Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
$RMH4FA8.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
initial sample
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Network Start\1\extract_1727760940_7564_7596_541766985\ISL_Light_Client_4_4_2332_44
49919761.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\ISLClient.out
|
ASCII text, with very long lines (3008), with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\ISLLight.dll
|
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\conf\ISLConfiguration.ini
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\conf\cmdline.txt
|
ASCII text, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\conf_static\ISLStaticConfiguration.ini
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\conf_static\icon.ico
|
MS Windows icon resource - 10 icons, 16x16, 16 colors, 4 bits/pixel, 16x16, 8 bits/pixel
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\conf_static\logo.bmp
|
PC bitmap, Windows 3.x format, 311 x 80 x 24, cbSize 74694, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\datachannel.dll
|
PE32 executable (DLL) (console) Intel 80386, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\isllight.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\mailopen.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\shellsendto.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\VNC-blue-ikone.bmp
|
PC bitmap, Windows 3.x format, 330 x 30 x 32, image size 39602, resolution 2834 x 2834 px/m, cbSize 39656, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\background.bmp
|
PC bitmap, Windows 3.x format, 32 x 32 x 24, image size 3072, resolution 2834 x 2834 px/m, cbSize 3126, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\btn-ctrl-dsk-small.bmp
|
PC bitmap, Windows 3.x format, 120 x 29 x 24, image size 10440, resolution 3780 x 3780 px/m, cbSize 10494, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\btn-dsk-vnc-ex.bmp
|
PC bitmap, Windows 3.x format, 190 x 34 x 24, image size 19448, resolution 2834 x 2834 px/m, cbSize 19502, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\btn-dsk-vnc.bmp
|
PC bitmap, Windows 3.x format, 500 x 34 x 24, image size 51000, resolution 2834 x 2834 px/m, cbSize 51054, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\btn-vnc-top.bmp
|
PC bitmap, Windows 3.x format, 96 x 24 x 24, image size 6914, resolution 2834 x 2834 px/m, cbSize 6968, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\btns-ft.bmp
|
PC bitmap, Windows 3.x format, 550 x 32 x 24, image size 52866, resolution 2834 x 2834 px/m, cbSize 52920, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\buttons-chooser.bmp
|
PC bitmap, Windows 3.x format, 750 x 38 x 24, image size 85576, resolution 3780 x 3780 px/m, cbSize 85630, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\buttons-connect.bmp
|
PC bitmap, Windows 3.x format, 750 x 38 x 24, image size 85576, resolution 2834 x 2834 px/m, cbSize 85630, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\buttons-start-frame.bmp
|
PC bitmap, Windows 3.x format, 144 x 36 x 24, image size 15552, resolution 2834 x 2834 px/m, cbSize 15606, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\buttons-start.bmp
|
PC bitmap, Windows 3.x format, 144 x 36 x 32, image size 20736, resolution 2834 x 2834 px/m, cbSize 20790, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\buttons.bmp
|
PC bitmap, Windows 3.x format, 550 x 32 x 24, image size 52866, resolution 2834 x 2834 px/m, cbSize 52920, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\client-bk-black.bmp
|
PC bitmap, Windows 3.x format, 55 x 58 x 24, image size 9744, cbSize 9798, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\client-bk-gray-top.bmp
|
PC bitmap, Windows 3.x format, 63 x 45 x 24, image size 8640, cbSize 8694, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\client-bk-gray.bmp
|
PC bitmap, Windows 3.x format, 47 x 30 x 24, image size 4320, resolution 2834 x 2834 px/m, cbSize 4374, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\client-edit.bmp
|
