IOC Report
$RMH4FA8.exe

loading gif

Files

File Path
Type
Category
Malicious
$RMH4FA8.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
C:\Users\user\AppData\Local\ISL Online Cache\ISL Network Start\1\extract_1727760940_7564_7596_541766985\ISL_Light_Client_4_4_2332_44 49919761.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\ISLClient.out
ASCII text, with very long lines (3008), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\ISLLight.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\conf\ISLConfiguration.ini
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\conf\cmdline.txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\conf_static\ISLStaticConfiguration.ini
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\conf_static\icon.ico
MS Windows icon resource - 10 icons, 16x16, 16 colors, 4 bits/pixel, 16x16, 8 bits/pixel
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\conf_static\logo.bmp
PC bitmap, Windows 3.x format, 311 x 80 x 24, cbSize 74694, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\datachannel.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\isllight.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\mailopen.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\shellsendto.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\VNC-blue-ikone.bmp
PC bitmap, Windows 3.x format, 330 x 30 x 32, image size 39602, resolution 2834 x 2834 px/m, cbSize 39656, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\background.bmp
PC bitmap, Windows 3.x format, 32 x 32 x 24, image size 3072, resolution 2834 x 2834 px/m, cbSize 3126, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\btn-ctrl-dsk-small.bmp
PC bitmap, Windows 3.x format, 120 x 29 x 24, image size 10440, resolution 3780 x 3780 px/m, cbSize 10494, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\btn-dsk-vnc-ex.bmp
PC bitmap, Windows 3.x format, 190 x 34 x 24, image size 19448, resolution 2834 x 2834 px/m, cbSize 19502, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\btn-dsk-vnc.bmp
PC bitmap, Windows 3.x format, 500 x 34 x 24, image size 51000, resolution 2834 x 2834 px/m, cbSize 51054, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\btn-vnc-top.bmp
PC bitmap, Windows 3.x format, 96 x 24 x 24, image size 6914, resolution 2834 x 2834 px/m, cbSize 6968, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\btns-ft.bmp
PC bitmap, Windows 3.x format, 550 x 32 x 24, image size 52866, resolution 2834 x 2834 px/m, cbSize 52920, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\buttons-chooser.bmp
PC bitmap, Windows 3.x format, 750 x 38 x 24, image size 85576, resolution 3780 x 3780 px/m, cbSize 85630, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\buttons-connect.bmp
PC bitmap, Windows 3.x format, 750 x 38 x 24, image size 85576, resolution 2834 x 2834 px/m, cbSize 85630, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\buttons-start-frame.bmp
PC bitmap, Windows 3.x format, 144 x 36 x 24, image size 15552, resolution 2834 x 2834 px/m, cbSize 15606, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\buttons-start.bmp
PC bitmap, Windows 3.x format, 144 x 36 x 32, image size 20736, resolution 2834 x 2834 px/m, cbSize 20790, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\buttons.bmp
PC bitmap, Windows 3.x format, 550 x 32 x 24, image size 52866, resolution 2834 x 2834 px/m, cbSize 52920, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\client-bk-black.bmp
PC bitmap, Windows 3.x format, 55 x 58 x 24, image size 9744, cbSize 9798, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\client-bk-gray-top.bmp
PC bitmap, Windows 3.x format, 63 x 45 x 24, image size 8640, cbSize 8694, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\client-bk-gray.bmp
PC bitmap, Windows 3.x format, 47 x 30 x 24, image size 4320, resolution 2834 x 2834 px/m, cbSize 4374, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\client-edit.bmp
PC bitmap, Windows 3.x format, 180 x 24 x 24, image size 12960, resolution 2834 x 2834 px/m, cbSize 13014, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\close_info.bmp
PC bitmap, Windows 3.x format, 16 x 16 x 32, image size 1026, resolution 2834 x 2834 px/m, cbSize 1080, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\custom_texts.ini
