Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
JpQFDOA7Uk.exe
|
PE32 executable (console) Intel 80386, for MS Windows
|
initial sample
|
||
C:\Users\user\.ms-ad\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\user\3D Objects\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\user\Contacts\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\user\Desktop\BJZFPPWAPT\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\user\Desktop\EIVQSAOTAQ\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\user\Desktop\EWZCVGNOWT\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\user\Desktop\GRXZDKKVDB\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\user\Desktop\JpQFDOA7Uk.exe.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Downloads\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\user\Favorites\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\user\Favorites\Links\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\CyberVolk_ReadMe.txt
|
ASCII text
|
modified
|
||
C:\Users\Public\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\Public\Documents\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\Public\Documents\desktop.ini.CyberVolk
|
data
|
dropped
|
||
C:\Users\Public\Downloads\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\Public\Downloads\desktop.ini.CyberVolk
|
data
|
dropped
|
||
C:\Users\Public\Music\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\Public\Music\desktop.ini.CyberVolk
|
data
|
dropped
|
||
C:\Users\Public\Pictures\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\Public\Pictures\desktop.ini.CyberVolk
|
data
|
dropped
|
||
C:\Users\Public\Videos\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\Public\Videos\desktop.ini.CyberVolk
|
data
|
dropped
|
||
C:\Users\Public\desktop.ini.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\.curlrc.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\3D Objects\desktop.ini.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\tmp.bmp
|
PC bitmap, Windows 3.x format, 1920 x 1080 x 24, image size 6220800, cbSize 6220854, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\Roaming\time.dat
|
ASCII text, with no line terminators
|
dropped
|
||
C:\Users\user\Contacts\desktop.ini.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\user\Desktop\BJZFPPWAPT.docx.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Desktop\BJZFPPWAPT.xlsx.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Desktop\BJZFPPWAPT\BJZFPPWAPT.docx.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Desktop\BJZFPPWAPT\DUUDTUBZFW.xlsx.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Desktop\BJZFPPWAPT\EWZCVGNOWT.jpg.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Desktop\BJZFPPWAPT\JDDHMPCDUJ.mp3.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Desktop\BJZFPPWAPT\KLIZUSIQEN.png.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Desktop\BJZFPPWAPT\ZGGKNSUKOP.pdf.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Desktop\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\user\Desktop\DUUDTUBZFW.jpg.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Desktop\DUUDTUBZFW.xlsx.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Desktop\EOWRVPQCCS.png.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Desktop\EWZCVGNOWT.jpg.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Desktop\Excel.lnk.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Desktop\GIGIYTFFYT.pdf.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Desktop\GLTYDMDUST.mp3.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Desktop\GRXZDKKVDB.docx.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Desktop\GRXZDKKVDB\BJZFPPWAPT.xlsx.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Desktop\GRXZDKKVDB\DUUDTUBZFW.jpg.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Desktop\GRXZDKKVDB\EOWRVPQCCS.png.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Desktop\GRXZDKKVDB\GRXZDKKVDB.docx.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Desktop\GRXZDKKVDB\PALRGUCVEH.pdf.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Desktop\GRXZDKKVDB\ZGGKNSUKOP.mp3.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Desktop\JDDHMPCDUJ.jpg.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Desktop\JDDHMPCDUJ.mp3.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Desktop\KLIZUSIQEN.png.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Desktop\LIJDSFKJZG\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\user\Desktop\NWCXBPIUYI\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\user\Desktop\NYMMPCEIMA\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\user\Desktop\PALRGUCVEH.docx.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Desktop\PALRGUCVEH.pdf.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Desktop\PALRGUCVEH\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\user\Desktop\PALRGUCVEH\GIGIYTFFYT.pdf.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Desktop\PALRGUCVEH\GLTYDMDUST.mp3.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Desktop\PALRGUCVEH\JDDHMPCDUJ.jpg.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Desktop\PALRGUCVEH\PALRGUCVEH.docx.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Desktop\PALRGUCVEH\ZGGKNSUKOP.xlsx.