4-0\Drivers\WdBoot.sys
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2107.4-0\Drivers\WdDevFlt.sys
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2107.4-0\Drivers\WdFilter.sys
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2107.4-0\Drivers\WdNisDrv.sys
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2107.4-0\MpAsDesc.dll
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2107.4-0\MpAzSubmit.dll
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2107.4-0\MpClient.dll
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2107.4-0\MpCmdRun.exe
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2107.4-0\MpCommu.dll
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2107.4-0\MpDetours.dll
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2107.4-0\MpDlpCmd.exe
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2107.4-0\MpOAV.dll
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2107.4-0\MpRtp.dll
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2107.4-0\MpSvc.dll
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2107.4-0\MpUpdate.dll
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2107.4-0\MpUxAgent.dll
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2107.4-0\MsMpEng.exe
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2107.4-0\MsMpLics.dll
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2107.4-0\NisSrv.exe
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2107.4-0\X86\MpAsDesc.dll
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2107.4-0\X86\MpClient.dll
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2107.4-0\X86\MpCmdRun.exe
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2107.4-0\X86\MpDetours.dll
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2107.4-0\X86\MpOAV.dll
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2107.4-0\X86\MsMpLics.dll
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2107.4-0\X86\endpointdlp.dll
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2107.4-0\endpointdlp.dll
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2107.4-0\mpextms.exe
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\DefenderCSP.dll
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\Drivers\WdBoot.sys
data
modified
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\Drivers\WdDevFlt.sys
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\Drivers\WdFilter.sys
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\MpAzSubmit.dll
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\MpCmdRun.exe
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\MpDetours.dll
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\MpDlpCmd.exe
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\MpEvMsg.dll
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\MpUpdate.dll
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\MpUxAgent.dll
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\MsMpLics.dll
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\X86\MpAsDesc.dll
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\X86\MpClient.dll
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\X86\MpCmdRun.exe
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\X86\MpDetours.dll
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\X86\MsMpLics.dll
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\X86\endpointdlp.dll
SysEx File - Matsushita
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\endpointdlp.dll
data
dropped
malicious
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2108.7-0\mpextms.exe
data
dropped
malicious
C:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics\energy-report.html
data
dropped
malicious
\Device\Harddisk0\DR0
data
dropped
malicious
C:\$Recycle.Bin\S-1-5-18\desktop.ini
data
dropped
C:\$Recycle.Bin\S-1-5-21-3425316567-2969588382-3778222414-1000\desktop.ini
data
dropped
C:\$Recycle.Bin\S-1-5-21-3425316567-2969588382-3778222414-1001\desktop.ini
data
dropped
C:\ProgramData\Adobe\ARM\{291AA914-A987-4CE9-BD63-AC0A92D435E5}\RdrManifest3.msi
data
dropped
C:\ProgramData\Intel\GCC\IGCCSvc.db
data
dropped
C:\ProgramData\Intel\GCC\gcc_svc_log_2021-09-03.txt
PGP\011Secret Sub-key -
dropped
C:\ProgramData\Intel\GCC\gcc_svc_log_2021-09-14.txt
data
dropped
C:\ProgramData\Intel\GCC\gcc_svc_log_2021-09-22.txt
data
dropped
C:\ProgramData\Intel\GCC\gcc_svc_log_2021-09-30.txt
data
dropped
C:\ProgramData\Intel\GCC\gcc_svc_log_2022-01-20.txt
data
dropped
C:\ProgramData\Intel\GCC\gcc_svc_log_2022-02-23.txt