ASCII text
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\dialog_205.xml
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\dlgframe.bmp
PC bitmap, Windows 3.x format, 85 x 80 x 24, image size 20480, resolution 2834 x 2834 px/m, cbSize 20534, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\ic-backspace.bmp
PC bitmap, Windows 3.x format, 24 x 24 x 32, image size 2304, resolution 3780 x 3780 px/m, cbSize 2358, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\ic-enter.bmp
PC bitmap, Windows 3.x format, 24 x 24 x 32, image size 2304, resolution 3780 x 3780 px/m, cbSize 2358, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\ik-enter.bmp
PC bitmap, Windows 3.x format, 24 x 24 x 32, image size 2304, resolution 2835 x 2835 px/m, cbSize 2358, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\ik-exit.bmp
PC bitmap, Windows 3.x format, 32 x 32 x 32, image size 4096, resolution 2835 x 2835 px/m, cbSize 4150, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\ik-play.bmp
PC bitmap, Windows 3.x format, 84 x 28 x 32, image size 9410, resolution 2834 x 2834 px/m, cbSize 9464, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\ik-settings.bmp
PC bitmap, Windows 3.x format, 32 x 32 x 32, image size 4096, resolution 2835 x 2835 px/m, cbSize 4150, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\incurves.bmp
PC bitmap, Windows 3.x format, 81 x 72 x 24, image size 17570, resolution 2834 x 2834 px/m, cbSize 17624, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\mail.bmp
PC bitmap, Windows 3.x format, 32 x 32 x 32, image size 4096, resolution 2835 x 2835 px/m, cbSize 4150, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\outcurves.bmp
PC bitmap, Windows 3.x format, 95 x 83 x 24, image size 23904, resolution 2834 x 2834 px/m, cbSize 23958, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\pin.bmp
PC bitmap, Windows 3.x format, 40 x 20 x 32, image size 3200, resolution 2835 x 2835 px/m, cbSize 3254, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\skin_data.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\slider_btns.bmp
PC bitmap, Windows 3.x format, 90 x 18 x 24, image size 4898, resolution 2834 x 2834 px/m, cbSize 4952, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\slider_inner.bmp
PC bitmap, Windows 3.x format, 36 x 26 x 24, image size 2810, resolution 2834 x 2834 px/m, cbSize 2864, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\thumb-audio.bmp
PC bitmap, Windows 3.x format, 13 x 12 x 24, image size 482, resolution 3779 x 3779 px/m, cbSize 536, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\thumb-desktop.bmp
PC bitmap, Windows 3.x format, 12 x 11 x 24, image size 398, resolution 2834 x 2834 px/m, cbSize 452, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\thumb-file.bmp
PC bitmap, Windows 3.x format, 16 x 14 x 24, image size 674, resolution 2834 x 2834 px/m, cbSize 728, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\thumb-video.bmp
PC bitmap, Windows 3.x format, 12 x 10 x 24, image size 362, resolution 3779 x 3779 px/m, cbSize 416, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\titlebar-vnc-top.bmp
PC bitmap, Windows 3.x format, 640 x 29 x 24, image size 55680, resolution 2834 x 2834 px/m, cbSize 55734, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\titlebar-vnc.bmp
PC bitmap, Windows 3.x format, 320 x 28 x 24, image size 26880, resolution 2834 x 2834 px/m, cbSize 26934, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\v4_arrow-up.bmp
PC bitmap, Windows 3.x format, 20 x 20 x 32, image size 1600, resolution 2835 x 2835 px/m, cbSize 1654, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\v4_arrow.bmp
PC bitmap, Windows 3.x format, 20 x 20 x 32, image size 1600, resolution 2835 x 2835 px/m, cbSize 1654, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\v4_files.bmp
PC bitmap, Windows 3.x format, 32 x 32 x 32, image size 4096, resolution 2835 x 2835 px/m, cbSize 4150, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\v4_icon_chat_audio.bmp
PC bitmap, Windows 3.x format, 32 x 32 x 32, image size 4096, resolution 2835 x 2835 px/m, cbSize 4150, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\v4_icon_chat_video.bmp