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Desktop\PALRGUCVEH\ZIPXYXWIOY.png.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Desktop\VWDFPKGDUF\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\user\Desktop\ZGGKNSUKOP.mp3.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Desktop\ZGGKNSUKOP.pdf.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Desktop\ZGGKNSUKOP.xlsx.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Desktop\ZIPXYXWIOY.png.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Desktop\desktop.ini.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Documents\BJZFPPWAPT.docx.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Documents\BJZFPPWAPT.xlsx.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Documents\BJZFPPWAPT\BJZFPPWAPT.docx.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Documents\BJZFPPWAPT\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\user\Documents\BJZFPPWAPT\DUUDTUBZFW.xlsx.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Documents\BJZFPPWAPT\EWZCVGNOWT.jpg.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Documents\BJZFPPWAPT\JDDHMPCDUJ.mp3.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Documents\BJZFPPWAPT\KLIZUSIQEN.png.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Documents\BJZFPPWAPT\ZGGKNSUKOP.pdf.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Documents\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\user\Documents\DUUDTUBZFW.jpg.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Documents\DUUDTUBZFW.xlsx.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Documents\EIVQSAOTAQ\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\user\Documents\EOWRVPQCCS.png.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Documents\EWZCVGNOWT.jpg.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Documents\EWZCVGNOWT\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\user\Documents\GIGIYTFFYT.pdf.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Documents\GLTYDMDUST.mp3.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Documents\GRXZDKKVDB.docx.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Documents\GRXZDKKVDB\BJZFPPWAPT.xlsx.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Documents\GRXZDKKVDB\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\user\Documents\GRXZDKKVDB\DUUDTUBZFW.jpg.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Documents\GRXZDKKVDB\EOWRVPQCCS.png.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Documents\GRXZDKKVDB\GRXZDKKVDB.docx.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Documents\GRXZDKKVDB\PALRGUCVEH.pdf.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Documents\GRXZDKKVDB\ZGGKNSUKOP.mp3.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Documents\JDDHMPCDUJ.jpg.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Documents\JDDHMPCDUJ.mp3.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Documents\KLIZUSIQEN.png.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Documents\LIJDSFKJZG\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\user\Documents\NWCXBPIUYI\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\user\Documents\NYMMPCEIMA\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\user\Documents\PALRGUCVEH.docx.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Documents\PALRGUCVEH.pdf.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Documents\PALRGUCVEH\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\user\Documents\PALRGUCVEH\GIGIYTFFYT.pdf.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Documents\PALRGUCVEH\GLTYDMDUST.mp3.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Documents\PALRGUCVEH\JDDHMPCDUJ.jpg.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Documents\PALRGUCVEH\PALRGUCVEH.docx.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Documents\PALRGUCVEH\ZGGKNSUKOP.xlsx.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Documents\PALRGUCVEH\ZIPXYXWIOY.png.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Documents\VWDFPKGDUF\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\user\Documents\ZGGKNSUKOP.mp3.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Documents\ZGGKNSUKOP.pdf.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Documents\ZGGKNSUKOP.xlsx.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Documents\ZIPXYXWIOY.png.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Documents\desktop.ini.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Downloads\BJZFPPWAPT.docx.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Downloads\BJZFPPWAPT.xlsx.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Downloads\DUUDTUBZFW.jpg.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Downloads\DUUDTUBZFW.xlsx.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Downloads\EOWRVPQCCS.png.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Downloads\EWZCVGNOWT.jpg.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Downloads\GIGIYTFFYT.pdf.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Downloads\GLTYDMDUST.mp3.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Downloads\GRXZDKKVDB.docx.