data
dropped
C:\ProgramData\Intel\GCC\gcc_svc_log_2022-03-02.txt
data
dropped
C:\ProgramData\Microsoft\ClickToRun\DeploymentConfig.1.xml
data
dropped
C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\TELEMETRY.ASM-WINDOWSSQ.json
data
dropped
C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.allow.json
data
dropped
C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.app.json
data
dropped
C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.app.json.bk
data
dropped
C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.cert.json
data
dropped
C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.cert.json.bk
data
dropped
C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.privacy.json
data
dropped
C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.tracing.json
data
dropped
C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.tracing.json.bk
data
dropped
C:\ProgramData\Microsoft\Diagnosis\ETLLogs\ShutdownLogger\Diagtrack-Listener.etl
data
dropped
C:\ProgramData\Microsoft\Diagnosis\EventStore.db
data
dropped
C:\ProgramData\Microsoft\Diagnosis\ScenariosSqlStore\EventStore.db
data
dropped
C:\ProgramData\Microsoft\Diagnosis\TenantStorage\P-ARIA\EventStore.db
data
dropped
C:\ProgramData\Microsoft\Diagnosis\osver.txt
data
dropped
C:\ProgramData\Microsoft\EdgeUpdate\Log\MicrosoftEdgeUpdate.log
data
dropped
C:\ProgramData\Microsoft\IdentityCRL\INT\wlidsvcconfig.xml
data
dropped
C:\ProgramData\Microsoft\IdentityCRL\production\wlidsvcconfig.xml
data
dropped
C:\ProgramData\Microsoft\MF\Active.GRL
data
dropped
C:\ProgramData\Microsoft\MF\Pending.GRL
data
dropped
C:\ProgramData\Microsoft\Network\Downloader\edb.chk
data
dropped
C:\ProgramData\Microsoft\Network\Downloader\edb.log
data
dropped
C:\ProgramData\Microsoft\Network\Downloader\edb00001.log
data
dropped
C:\ProgramData\Microsoft\Network\Downloader\edbres00001.jrs
data
dropped
C:\ProgramData\Microsoft\Network\Downloader\edbres00002.jrs
data
dropped
C:\ProgramData\Microsoft\Network\Downloader\edbtmp.log
data
dropped
C:\ProgramData\Microsoft\Network\Downloader\qmgr.db
data
dropped
C:\ProgramData\Microsoft\Network\Downloader\qmgr.jfm
data
dropped
C:\ProgramData\Microsoft\Office\Licenses\5\Perpetual\21661362613886715948323998795
data
dropped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb
data
dropped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.jfm
data
dropped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb.jcp
data
dropped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb.jtx
data
dropped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb0000C.jtx
data
dropped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb0000D.jtx
data
dropped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb0000E.jtx
data
dropped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edbres00001.jrs
data
dropped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edbres00002.jrs
data
dropped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edbtmp.jtx
data
dropped
C:\ProgramData\Microsoft\SmsRouter\MessageStore\SmsInterceptStore.db
data
dropped
C:\ProgramData\Microsoft\SmsRouter\MessageStore\SmsInterceptStore.jfm
data
dropped
C:\ProgramData\Microsoft\SmsRouter\MessageStore\edb.chk
data
dropped
C:\ProgramData\Microsoft\SmsRouter\MessageStore\edb.log
data
dropped
C:\ProgramData\Microsoft\SmsRouter\MessageStore\edb00003.log
data
dropped
C:\ProgramData\Microsoft\SmsRouter\MessageStore\edb00004.log
data
dropped
C:\ProgramData\Microsoft\SmsRouter\MessageStore\edbres00001.jrs
data
dropped
C:\ProgramData\Microsoft\SmsRouter\MessageStore\edbres00002.jrs
data
dropped
C:\ProgramData\Microsoft\SmsRouter\MessageStore\edbtmp.log
data
dropped
C:\ProgramData\Microsoft\User Account Pictures\guest.bmp
data
dropped
C:\ProgramData\Microsoft\User Account Pictures\guest.png
data
dropped
C:\ProgramData\Microsoft\User Account Pictures\user-192.png
data
dropped
C:\ProgramData\Microsoft\User Account Pictures\user-32.png
data
dropped
C:\ProgramData\Microsoft\User Account Pictures\user-40.png
data
dropped
C:\ProgramData\Microsoft\User Account Pictures\user-48.png
data
dropped
C:\ProgramData\Microsoft\User Account Pictures\user.bmp
data
dropped
C:\ProgramData\Microsoft\User Account Pictures\user.png
data
dropped
C:\ProgramData\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204\Policy.vpol
data
dropped
C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpasdlta.vdm
data
dropped
C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpavdlta.vdm