PC bitmap, Windows 3.x format, 180 x 24 x 24, image size 12960, resolution 2834 x 2834 px/m, cbSize 13014, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\close_info.bmp
|
PC bitmap, Windows 3.x format, 16 x 16 x 32, image size 1026, resolution 2834 x 2834 px/m, cbSize 1080, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\custom_texts.ini
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\dialog_205.xml
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\dlgframe.bmp
|
PC bitmap, Windows 3.x format, 85 x 80 x 24, image size 20480, resolution 2834 x 2834 px/m, cbSize 20534, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\ic-backspace.bmp
|
PC bitmap, Windows 3.x format, 24 x 24 x 32, image size 2304, resolution 3780 x 3780 px/m, cbSize 2358, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\ic-enter.bmp
|
PC bitmap, Windows 3.x format, 24 x 24 x 32, image size 2304, resolution 3780 x 3780 px/m, cbSize 2358, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\ik-enter.bmp
|
PC bitmap, Windows 3.x format, 24 x 24 x 32, image size 2304, resolution 2835 x 2835 px/m, cbSize 2358, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\ik-exit.bmp
|
PC bitmap, Windows 3.x format, 32 x 32 x 32, image size 4096, resolution 2835 x 2835 px/m, cbSize 4150, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\ik-play.bmp
|
PC bitmap, Windows 3.x format, 84 x 28 x 32, image size 9410, resolution 2834 x 2834 px/m, cbSize 9464, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\ik-settings.bmp
|
PC bitmap, Windows 3.x format, 32 x 32 x 32, image size 4096, resolution 2835 x 2835 px/m, cbSize 4150, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\incurves.bmp
|
PC bitmap, Windows 3.x format, 81 x 72 x 24, image size 17570, resolution 2834 x 2834 px/m, cbSize 17624, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\mail.bmp
|
PC bitmap, Windows 3.x format, 32 x 32 x 32, image size 4096, resolution 2835 x 2835 px/m, cbSize 4150, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\outcurves.bmp
|
PC bitmap, Windows 3.x format, 95 x 83 x 24, image size 23904, resolution 2834 x 2834 px/m, cbSize 23958, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\pin.bmp
|
PC bitmap, Windows 3.x format, 40 x 20 x 32, image size 3200, resolution 2835 x 2835 px/m, cbSize 3254, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\skin_data.txt
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\slider_btns.bmp
|
PC bitmap, Windows 3.x format, 90 x 18 x 24, image size 4898, resolution 2834 x 2834 px/m, cbSize 4952, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\slider_inner.bmp
|
PC bitmap, Windows 3.x format, 36 x 26 x 24, image size 2810, resolution 2834 x 2834 px/m, cbSize 2864, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\thumb-audio.bmp
|
PC bitmap, Windows 3.x format, 13 x 12 x 24, image size 482, resolution 3779 x 3779 px/m, cbSize 536, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\thumb-desktop.bmp
|
PC bitmap, Windows 3.x format, 12 x 11 x 24, image size 398, resolution 2834 x 2834 px/m, cbSize 452, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\thumb-file.bmp
|
PC bitmap, Windows 3.x format, 16 x 14 x 24, image size 674, resolution 2834 x 2834 px/m, cbSize 728, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\thumb-video.bmp
|
PC bitmap, Windows 3.x format, 12 x 10 x 24, image size 362, resolution 3779 x 3779 px/m, cbSize 416, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\titlebar-vnc-top.bmp
|
PC bitmap, Windows 3.x format, 640 x 29 x 24, image size 55680, resolution 2834 x 2834 px/m, cbSize 55734, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\titlebar-vnc.bmp
|
PC bitmap, Windows 3.x format, 320 x 28 x 24, image size 26880, resolution 2834 x 2834 px/m, cbSize 26934, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\v4_arrow-up.bmp
|
PC bitmap, Windows 3.x format, 20 x 20 x 32, image size 1600, resolution 2835 x 2835 px/m, cbSize 1654, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\v4_arrow.bmp
|