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Downloads\JDDHMPCDUJ.jpg.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Downloads\JDDHMPCDUJ.mp3.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Downloads\KLIZUSIQEN.png.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Downloads\PALRGUCVEH.docx.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Downloads\PALRGUCVEH.pdf.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Downloads\ZGGKNSUKOP.mp3.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Downloads\ZGGKNSUKOP.pdf.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Downloads\ZGGKNSUKOP.xlsx.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Downloads\ZIPXYXWIOY.png.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Downloads\desktop.ini.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Favorites\Amazon.url.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Favorites\Bing.url.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Favorites\Facebook.url.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Favorites\Google.url.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Favorites\Links\desktop.ini.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Favorites\Live.url.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Favorites\NYTimes.url.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Favorites\Reddit.url.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Favorites\Twitter.url.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Favorites\Wikipedia.url.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Favorites\Youtube.url.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Favorites\desktop.ini.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Links\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\user\Links\Desktop.lnk.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Links\Downloads.lnk.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Links\desktop.ini.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Music\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\user\Music\desktop.ini.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\NTUSER.DAT{53b39e88-18c4-11ea-a811-000d3aa4692b}.TM.blf.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\NTUSER.DAT{53b39e88-18c4-11ea-a811-000d3aa4692b}.TMContainer00000000000000000001.regtrans-ms.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\NTUSER.DAT{53b39e88-18c4-11ea-a811-000d3aa4692b}.TMContainer00000000000000000002.regtrans-ms.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\OneDrive\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\user\OneDrive\desktop.ini.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Pictures\Camera Roll\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\user\Pictures\Camera Roll\desktop.ini.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Pictures\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\user\Pictures\Saved Pictures\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\user\Pictures\Saved Pictures\desktop.ini.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Pictures\desktop.ini.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Recent\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\user\Saved Games\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\user\Saved Games\desktop.ini.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Searches\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\user\Searches\Everywhere.search-ms.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Searches\Indexed Locations.search-ms.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Searches\desktop.ini.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Searches\winrt--{S-1-5-21-2246122658-3693405117-2476756634-1003}-.searchconnector-ms.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\Videos\CyberVolk_ReadMe.txt
|
ASCII text
|
dropped
|
||
C:\Users\user\Videos\desktop.ini.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\_curlrc.CyberVolk
|
data
|
dropped
|
||
C:\Users\user\ntuser.ini.CyberVolk
|
data
|
dropped
|
||
C:\Users\desktop.ini.CyberVolk
|
data
|
dropped
|
||
\Device\ConDrv
|
ASCII text, with CRLF line terminators
|
dropped
|
There are 174 hidden files, click here to show them.
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\JpQFDOA7Uk.exe
|
"C:\Users\user\Desktop\JpQFDOA7Uk.exe"
|
||
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
https://t.me/cubervolk
|
unknown
|
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
241.42.69.40.in-addr.arpa
|
unknown
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
ED7000
|
heap
|
page read and write
|
||
EDE000
|
heap
|
page read and write
|
||
EDA000
|
heap
|
page read and write
|
||
ED0000
|
heap
|
page read and write
|
||
EDE000
|
heap
|
page read and write
|
||
EDF000
|
heap
|
page read and write
|
||
EDE000
|
heap
|
page read and write
|
||
ED9000
|
heap
|
page read and write
|
||
EE0000
|
heap
|
page read and write
|
||
EDE000
|
heap
|
page read and write
|
||
EDE000
|
heap
|
page read and write
|
||
ED6000
|
heap
|
page read and write
|
||
F00000
|
heap
|
page read and write
|
||
CA0000
|
heap
|
page read and write
|
||
42B000
|
unkown
|
page read and write
|
||
3440000
|