data
dropped
C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.lkg
data
dropped
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\Detections.log
ISO-8859 text, with no line terminators
dropped
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\History.Log
data
dropped
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\Unknown.Log
data
dropped
C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db
data
dropped
C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db-wal
data
dropped
C:\ProgramData\Microsoft\Windows\AppxProvisioning.xml
data
dropped
C:\ProgramData\Microsoft\Windows\Caches\cversions.2.db
data
dropped
C:\ProgramData\Microsoft\Windows\DeviceMetadataCache\dmrc.idx
data
dropped
C:\ProgramData\Microsoft\Windows\OneSettings\ASAP_CloudPolicy.json
data
dropped
C:\ProgramData\Microsoft\Windows\OneSettings\CTAC.json
data
dropped
C:\ProgramData\Microsoft\Windows\OneSettings\CortanaUWP.json
data
dropped
C:\ProgramData\Microsoft\Windows\OneSettings\DirectXDbVersion.json
data
dropped
C:\ProgramData\Microsoft\Windows\OneSettings\FeatureConfig.bak.json
data
dropped
C:\ProgramData\Microsoft\Windows\OneSettings\FeatureConfig.json
data
dropped
C:\ProgramData\Microsoft\Windows\OneSettings\StorageGroveler.json
data
dropped
C:\ProgramData\Microsoft\Windows\OneSettings\TroubleshootingSvc.json
data
dropped
C:\ProgramData\Microsoft\Windows\OneSettings\UsoSettings.json
data
dropped
C:\ProgramData\Microsoft\Windows\OneSettings\config.json
data
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
data
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\desktop.ini
data
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\dfrgui.lnk
data
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
data
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\AutoIt Help File.lnk
data
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Check For Updates.lnk
data
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Examples.lnk
data
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Run Script (x64).lnk
data
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Run Script (x86).lnk
data
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\SciTE Script Editor.lnk
data
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk
data
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
data
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
data
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
data
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
data
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote.lnk
data
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
data
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
data
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\desktop.ini
data
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\jbxinit.au3
data
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Task Manager.lnk
data
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\desktop.ini
data
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tmf18E.tmp\Speech Recognition.lnk
data
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tmf18E.tmp\desktop.ini
data
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tmf382.tmp\About Java.lnk
data
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tmf382.tmp\Check For Updates.lnk
data
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tmf382.tmp\Configure Java.lnk
data
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tmf382.tmp\Get Help.url
data
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tmf382.tmp\Visit Java.com.url
data
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TmfB3.tmp\Desktop.ini
data
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TmfFEEE.tmp\Math Input Panel.lnk
data
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TmfFEEE.tmp\Notepad.lnk
data
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TmfFEEE.tmp\Paint.lnk
data
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TmfFEEE.tmp\Quick Assist.lnk
data
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TmfFEEE.tmp\Snipping Tool.lnk
data
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TmfFEEE.tmp\Steps Recorder.lnk
data
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TmfFEEE.tmp\Wordpad.lnk
data
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TmfFEEE.tmp\desktop.ini
data
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\desktop.ini
data
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk
data