PC bitmap, Windows 3.x format, 20 x 20 x 32, image size 1600, resolution 2835 x 2835 px/m, cbSize 1654, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\v4_files.bmp
|
PC bitmap, Windows 3.x format, 32 x 32 x 32, image size 4096, resolution 2835 x 2835 px/m, cbSize 4150, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\v4_icon_chat_audio.bmp
|
PC bitmap, Windows 3.x format, 32 x 32 x 32, image size 4096, resolution 2835 x 2835 px/m, cbSize 4150, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\v4_icon_chat_video.bmp
|
PC bitmap, Windows 3.x format, 32 x 32 x 32, image size 4096, resolution 2835 x 2835 px/m, cbSize 4150, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\v4_icon_start_sharing.bmp
|
PC bitmap, Windows 3.x format, 18 x 18 x 32, image size 1296, resolution 2835 x 2835 px/m, cbSize 1350, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\v4_icon_stop_sharing.bmp
|
PC bitmap, Windows 3.x format, 18 x 18 x 32, image size 1296, resolution 2835 x 2835 px/m, cbSize 1350, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\v4_ik-VNC-top.bmp
|
PC bitmap, Windows 3.x format, 30 x 14 x 32, image size 1680, resolution 2835 x 2835 px/m, cbSize 1734, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\white.bmp
|
PC bitmap, Windows 3.x format, 17 x 17 x 24, image size 884, cbSize 938, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\source_pkg.dat
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\trace.out
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\translations\LangAll.tr2
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Network Start\1\ISLNetworkStart.dll
|
PE32 executable (DLL) (console) Intel 80386, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Network Start\1\conf\address
|
ASCII text, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Network Start\1\conf\port
|
ASCII text, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Network Start\1\conf\query
|
ASCII text, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Network Start\1\conf\use_http
|
very short file (no magic)
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Network Start\1\conf\use_https
|
very short file (no magic)
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Network Start\1\conf_static\caption
|
ASCII text, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Network Start\1\connection_keys\connection_keys
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Network Start\1\isl_network_start.log
|
ASCII text, with very long lines (3008), with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Network Start\1\translations\translations
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Network Start\cache\file_cache_v3_043065b2e452ce2cf70257bf9425894cba1c5de87ed10248a2b672c5c399c723
(copy)
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Network Start\cache\file_cache_v3_3ed70ed34cf00c10cc154e384abd36a689ae85d7c5b9bae1ab71608ebbb9fb8c
(copy)
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Network Start\cache\file_cache_v3_419ef57f0b28960c833825d468211467de332c0e3dfadec7b6e72b82ed3c04b7
(copy)
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Network Start\cache\file_cache_v3_45390ea339a822941ab593a53883383e16a0d5f46ac05d5b9c7b49218cb8014e
(copy)
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Network Start\cache\file_cache_v3_68e7d0a5d2fbad6a95db87b21edc997063a5b30d2660721392f4498ac45d20b5
(copy)
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Network Start\cache\file_cache_v3_b5ca13e92e299006b18361a251e52720a13c30ba0c08a23fc19e6b6ba3b0c01f
(copy)
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Network Start\cache\file_cache_v3_ccc40b01224b537ac32e8a9ac7abe0c619020bafddf89f6f60f98345b23e5563
(copy)
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Network Start\cache\file_cache_v3_e05fc368b8b5e4bdfc11af1c131268794ca22b3ce2da363e9d7d1418b807ce98
(copy)
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\ISL Online Cache\ISL Network Start\cache\tmp_7564_7596
|
data