PC bitmap, Windows 3.x format, 32 x 32 x 32, image size 4096, resolution 2835 x 2835 px/m, cbSize 4150, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\v4_icon_start_sharing.bmp
PC bitmap, Windows 3.x format, 18 x 18 x 32, image size 1296, resolution 2835 x 2835 px/m, cbSize 1350, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\v4_icon_stop_sharing.bmp
PC bitmap, Windows 3.x format, 18 x 18 x 32, image size 1296, resolution 2835 x 2835 px/m, cbSize 1350, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\v4_ik-VNC-top.bmp
PC bitmap, Windows 3.x format, 30 x 14 x 32, image size 1680, resolution 2835 x 2835 px/m, cbSize 1734, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\skin\white.bmp
PC bitmap, Windows 3.x format, 17 x 17 x 24, image size 884, cbSize 938, bits offset 54
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\source_pkg.dat
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\trace.out
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Light Client\1\translations\LangAll.tr2
data
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Network Start\1\ISLNetworkStart.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Network Start\1\conf\address
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Network Start\1\conf\port
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Network Start\1\conf\query
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Network Start\1\conf\use_http
very short file (no magic)
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Network Start\1\conf\use_https
very short file (no magic)
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Network Start\1\conf_static\caption
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Network Start\1\connection_keys\connection_keys
data
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Network Start\1\isl_network_start.log
ASCII text, with very long lines (3008), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Network Start\1\translations\translations
data
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Network Start\cache\file_cache_v3_043065b2e452ce2cf70257bf9425894cba1c5de87ed10248a2b672c5c399c723 (copy)
data
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Network Start\cache\file_cache_v3_3ed70ed34cf00c10cc154e384abd36a689ae85d7c5b9bae1ab71608ebbb9fb8c (copy)
data
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Network Start\cache\file_cache_v3_419ef57f0b28960c833825d468211467de332c0e3dfadec7b6e72b82ed3c04b7 (copy)
data
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Network Start\cache\file_cache_v3_45390ea339a822941ab593a53883383e16a0d5f46ac05d5b9c7b49218cb8014e (copy)
data
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Network Start\cache\file_cache_v3_68e7d0a5d2fbad6a95db87b21edc997063a5b30d2660721392f4498ac45d20b5 (copy)
data
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Network Start\cache\file_cache_v3_b5ca13e92e299006b18361a251e52720a13c30ba0c08a23fc19e6b6ba3b0c01f (copy)
data
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Network Start\cache\file_cache_v3_ccc40b01224b537ac32e8a9ac7abe0c619020bafddf89f6f60f98345b23e5563 (copy)
data
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Network Start\cache\file_cache_v3_e05fc368b8b5e4bdfc11af1c131268794ca22b3ce2da363e9d7d1418b807ce98 (copy)
data
dropped
C:\Users\user\AppData\Local\ISL Online Cache\ISL Network Start\cache\tmp_7564_7596
data
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\SendTo\ISL Light Client.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 1 02:38:49 2024, mtime=Tue Oct 1 02:38:49 2024, atime=Tue Oct 1 02:38:49 2024, length=14648, window=hide
dropped
There are 74 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Users\user\AppData\Local\ISL Online Cache\ISL Network Start\1\extract_1727760940_7564_7596_541766985\ISL_Light_Client_4_4_2332_44 49919761.exe
ISL_Light_Client_4_4_2332_44_49919761.exe
malicious
C:\Users\user\Desktop\$RMH4FA8.exe
"C:\Users\user\Desktop\$RMH4FA8.exe"

URLs

Name
IP
Malicious
http://www.apache.org/licenses/LICENSE-2.0).P
unknown
http://www.islonline.com
unknown
http://www.islonline.com/help?%5%
unknown
http://www.islonline.com/r301?
unknown
http://www.apache.org/licenses/LICENSE-2.0).