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini
COM executable for DOS
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini
data
dropped
C:\ProgramData\Mozilla\profile_count_308046B0AF4A39CB.json
data
dropped
C:\ProgramData\Mozilla\updates\308046B0AF4A39CB\active-update.xml
DOS executable (COM, 0x8C-variant)
dropped
C:\ProgramData\Mozilla\updates\308046B0AF4A39CB\update-config.json
data
dropped
C:\ProgramData\Mozilla\updates\308046B0AF4A39CB\updates\0\update.status
PGP\011Secret Sub-key -
dropped
C:\ProgramData\Oracle\Java\installcache\baseimagefam8
empty
modified
C:\ProgramData\log.txt
data
dropped
C:\Users\Public\Desktop\Acrobat Reader DC.lnk
data
dropped
C:\Users\Public\Desktop\Firefox.lnk
data
dropped
C:\Users\Public\Desktop\Google Chrome.lnk
data
dropped
C:\Users\Public\Desktop\Microsoft Edge.lnk
data
dropped
C:\Users\Public\Desktop\desktop.ini
data
dropped
C:\Users\Public\Documents\desktop.ini
data
dropped
C:\Users\Public\Music\desktop.ini
data
dropped
C:\Users\Public\Pictures\desktop.ini
data
dropped
C:\Users\Public\Videos\desktop.ini
data
dropped
C:\bootTel.dat
data
dropped
There are 192 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Windows\SysWOW64\cmd.exe
cmd.exe /C rundll32.exe "C:\Users\user\Desktop\dqwdq.dll",#1
malicious
C:\Windows\SysWOW64\rundll32.exe
rundll32.exe C:\Users\user\Desktop\dqwdq.dll,_Start@4
malicious
C:\Windows\SysWOW64\rundll32.exe
rundll32.exe "C:\Users\user\Desktop\dqwdq.dll",#1
malicious
C:\Windows\SysWOW64\rundll32.exe
rundll32.exe "C:\Users\user\Desktop\dqwdq.dll",_Start@4
malicious
C:\Windows\System32\loaddll32.exe
loaddll32.exe "C:\Users\user\Desktop\dqwdq.dll"

Memdumps

Base Address
Regiontype
Protect
Malicious
Download
FAE000
stack
page read and write
10AF000
stack
page read and write
8D3000
heap
page read and write
70FC6000
unkown
page readonly
35E0000
heap
page read and write
B80000
heap
page read and write
773000
stack
page read and write
BA0000
heap
page read and write
70FD5000
unkown
page read and write
EA0000
trusted library allocation
page read and write
7C0000
unclassified section
page readonly
D30000
heap
page read and write
70FD5000
unkown
page read and write
F6F000
stack
page read and write
30F0000
heap
page read and write
D53000
heap
page read and write
870000
unclassified section
page readonly
4D30000
heap
page read and write
E6E000
stack
page read and write
CD0000
unclassified section
page readonly
6E0000
heap
page read and write
CE0000
heap
page read and write
470E000
stack
page read and write
F00000
heap
page read and write
3D0000
unclassified section
page readonly
720000
heap
page read and write
46DE000
stack
page read and write
11EF000
stack
page read and write
D3E000
heap
page read and write
70FD7000
unkown
page readonly
CE0000
heap
page read and write
70FD7000
unkown
page readonly
AD0000
trusted library allocation
page read and write
CF0000
unclassified section
page readonly
FD0000
heap
page read and write
384000
stack
page read and write
7D0000
heap
page read and write
70FD5000
unkown
page read and write
D4B000
stack
page read and write
9EC000
stack
page read and write
6D0000
unclassified section
page readonly
10EE000
stack
page read and write
7D0000
heap
page read and write
70FA1000
unkown
page execute read
E8E000
stack
page read and write
D50000
heap
page read and write
3134000
heap
page read and write
70FA1000
unkown
page execute read
30EE000
stack
page read and write
880000
trusted library allocation
page read and write
74B000
stack
page read and write
30FA000
heap
page read and write
70FA0000
unkown
page readonly
35B000
stack
page read and write
BE3000
heap
page read and write
70FA0000
unkown
page readonly
7C0000
unclassified section
page readonly
70FC6000
unkown
page readonly
70FC6000
unkown
page readonly
890000
heap
page read and write
2E0000
unclassified section
page readonly
7B0000
heap
page read and write
83C000
stack
page read and write
CD0000
unclassified section
page readonly
6D0000
trusted library allocation
page read and write
BAA000
heap
page read and write
70FA0000
unkown
page readonly
70FD7000
unkown
page readonly
29E0000
heap
page read and write
70FA1000
unkown
page execute read
35BE000
stack
page read and write
DC0000
unclassified section
page readonly
2F0000
heap
page read and write
D47000
heap
page read and write
89A000
heap
page read and write
D3B000
heap
page read and write
D74000
stack
page read and write
EBE000
stack
page read and write
There are 68 hidden memdumps, click here to show them.