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\SendTo\ISL Light Client.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has command line arguments, Icon number=0, Archive,
ctime=Tue Oct 1 02:38:49 2024, mtime=Tue Oct 1 02:38:49 2024, atime=Tue Oct 1 02:38:49 2024, length=14648, window=hide
|
dropped
|
There are 74 hidden files, click here to show them.
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\AppData\Local\ISL Online Cache\ISL Network Start\1\extract_1727760940_7564_7596_541766985\ISL_Light_Client_4_4_2332_44
49919761.exe
|
ISL_Light_Client_4_4_2332_44_49919761.exe
|
||
C:\Users\user\Desktop\$RMH4FA8.exe
|
"C:\Users\user\Desktop\$RMH4FA8.exe"
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://www.apache.org/licenses/LICENSE-2.0).P
|
unknown
|
||
http://www.islonline.com
|
unknown
|
||
http://www.islonline.com/help?%5%
|
unknown
|
||
http://www.islonline.com/r301?
|
unknown
|
||
http://www.apache.org/licenses/LICENSE-2.0).
|
unknown
|
||
http://www.islonline.com/r301?&topic=SETTINGS_PLUGINS_AVAILABLESETTINGS_PLUGINS_LOADEDplugin
|
unknown
|
||
http://www.apache.org/licenses/LICENSE-2.0).6L
|
unknown
|
||
http://www.apache.org/licenses/LICENSE-2.0).invalid
|
unknown
|
||
http://www.islonline.com/help?p=isl-light&v=3-2&f=html&l=%5%
|
unknown
|
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
isllight-myipaicohlcbrbhl.islonline.net
|
139.144.234.209
|
||
networkstart-ivfqcxy.islonline.net
|
195.201.59.111
|
||
networkstart-myipaicohlcbpwnb.islonline.net
|
170.187.160.42
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
170.187.160.42
|
networkstart-myipaicohlcbpwnb.islonline.net
|
United States
|
||
139.144.234.209
|
isllight-myipaicohlcbrbhl.islonline.net
|
United States
|
||
195.201.59.111
|
networkstart-ivfqcxy.islonline.net
|
Germany
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
HKEY_CURRENT_USER\SOFTWARE\ISL Online\Grid\ISL Online Network
|
grid_id
|
||
HKEY_CURRENT_USER\SOFTWARE\ISL Online\Grid\ISL Online Network
|
cp_protocol
|
||
HKEY_CURRENT_USER\SOFTWARE\ISL Online\Grid\ISL Online Network
|
key_cs
|
||
HKEY_CURRENT_USER\SOFTWARE\ISL Online\Grid\ISL Online Network
|
key_cs_latest
|
||
HKEY_CURRENT_USER\SOFTWARE\ISL Online\AutoTransport\Last public IP
|
.islonline.net
|
||
HKEY_CURRENT_USER\SOFTWARE\ISL Online\Grid\ISL Online Network
|
key_hash
|
||
HKEY_CURRENT_USER\SOFTWARE\ISL Online\Grid\ISL Online Network
|
key_ss
|
||
HKEY_CURRENT_USER\SOFTWARE\ISL Online\AutoTransport\Boost transport type
|
v1
|
||
HKEY_CURRENT_USER\SOFTWARE\ISL Online\AutoTransport\HTTP proxy PAC
|
v1
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
3A5A000
|
heap
|
page read and write
|
||
6500000
|
heap
|
page read and write
|
||
30D3000
|
heap
|
page read and write
|
||
300D000
|
heap
|
page read and write
|
||
2E39000
|
heap
|
page read and write
|
||
35F0000
|
unkown
|
page readonly
|
||
2EAF000
|
heap
|
page read and write
|
||
6D05A000
|
unkown
|
page readonly
|
||
29B6000
|
heap
|
page read and write
|
||
2884000
|
heap
|
page read and write
|
||
51C8000
|
heap
|
page read and write
|
||
2DDF000
|
heap
|
page read and write
|
||
394F000
|
heap
|
page read and write
|
||
32D9000
|
heap
|
page read and write
|
||
3606000
|
unkown
|
page readonly
|
||
395A000
|
heap
|
page read and write
|
||
BAF000
|
heap
|
page read and write
|
||
B74000
|
heap
|
page read and write
|
||
6A3E000
|
stack
|
page read and write
|
||
306D000
|
heap
|
page read and write
|
||
4F88000
|
heap
|
page read and write
|
||
2E3F000
|
heap
|
page read and write
|
||
2EFE000
|
stack
|
page read and write
|
||
2812000
|
heap
|
page read and write
|
||
2E3B000
|
heap
|
page read and write
|
||
2D00000
|
unkown
|
page readonly
|
||
5238000
|
heap
|
page read and write
|
||
36C0000
|
heap
|
page read and write
|
||
3600000
|
unkown
|
page readonly
|
||
6D002000
|
unkown
|
page readonly
|
||
3085000
|
heap
|
page read and write
|
||
2F7F000
|
heap
|
page read and write
|
||
5038000
|
heap
|
page read and write
|
||
2F97000
|
heap
|
page read and write
|
||
6B3F000
|
stack
|
page read and write
|
||
960000
|
heap
|
page read and write
|
||
312D000
|
heap
|