unknown
http://www.islonline.com/r301?&topic=SETTINGS_PLUGINS_AVAILABLESETTINGS_PLUGINS_LOADEDplugin
unknown
http://www.apache.org/licenses/LICENSE-2.0).6L
unknown
http://www.apache.org/licenses/LICENSE-2.0).invalid
unknown
http://www.islonline.com/help?p=isl-light&v=3-2&f=html&l=%5%
unknown

Domains

Name
IP
Malicious
isllight-myipaicohlcbrbhl.islonline.net
139.144.234.209
networkstart-ivfqcxy.islonline.net
195.201.59.111
networkstart-myipaicohlcbpwnb.islonline.net
170.187.160.42

IPs

IP
Domain
Country
Malicious
170.187.160.42
networkstart-myipaicohlcbpwnb.islonline.net
United States
139.144.234.209
isllight-myipaicohlcbrbhl.islonline.net
United States
195.201.59.111
networkstart-ivfqcxy.islonline.net
Germany

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\ISL Online\Grid\ISL Online Network
grid_id
HKEY_CURRENT_USER\SOFTWARE\ISL Online\Grid\ISL Online Network
cp_protocol
HKEY_CURRENT_USER\SOFTWARE\ISL Online\Grid\ISL Online Network
key_cs
HKEY_CURRENT_USER\SOFTWARE\ISL Online\Grid\ISL Online Network
key_cs_latest
HKEY_CURRENT_USER\SOFTWARE\ISL Online\AutoTransport\Last public IP
.islonline.net
HKEY_CURRENT_USER\SOFTWARE\ISL Online\Grid\ISL Online Network
key_hash
HKEY_CURRENT_USER\SOFTWARE\ISL Online\Grid\ISL Online Network
key_ss
HKEY_CURRENT_USER\SOFTWARE\ISL Online\AutoTransport\Boost transport type
v1
HKEY_CURRENT_USER\SOFTWARE\ISL Online\AutoTransport\HTTP proxy PAC
v1

Memdumps

Base Address
Regiontype
Protect
Malicious
3A5A000
heap
page read and write
6500000
heap
page read and write
30D3000
heap
page read and write
300D000
heap
page read and write
2E39000
heap
page read and write
35F0000
unkown
page readonly
2EAF000
heap
page read and write
6D05A000
unkown
page readonly
29B6000
heap
page read and write
2884000
heap
page read and write
51C8000
heap
page read and write
2DDF000
heap
page read and write
394F000
heap
page read and write
32D9000
heap
page read and write
3606000
unkown
page readonly
395A000
heap
page read and write
BAF000
heap
page read and write
B74000
heap
page read and write
6A3E000
stack
page read and write
306D000
heap
page read and write
4F88000
heap
page read and write
2E3F000
heap
page read and write
2EFE000
stack
page read and write
2812000
heap
page read and write
2E3B000
heap
page read and write
2D00000
unkown
page readonly
5238000
heap
page read and write
36C0000
heap
page read and write
3600000
unkown
page readonly
6D002000
unkown
page readonly
3085000
heap
page read and write
2F7F000
heap
page read and write
5038000
heap
page read and write
2F97000
heap
page read and write
6B3F000
stack
page read and write
960000
heap
page read and write
312D000
heap
page read and write
2F9B000
heap
page read and write
5018000
heap
page read and write
3E08000
heap
page read and write
30DD000
heap
page read and write
3600000
unkown
page readonly
300F000
heap
page read and write
39E1000
heap
page read and write
5068000
heap
page read and write
3DAC000
heap
page read and write
470000
unkown
page readonly
27F6000
heap
page read and write
8FA000
stack
page read and write
5188000
heap
page read and write
30AD000
heap
page read and write
311D000
heap
page read and write
3600000
unkown
page readonly
5218000
heap
page read and write
3600000
unkown
page readonly
8FC000
stack
page read and write
5098000
heap
page read and write
3600000
unkown
page readonly
E7E000
stack
page read and write
3DA7000
heap
page read and write
E4E000
heap
page read and write
9F5000
heap
page read and write
3011000
heap
page read and write
34EE000
stack
page read and write
27B0000
heap
page read and write
302D000
heap
page read and write
63ED000
stack
page read and write
C40000
unkown
page readonly
4A82000
heap
page read and write
4F7E000
stack
page read and write
3091000
heap
page read and write
36F0000
unkown
page readonly
5118000
heap
page read and write
ADC000
stack