trusted library allocation
|
page read and write
|
||
2FF5000
|
heap
|
page read and write
|
||
2FF0000
|
heap
|
page read and write
|
||
DFF000
|
stack
|
page read and write
|
||
2F04000
|
heap
|
page read and write
|
||
ED8000
|
heap
|
page read and write
|
||
EE0000
|
heap
|
page read and write
|
||
EDA000
|
heap
|
page read and write
|
||
343C000
|
stack
|
page read and write
|
||
ED6000
|
heap
|
page read and write
|
||
EFE000
|
heap
|
page read and write
|
||
EDE000
|
heap
|
page read and write
|
||
423000
|
unkown
|
page readonly
|
||
ED9000
|
heap
|
page read and write
|
||
EDA000
|
heap
|
page read and write
|
||
ED8000
|
heap
|
page read and write
|
||
EDE000
|
heap
|
page read and write
|
||
EE9000
|
heap
|
page read and write
|
||
ED8000
|
heap
|
page read and write
|
||
431000
|
unkown
|
page readonly
|
||
EDA000
|
heap
|
page read and write
|
||
EDE000
|
heap
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
ED5000
|
heap
|
page read and write
|
||
EDE000
|
heap
|
page read and write
|
||
EDE000
|
heap
|
page read and write
|
||
2FD0000
|
heap
|
page read and write
|
||
19D000
|
stack
|
page read and write
|
||
3435000
|
stack
|
page read and write
|
||
ED9000
|
heap
|
page read and write
|
||
EE0000
|
heap
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
E8A000
|
heap
|
page read and write
|
||
2F00000
|
heap
|
page read and write
|
||
EDF000
|
heap
|
page read and write
|
||
ED9000
|
heap
|
page read and write
|
||
1F0000
|
heap
|
page read and write
|
||
EDE000
|
heap
|
page read and write
|
||
ED6000
|
heap
|
page read and write
|
||
9B000
|
stack
|
page read and write
|
||
EDE000
|
heap
|
page read and write
|
||
ED6000
|
heap
|
page read and write
|
||
ED9000
|
heap
|
page read and write
|
||
EDE000
|
heap
|
page read and write
|
||
EA2000
|
heap
|
page read and write
|
||
ED8000
|
heap
|
page read and write
|
||
E80000
|
heap
|
page read and write
|
||
ED6000
|
heap
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
431000
|
unkown
|
page readonly
|
||
EDE000
|
heap
|
page read and write
|
||
EDA000
|
heap
|
page read and write
|
||
EDE000
|
heap
|
page read and write
|
||
ED9000
|
heap
|
page read and write
|
||
EDF000
|
heap
|
page read and write
|
||
EDE000
|
heap
|
page read and write
|
||
2F4E000
|
stack
|
page read and write
|
||
F59000
|
heap
|
page read and write
|
||
EDE000
|
heap
|
page read and write
|
||
EDA000
|
heap
|
page read and write
|
||
CFE000
|
stack
|
page read and write
|
||
EEA000
|
heap
|
page read and write
|
||
EEA000
|
heap
|
page read and write
|
||
ED7000
|
heap
|
page read and write
|
||
2A9F000
|
stack
|
page read and write
|
||
42B000
|
unkown
|
page write copy
|
||
EDE000
|
heap
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
EDA000
|
heap
|
page read and write
|
||
ED8000
|
heap
|
page read and write
|
||
EF7000
|
heap
|
page read and write
|
||
EDE000
|
heap
|
page read and write
|
||
EDE000
|
heap
|
page read and write
|
||
EE9000
|
heap
|
page read and write
|
||
EDA000
|
heap
|
page read and write
|
||
ED8000
|
heap
|
page read and write
|
||
ED8000
|
heap
|
page read and write
|
||
EDE000
|
heap
|
page read and write
|
||
EDE000
|
heap
|
page read and write
|
||
ED8000
|
heap
|
page read and write
|
||
ED8000
|
heap
|
page read and write
|
||
ED6000
|
heap
|
page read and write
|
||
EDA000
|
heap
|
page read and write
|
||
ED7000
|
heap
|
page read and write
|
||
ED9000
|
heap
|
page read and write
|
||
EDE000
|
heap
|
page read and write
|
||
ECE000
|
heap
|
page read and write
|
||
EE0000
|
heap
|
page read and write
|
||
ED9000
|
heap
|
page read and write
|
||
295C000
|
stack
|
page read and write
|
||
EDE000
|
heap
|
page read and write
|
||
CB0000
|
heap
|
page read and write
|
||
F62000
|
heap
|
page read and write
|
||
EDE000
|
heap
|
page read and write
|
||
E8E000
|
heap
|
page read and write
|
||
ED6000
|
heap
|
page read and write
|
||
EDE000
|
heap
|
page read and write
|
||
ED7000
|
heap
|
page read and write
|
||
ED7000
|
heap
|
page read and write
|
||
ED6000
|
heap
|
page read and write
|
||
EDE000
|
heap
|
page read and write
|
||
ED6000
|
heap
|
page read and write
|
||
ED6000
|
heap
|
page read and write
|
||
EDF000
|
heap
|
page read and write
|
||
2FF9000
|
heap
|
page read and write
|
||
EDE000
|
heap
|
page read and write
|
||
EE0000
|
heap
|
page read and write
|
||
343E000
|
stack
|
page read and write
|
||
EDA000
|
heap
|
page read and write
|
||
EDA000
|
heap
|
page read and write
|
||
ED7000
|
heap
|
page read and write
|
||
EEA000
|
heap
|
page read and write
|
||
EA9000
|
heap
|
page read and write
|
||
431000
|
unkown
|
page readonly
|
||
423000
|
unkown
|
page readonly
|
||
ED7000
|
heap
|
page read and write
|
||
285A000
|
stack
|
page read and write
|
||
2EF0000
|
heap
|
page read and write
|
||
EE0000
|
heap
|
page read and write
|
||
ED6000
|
heap
|
page read and write
|
||
ED8000
|
heap
|
page read and write
|
||
EDE000
|
heap
|
page read and write
|
||
EDA000
|
heap
|
page read and write
|
||
EDE000
|
heap
|
page read and write
|
||
ED8000
|
heap
|
page read and write
|
||
299C000
|
stack
|
page read and write
|
||
EDE000
|
heap
|
page read and write
|
There are 132 hidden memdumps, click here to show them.