page read and write
|
||
2F9B000
|
heap
|
page read and write
|
||
5018000
|
heap
|
page read and write
|
||
3E08000
|
heap
|
page read and write
|
||
30DD000
|
heap
|
page read and write
|
||
3600000
|
unkown
|
page readonly
|
||
300F000
|
heap
|
page read and write
|
||
39E1000
|
heap
|
page read and write
|
||
5068000
|
heap
|
page read and write
|
||
3DAC000
|
heap
|
page read and write
|
||
470000
|
unkown
|
page readonly
|
||
27F6000
|
heap
|
page read and write
|
||
8FA000
|
stack
|
page read and write
|
||
5188000
|
heap
|
page read and write
|
||
30AD000
|
heap
|
page read and write
|
||
311D000
|
heap
|
page read and write
|
||
3600000
|
unkown
|
page readonly
|
||
5218000
|
heap
|
page read and write
|
||
3600000
|
unkown
|
page readonly
|
||
8FC000
|
stack
|
page read and write
|
||
5098000
|
heap
|
page read and write
|
||
3600000
|
unkown
|
page readonly
|
||
E7E000
|
stack
|
page read and write
|
||
3DA7000
|
heap
|
page read and write
|
||
E4E000
|
heap
|
page read and write
|
||
9F5000
|
heap
|
page read and write
|
||
3011000
|
heap
|
page read and write
|
||
34EE000
|
stack
|
page read and write
|
||
27B0000
|
heap
|
page read and write
|
||
302D000
|
heap
|
page read and write
|
||
63ED000
|
stack
|
page read and write
|
||
C40000
|
unkown
|
page readonly
|
||
4A82000
|
heap
|
page read and write
|
||
4F7E000
|
stack
|
page read and write
|
||
3091000
|
heap
|
page read and write
|
||
36F0000
|
unkown
|
page readonly
|
||
5118000
|
heap
|
page read and write
|
||
ADC000
|
stack
|
page read and write
|
||
2DD5000
|
heap
|
page read and write
|
||
39BD000
|
heap
|
page read and write
|
||
970000
|
heap
|
page read and write
|
||
BE6000
|
heap
|
page read and write
|
||
3600000
|
unkown
|
page readonly
|
||
67BE000
|
stack
|
page read and write
|
||
3600000
|
unkown
|
page readonly
|
||
D7E000
|
stack
|
page read and write
|
||
3600000
|
unkown
|
page readonly
|
||
2CBE000
|
stack
|
page read and write
|
||
9BE000
|
stack
|
page read and write
|
||
390E000
|
heap
|
page read and write
|
||
2DFA000
|
heap
|
page read and write
|
||
3A7D000
|
heap
|
page read and write
|
||
5198000
|
heap
|
page read and write
|
||
2B4A000
|
heap
|
page read and write
|
||
3E08000
|
heap
|
page read and write
|
||
36E0000
|
heap
|
page read and write
|
||
470000
|
unkown
|
page readonly
|
||
2EAF000
|
heap
|
page read and write
|
||
3DA2000
|
heap
|
page read and write
|
||
3025000
|
heap
|
page read and write
|
||
38FA000
|
heap
|
page read and write
|
||
50B8000
|
heap
|
page read and write
|
||
3A8D000
|
heap
|
page read and write
|
||
3600000
|
unkown
|
page readonly
|
||
3949000
|
heap
|
page read and write
|
||
C41000
|
unkown
|
page execute read
|
||
3A1B000
|
heap
|
page read and write
|
||
2F28000
|
heap
|
page read and write
|
||
2890000
|
heap
|
page read and write
|
||
3600000
|
unkown
|
page readonly
|
||
6CF30000
|
unkown
|
page readonly
|
||
51B8000
|
heap
|
page read and write
|
||
30FB000
|
heap
|
page read and write
|
||
2E68000
|
heap
|
page read and write
|
||
30F1000
|
heap
|
page read and write
|
||
3A07000
|
heap
|
page read and write
|
||
3600000
|
unkown
|
page readonly
|
||
E4A000
|
heap
|
page read and write
|
||
38EA000
|
heap
|
page read and write
|
||
3047000
|
heap
|
page read and write
|
||
E40000
|
heap
|
page read and write
|
||
390E000
|
heap
|
page read and write
|
||
304D000
|
heap
|
page read and write
|
||
6D036000
|
unkown
|
page write copy
|
||
50E8000
|
heap
|
page read and write
|
||
E70000
|
heap
|
page read and write
|
||
50C8000
|
heap
|
page read and write
|
||
3051000
|
heap
|
page read and write
|
||
3601000
|
unkown
|
page readonly
|
||
5228000
|
heap
|
page read and write
|
||
3696000
|
heap
|
page read and write
|
||
5158000
|
heap
|
page read and write
|
||
3600000
|
unkown
|
page readonly
|
||
B70000
|
heap
|
page read and write
|
||
301B000
|
heap
|
page read and write
|
||
3320000
|
heap
|
page read and write
|
||
5108000
|
heap
|
page read and write
|
||
4FB8000
|
heap
|
page read and write
|
||
30C7000
|
heap
|
page read and write