page read and write
2DD5000
heap
page read and write
39BD000
heap
page read and write
970000
heap
page read and write
BE6000
heap
page read and write
3600000
unkown
page readonly
67BE000
stack
page read and write
3600000
unkown
page readonly
D7E000
stack
page read and write
3600000
unkown
page readonly
2CBE000
stack
page read and write
9BE000
stack
page read and write
390E000
heap
page read and write
2DFA000
heap
page read and write
3A7D000
heap
page read and write
5198000
heap
page read and write
2B4A000
heap
page read and write
3E08000
heap
page read and write
36E0000
heap
page read and write
470000
unkown
page readonly
2EAF000
heap
page read and write
3DA2000
heap
page read and write
3025000
heap
page read and write
38FA000
heap
page read and write
50B8000
heap
page read and write
3A8D000
heap
page read and write
3600000
unkown
page readonly
3949000
heap
page read and write
C41000
unkown
page execute read
3A1B000
heap
page read and write
2F28000
heap
page read and write
2890000
heap
page read and write
3600000
unkown
page readonly
6CF30000
unkown
page readonly
51B8000
heap
page read and write
30FB000
heap
page read and write
2E68000
heap
page read and write
30F1000
heap
page read and write
3A07000
heap
page read and write
3600000
unkown
page readonly
E4A000
heap
page read and write
38EA000
heap
page read and write
3047000
heap
page read and write
E40000
heap
page read and write
390E000
heap
page read and write
304D000
heap
page read and write
6D036000
unkown
page write copy
50E8000
heap
page read and write
E70000
heap
page read and write
50C8000
heap
page read and write
3051000
heap
page read and write
3601000
unkown
page readonly
5228000
heap
page read and write
3696000
heap
page read and write
5158000
heap
page read and write
3600000
unkown
page readonly
B70000
heap
page read and write
301B000
heap
page read and write
3320000
heap
page read and write
5108000
heap
page read and write
4FB8000
heap
page read and write
30C7000
heap
page read and write
3270000
heap
page read and write
33AE000
stack
page read and write
3600000
unkown
page readonly
333E000
heap
page read and write
8CB000
stack
page read and write
2C7E000
stack
page read and write
43D0000
heap
page read and write
5208000
heap
page read and write
3600000
unkown
page readonly
6D065000
unkown
page read and write
2B4D000
heap
page read and write
30ED000
heap
page read and write
4E7D000
stack
page read and write
B80000
heap
page read and write
2E62000
heap
page read and write
372E000
stack
page read and write
2815000
heap
page read and write
8EC000
stack
page read and write
3870000
heap
page read and write
2EF7000
heap
page read and write
BF7000
heap
page read and write
30CB000
heap
page read and write
3DFF000
heap
page read and write
4F98000
heap
page read and write
C3D000
stack
page read and write
AF2000
stack
page read and write
3600000
unkown
page readonly
AFC000
stack
page read and write
333E000
heap
page read and write
30E3000
heap
page read and write
30F3000
heap
page read and write
68FE000
stack
page read and write
328F000
heap
page read and write
2EAE000
heap
page read and write
30EB000
heap
page read and write
2E62000
heap
page read and write
5078000
heap
page read and write
6B5F000
heap
page read and write
44EA000
heap
page read and write
39A7000
heap
page read and write
9F0000
heap
page read and write
36E4000
heap
page read and write
3005000
heap
page read and write
4F7B000
stack
page read and write
3069000
heap
page read and write
2E55000
heap
page read and write
30D9000
heap
page read and write
3DA5000
heap
page read and write
AE7000
stack
page read and write
5058000
heap
page read and write
30F7000
heap
page read and write
6D07E000
unkown
page readonly
30A3000
heap
page read and write
3600000
unkown
page readonly
304B000
heap
page read and write
30E7000
heap
page read and write
30D1000
heap
page read and write
4FA8000
heap
page read and write
6C7F000
stack
page read and write
64EF000
stack
page read and write
3DA1000
heap
page read and write
38A4000
heap
page read and write
38EA000
heap
page read and write
2F67000
heap
page read and write
4FC8000
heap
page read and write
2896000
heap
page read and write
3600000
unkown
page readonly
3A6A000
heap
page read and write
5288000
heap
page read and write
2F74000
heap
page read and write
39F5000
heap
page read and write
30EF000
heap
page read and write
3A1C000
heap
page read and write
2877000
heap
page read and write
2FA3000
heap
page read and write
3942000
heap
page read and write
32E0000
heap
page read and write
390B000
heap
page read and write
312F000
heap
page read and write
3600000
unkown
page readonly
3031000
heap
page read and write
50A8000
heap
page read and write
D9E000
stack
page read and write
311B000
heap
page read and write
3949000
heap
page read and write
C4D000
unkown
page readonly
3940000
heap
page read and write
2EF7000
heap
page read and write
2DBD000
stack
page read and write
59F0000
trusted library allocation
page read and write
308B000
heap
page read and write
5168000
heap
page read and write
5128000
heap
page read and write
3315000
heap
page read and write
4D3E000
stack
page read and write
2E52000
heap
page read and write
5138000
heap
page read and write
3620000
unkown
page readonly
4FD8000
heap
page read and write
471000
unkown
page execute read
360D000
unkown
page readonly
B0D000
stack
page read and write
6D061000
unkown
page read and write
6CD50000
unkown
page readonly
3600000
unkown
page readonly
390B000
heap
page read and write
30F5000
heap
page read and write
5088000
heap
page read and write
3302000
heap
page read and write
3600000
unkown
page readonly
27F0000
heap
page read and write
6D03D000
unkown
page read and write
5F8000
stack
page read and write
2E4F000
heap
page read and write
3A66000
heap
page read and write
27E4000
heap
page read and write
38F2000
heap
page read and write
2E68000
heap
page read and write
2854000
heap
page read and write
3600000
unkown
page readonly
2E47000
heap
page read and write
32CA000
heap
page read and write
3600000
unkown
page readonly
C4D000
unkown
page readonly
30CF000
heap
page read and write
30A5000
heap
page read and write
799000
stack
page read and write
6F0E000
heap
page read and write
3E45000
heap
page read and write
3013000
heap
page read and write
2E65000
heap
page read and write
B00000
heap
page read and write
5048000
heap
page read and write
38FA000
heap
page read and write
3600000
unkown
page readonly
3600000
unkown
page readonly
2DF0000
heap
page read and write
3600000
unkown
page readonly
6CF31000
unkown
page execute read
4E3F000
stack
page read and write
677F000
stack
page read and write
3295000
heap
page read and write
3600000
unkown
page readonly
32BE000
heap
page read and write
B8A000
heap
page read and write
7119000
heap
page read and write
3039000
heap
page read and write
50F8000
heap
page read and write
3600000
unkown
page readonly
103E000
stack
page read and write
2888000
heap
page read and write
3073000
heap
page read and write
667E000
stack
page read and write
6D032000
unkown
page read and write
3023000
heap
page read and write
64CA000
stack
page read and write
BE6000
heap
page read and write
6D07C000
unkown
page readonly
32D4000
heap
page read and write
32B4000
heap
page read and write
6B7E000
stack
page read and write
2B41000
heap
page read and write
30E5000
heap
page read and write
5028000
heap
page read and write
2EF4000
heap
page read and write
30F9000
heap
page read and write
51E8000
heap
page read and write
52BD000
heap
page read and write
69FF000
stack
page read and write
2EAF000
heap
page read and write
BBB000
heap
page read and write
398C000
heap
page read and write
2F8A000
heap
page read and write
44EC000
heap
page read and write