|
||
3270000
|
heap
|
page read and write
|
||
33AE000
|
stack
|
page read and write
|
||
3600000
|
unkown
|
page readonly
|
||
333E000
|
heap
|
page read and write
|
||
8CB000
|
stack
|
page read and write
|
||
2C7E000
|
stack
|
page read and write
|
||
43D0000
|
heap
|
page read and write
|
||
5208000
|
heap
|
page read and write
|
||
3600000
|
unkown
|
page readonly
|
||
6D065000
|
unkown
|
page read and write
|
||
2B4D000
|
heap
|
page read and write
|
||
30ED000
|
heap
|
page read and write
|
||
4E7D000
|
stack
|
page read and write
|
||
B80000
|
heap
|
page read and write
|
||
2E62000
|
heap
|
page read and write
|
||
372E000
|
stack
|
page read and write
|
||
2815000
|
heap
|
page read and write
|
||
8EC000
|
stack
|
page read and write
|
||
3870000
|
heap
|
page read and write
|
||
2EF7000
|
heap
|
page read and write
|
||
BF7000
|
heap
|
page read and write
|
||
30CB000
|
heap
|
page read and write
|
||
3DFF000
|
heap
|
page read and write
|
||
4F98000
|
heap
|
page read and write
|
||
C3D000
|
stack
|
page read and write
|
||
AF2000
|
stack
|
page read and write
|
||
3600000
|
unkown
|
page readonly
|
||
AFC000
|
stack
|
page read and write
|
||
333E000
|
heap
|
page read and write
|
||
30E3000
|
heap
|
page read and write
|
||
30F3000
|
heap
|
page read and write
|
||
68FE000
|
stack
|
page read and write
|
||
328F000
|
heap
|
page read and write
|
||
2EAE000
|
heap
|
page read and write
|
||
30EB000
|
heap
|
page read and write
|
||
2E62000
|
heap
|
page read and write
|
||
5078000
|
heap
|
page read and write
|
||
6B5F000
|
heap
|
page read and write
|
||
44EA000
|
heap
|
page read and write
|
||
39A7000
|
heap
|
page read and write
|
||
9F0000
|
heap
|
page read and write
|
||
36E4000
|
heap
|
page read and write
|
||
3005000
|
heap
|
page read and write
|
||
4F7B000
|
stack
|
page read and write
|
||
3069000
|
heap
|
page read and write
|
||
2E55000
|
heap
|
page read and write
|
||
30D9000
|
heap
|
page read and write
|
||
3DA5000
|
heap
|
page read and write
|
||
AE7000
|
stack
|
page read and write
|
||
5058000
|
heap
|
page read and write
|
||
30F7000
|
heap
|
page read and write
|
||
6D07E000
|
unkown
|
page readonly
|
||
30A3000
|
heap
|
page read and write
|
||
3600000
|
unkown
|
page readonly
|
||
304B000
|
heap
|
page read and write
|
||
30E7000
|
heap
|
page read and write
|
||
30D1000
|
heap
|
page read and write
|
||
4FA8000
|
heap
|
page read and write
|
||
6C7F000
|
stack
|
page read and write
|
||
64EF000
|
stack
|
page read and write
|
||
3DA1000
|
heap
|
page read and write
|
||
38A4000
|
heap
|
page read and write
|
||
38EA000
|
heap
|
page read and write
|
||
2F67000
|
heap
|
page read and write
|
||
4FC8000
|
heap
|
page read and write
|
||
2896000
|
heap
|
page read and write
|
||
3600000
|
unkown
|
page readonly
|
||
3A6A000
|
heap
|
page read and write
|
||
5288000
|
heap
|
page read and write
|
||
2F74000
|
heap
|
page read and write
|
||
39F5000
|
heap
|
page read and write
|
||
30EF000
|
heap
|
page read and write
|
||
3A1C000
|
heap
|
page read and write
|
||
2877000
|
heap
|
page read and write
|
||
2FA3000
|
heap
|
page read and write
|
||
3942000
|
heap
|
page read and write
|
||
32E0000
|
heap
|
page read and write
|
||
390B000
|
heap
|
page read and write
|
||
312F000
|
heap
|
page read and write
|
||
3600000
|
unkown
|
page readonly
|
||
3031000
|
heap
|
page read and write
|
||
50A8000
|
heap
|
page read and write
|
||
D9E000
|
stack
|
page read and write
|
||
311B000
|
heap
|
page read and write
|
||
3949000
|
heap
|
page read and write
|
||
C4D000
|
unkown
|
page readonly
|
||
3940000
|
heap
|
page read and write
|
||
2EF7000
|
heap
|
page read and write
|
||
2DBD000
|
stack
|
page read and write
|
||
59F0000
|
trusted library allocation
|
page read and write
|
||
308B000
|
heap
|
page read and write
|
||
5168000
|
heap
|
page read and write
|
||
5128000
|
heap
|
page read and write
|
||
3315000
|
heap
|
page read and write
|
||
4D3E000
|
stack
|
page read and write
|
||
2E52000
|
heap
|
page read and write
|
||
5138000
|