50D8000
heap
page read and write
3601000
unkown
page readonly
6CD51000
unkown
page execute read
30D7000
heap
page read and write
BE6000
heap
page read and write
3125000
heap
page read and write
30B3000
heap
page read and write
D5F000
stack
page read and write
35ED000
stack
page read and write
30CD000
heap
page read and write
2E4F000
heap
page read and write
5278000
heap
page read and write
5008000
heap
page read and write
B20000
heap
page read and write
2F30000
unclassified section
page read and write
30A9000
heap
page read and write
30C9000
heap
page read and write
3600000
unkown
page readonly
8F2000
stack
page read and write
3DA0000
heap
page read and write
51F8000
heap
page read and write
3021000
heap
page read and write
36B0000
heap
page read and write
3101000
heap
page read and write
394A000
heap
page read and write
376D000
stack
page read and write
B8E000
heap
page read and write
C41000
unkown
page execute read
3071000
heap
page read and write
286C000
heap
page read and write
BEF000
heap
page read and write
2861000
heap
page read and write
6DC5000
heap
page read and write
6D046000
unkown
page read and write
44EE000
heap
page read and write
2FFE000
stack
page read and write
51A8000
heap
page read and write
2E47000
heap
page read and write
3029000
heap
page read and write
3600000
unkown
page readonly
30B7000
heap
page read and write
304F000
heap
page read and write
2E07000
heap
page read and write
3942000
heap
page read and write
3067000
heap
page read and write
3949000
heap
page read and write
3045000
heap
page read and write
2B7E000
stack
page read and write
3600000
unkown
page readonly
AD4000
stack
page read and write
32AC000
heap
page read and write
307F000
heap
page read and write
BAF000
heap
page read and write
3520000
heap
page read and write
3DFF000
heap
page read and write
3337000
heap
page read and write
3620000
unkown
page readonly
3600000
unkown
page readonly
3059000
heap
page read and write
390B000
heap
page read and write
7520000
heap
page read and write
316E000
stack
page read and write
4B4C000
heap
page read and write
2FA9000
heap
page read and write
B60000
heap
page read and write
29B9000
heap
page read and write
5178000
heap
page read and write
2F25000
heap
page read and write
6D063000
unkown
page write copy
2E68000
heap
page read and write
3E39000
heap
page read and write
36F0000
unkown
page readonly
3942000
heap
page read and write
300B000
heap
page read and write
5298000
heap
page read and write
47D000
unkown
page readonly
386E000
stack
page read and write
29B0000
heap
page read and write
47D000
unkown
page readonly
2940000
direct allocation
page read and write
BE0000
heap
page read and write
3602000
unkown
page readonly
4FE8000
heap
page read and write
3600000
unkown
page readonly
BB5000
heap
page read and write
BF0000
heap
page read and write
26C2000
heap
page read and write
AFA000
stack
page read and write
309F000
heap
page read and write
2DC0000
heap
page read and write
27E0000
heap
page read and write
34AF000
stack
page read and write
27ED000
heap
page read and write
4FF8000
heap
page read and write
3600000
unkown
page readonly
62EF000
stack
page read and write
3600000
unkown
page readonly
3109000
heap
page read and write
3600000
unkown
page readonly
30DF000
heap
page read and write
6C7B000
heap
page read and write
5148000
heap
page read and write
30E9000
heap
page read and write
C40000
unkown
page readonly
396B000
heap
page read and write
2EF7000
heap
page read and write
326E000
stack
page read and write
3601000
unkown
page readonly
471000
unkown
page execute read
330F000
heap
page read and write
330D000
heap
page read and write
68BF000
stack
page read and write
3093000
heap
page read and write
51D8000
heap
page read and write
3600000
unkown
page readonly
3600000
unkown
page readonly
There are 415 hidden memdumps, click here to show them.