heap
|
page read and write
|
||
3620000
|
unkown
|
page readonly
|
||
4FD8000
|
heap
|
page read and write
|
||
471000
|
unkown
|
page execute read
|
||
360D000
|
unkown
|
page readonly
|
||
B0D000
|
stack
|
page read and write
|
||
6D061000
|
unkown
|
page read and write
|
||
6CD50000
|
unkown
|
page readonly
|
||
3600000
|
unkown
|
page readonly
|
||
390B000
|
heap
|
page read and write
|
||
30F5000
|
heap
|
page read and write
|
||
5088000
|
heap
|
page read and write
|
||
3302000
|
heap
|
page read and write
|
||
3600000
|
unkown
|
page readonly
|
||
27F0000
|
heap
|
page read and write
|
||
6D03D000
|
unkown
|
page read and write
|
||
5F8000
|
stack
|
page read and write
|
||
2E4F000
|
heap
|
page read and write
|
||
3A66000
|
heap
|
page read and write
|
||
27E4000
|
heap
|
page read and write
|
||
38F2000
|
heap
|
page read and write
|
||
2E68000
|
heap
|
page read and write
|
||
2854000
|
heap
|
page read and write
|
||
3600000
|
unkown
|
page readonly
|
||
2E47000
|
heap
|
page read and write
|
||
32CA000
|
heap
|
page read and write
|
||
3600000
|
unkown
|
page readonly
|
||
C4D000
|
unkown
|
page readonly
|
||
30CF000
|
heap
|
page read and write
|
||
30A5000
|
heap
|
page read and write
|
||
799000
|
stack
|
page read and write
|
||
6F0E000
|
heap
|
page read and write
|
||
3E45000
|
heap
|
page read and write
|
||
3013000
|
heap
|
page read and write
|
||
2E65000
|
heap
|
page read and write
|
||
B00000
|
heap
|
page read and write
|
||
5048000
|
heap
|
page read and write
|
||
38FA000
|
heap
|
page read and write
|
||
3600000
|
unkown
|
page readonly
|
||
3600000
|
unkown
|
page readonly
|
||
2DF0000
|
heap
|
page read and write
|
||
3600000
|
unkown
|
page readonly
|
||
6CF31000
|
unkown
|
page execute read
|
||
4E3F000
|
stack
|
page read and write
|
||
677F000
|
stack
|
page read and write
|
||
3295000
|
heap
|
page read and write
|
||
3600000
|
unkown
|
page readonly
|
||
32BE000
|
heap
|
page read and write
|
||
B8A000
|
heap
|
page read and write
|
||
7119000
|
heap
|
page read and write
|
||
3039000
|
heap
|
page read and write
|
||
50F8000
|
heap
|
page read and write
|
||
3600000
|
unkown
|
page readonly
|
||
103E000
|
stack
|
page read and write
|
||
2888000
|
heap
|
page read and write
|
||
3073000
|
heap
|
page read and write
|
||
667E000
|
stack
|
page read and write
|
||
6D032000
|
unkown
|
page read and write
|
||
3023000
|
heap
|
page read and write
|
||
64CA000
|
stack
|
page read and write
|
||
BE6000
|
heap
|
page read and write
|
||
6D07C000
|
unkown
|
page readonly
|
||
32D4000
|
heap
|
page read and write
|
||
32B4000
|
heap
|
page read and write
|
||
6B7E000
|
stack
|
page read and write
|
||
2B41000
|
heap
|
page read and write
|
||
30E5000
|
heap
|
page read and write
|
||
5028000
|
heap
|
page read and write
|
||
2EF4000
|
heap
|
page read and write
|
||
30F9000
|
heap
|
page read and write
|
||
51E8000
|
heap
|
page read and write
|
||
52BD000
|
heap
|
page read and write
|
||
69FF000
|
stack
|
page read and write
|
||
2EAF000
|
heap
|
page read and write
|
||
BBB000
|
heap
|
page read and write
|
||
398C000
|
heap
|
page read and write
|
||
2F8A000
|
heap
|
page read and write
|
||
44EC000
|
heap
|
page read and write
|
||
50D8000
|
heap
|
page read and write
|
||
3601000
|
unkown
|
page readonly
|
||
6CD51000
|
unkown
|
page execute read
|
||
30D7000
|
heap
|
page read and write
|
||
BE6000
|
heap
|
page read and write
|
||
3125000
|
heap
|
page read and write
|
||
30B3000
|
heap
|
page read and write
|
||
D5F000
|
stack
|
page read and write
|
||
35ED000
|
stack
|
page read and write
|
||
30CD000
|
heap
|
page read and write
|
||
2E4F000
|
heap
|
page read and write
|
||
5278000
|
heap
|
page read and write
|
||
5008000
|
heap
|
page read and write
|
||
B20000
|
heap
|
page read and write
|
||
2F30000
|
unclassified section
|
page read and write
|
||
30A9000
|
heap
|
page read and write
|
||
30C9000
|
heap
|
page read and write
|
||
3600000
|
unkown
|
page readonly
|
||
8F2000
|
stack
|
page read and write
|
||
3DA0000
|
heap
|
page read and write
|
||
51F8000
|
heap
|
page read and write
|
||
3021000
|
heap
|
page read and write
|
||
36B0000
|
heap
|
page read and write
|
||
3101000
|
heap
|
page read and write
|
||
394A000
|
heap
|
page read and write
|
||
376D000
|
stack
|
page read and write
|
||
B8E000
|
heap
|
page read and write
|
||
C41000
|
unkown
|
page execute read
|
||
3071000
|
heap
|
page read and write
|
||
286C000
|
heap
|
page read and write
|
||
BEF000
|
heap
|
page read and write
|
||
2861000
|
heap
|
page read and write
|
||
6DC5000
|
heap
|
page read and write
|
||
6D046000
|
unkown
|
page read and write
|
||
44EE000
|
heap
|
page read and write
|
||
2FFE000
|
stack
|
page read and write
|
||
51A8000
|
heap
|
page read and write
|
||
2E47000
|
heap
|
page read and write
|
||
3029000
|
heap
|
page read and write
|
||
3600000
|
unkown
|
page readonly
|
||
30B7000
|
heap
|
page read and write
|
||
304F000
|
heap
|
page read and write
|
||
2E07000
|
heap
|
page read and write
|
||
3942000
|
heap
|
page read and write
|
||
3067000
|
heap
|
page read and write
|
||
3949000
|
heap
|
page read and write
|
||
3045000
|
heap
|
page read and write
|
||
2B7E000
|
stack
|
page read and write
|
||
3600000
|
unkown
|
page readonly
|
||
AD4000
|
stack
|
page read and write
|
||
32AC000
|
heap
|
page read and write
|
||
307F000
|
heap
|
page read and write
|
||
BAF000
|
heap
|
page read and write
|
||
3520000
|
heap
|
page read and write
|
||
3DFF000
|
heap
|
page read and write
|
||
3337000
|
heap
|
page read and write
|
||
3620000
|
unkown
|
page readonly
|
||
3600000
|
unkown
|
page readonly
|
||
3059000
|
heap
|
page read and write
|
||
390B000
|
heap
|
page read and write
|
||
7520000
|
heap
|
page read and write
|
||
316E000
|
stack
|
page read and write
|
||
4B4C000
|
heap
|
page read and write
|
||
2FA9000
|
heap
|
page read and write
|
||
B60000
|
heap
|
page read and write
|
||
29B9000
|
heap
|
page read and write
|
||
5178000
|
heap
|
page read and write
|
||
2F25000
|
heap
|
page read and write
|
||
6D063000
|
unkown
|
page write copy
|
||
2E68000
|
heap
|
page read and write
|
||
3E39000
|
heap
|
page read and write
|
||
36F0000
|
unkown
|
page readonly
|
||
3942000
|
heap
|
page read and write
|
||
300B000
|
heap
|
page read and write
|
||
5298000
|
heap
|
page read and write
|
||
47D000
|
unkown
|
page readonly
|
||
386E000
|
stack
|
page read and write
|
||
29B0000
|
heap
|
page read and write
|
||
47D000
|
unkown
|
page readonly
|
||
2940000
|
direct allocation
|
page read and write
|
||
BE0000
|
heap
|
page read and write
|
||
3602000
|
unkown
|
page readonly
|
||
4FE8000
|
heap
|
page read and write
|
||
3600000
|
unkown
|
page readonly
|
||
BB5000
|
heap
|
page read and write
|
||
BF0000
|
heap
|
page read and write
|
||
26C2000
|
heap
|
page read and write
|
||
AFA000
|
stack
|
page read and write
|
||
309F000
|
heap
|
page read and write
|
||
2DC0000
|
heap
|
page read and write
|
||
27E0000
|
heap
|
page read and write
|
||
34AF000
|
stack
|
page read and write
|
||
27ED000
|
heap
|
page read and write
|
||
4FF8000
|
heap
|
page read and write
|
||
3600000
|
unkown
|
page readonly
|
||
62EF000
|
stack
|
page read and write
|
||
3600000
|
unkown
|
page readonly
|
||
3109000
|
heap
|
page read and write
|
||
3600000
|
unkown
|
page readonly
|
||
30DF000
|
heap
|
page read and write
|
||
6C7B000
|
heap
|
page read and write
|
||
5148000
|
heap
|
page read and write
|
||
30E9000
|
heap
|
page read and write
|
||
C40000
|
unkown
|
page readonly
|
||
396B000
|
heap
|
page read and write
|
||
2EF7000
|
heap
|
page read and write
|
||
326E000
|
stack
|
page read and write
|
||
3601000
|
unkown
|
page readonly
|
||
471000
|
unkown
|
page execute read
|
||
330F000
|
heap
|
page read and write
|
||
330D000
|
heap
|
page read and write
|
||
68BF000
|
stack
|
page read and write
|
||
3093000
|
heap
|
page read and write
|
||
51D8000
|
heap
|
page read and write
|
||
3600000
|
unkown
|
page readonly
|
||
3600000
|
unkown
|
page readonly
|
There are 415 hidden memdumps, click here to show them.