IOC Report
gi5qOqqypd.exe

loading gif

Files

File Path
Type
Category
Malicious
gi5qOqqypd.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\ProgramData\Draw Panel Cleaner 10.25.46\Draw Panel Cleaner 10.25.46.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\is-18PC7.tmp
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\is-2NIU5.tmp
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\is-4L24O.tmp
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\is-9P9VL.tmp
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\is-A2GDJ.tmp
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\is-A792N.tmp
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\is-BUETS.tmp
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\is-DAL4I.tmp
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\is-E64LR.tmp
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\is-J677J.tmp
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\is-KBGAE.tmp
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\is-LMIEE.tmp
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\is-M3CK0.tmp
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\is-M6058.tmp
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\is-OPGUD.tmp
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\is-QRF3J.tmp
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\is-S6D4H.tmp
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\is-T6V9S.tmp
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\is-UOUT7.tmp
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\is-VF1PB.tmp
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\libgcc_s_dw2-1.dll (copy)
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\libgdk-win32-2.0-0.dll (copy)
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\libgdk_pixbuf-2.0-0.dll (copy)
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\libgdkmm-2.4-1.dll (copy)
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\libglibmm-2.4-1.dll (copy)
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\libgmodule-2.0-0.dll (copy)
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\libgobject-2.0-0.dll (copy)
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\libgomp-1.dll (copy)
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\libintl-8.dll (copy)
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\libjpeg-8.dll (copy)
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\liblcms2-2.dll (copy)
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\libpango-1.0-0.dll (copy)
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\libpangocairo-1.0-0.dll (copy)
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\libpangoft2-1.0-0.dll (copy)
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\libpangomm-1.4-1.dll (copy)
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\libpangowin32-1.0-0.dll (copy)
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\libpixman-1-0.dll (copy)
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\librsvg-2-2.dll (copy)
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\libsigc-2.0-0.dll (copy)
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\libtiff-5.dll (copy)
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\sigmavideoconverter32.exe
PE32 executable (GUI) Intel 80386, for MS Windows
modified
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\uninstall\is-VPU66.tmp
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\uninstall\unins000.exe (copy)
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Temp\is-6UIF0.tmp\gi5qOqqypd.tmp
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Temp\is-QQKS0.tmp\_isetup\_RegDLL.tmp
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Temp\is-QQKS0.tmp\_isetup\_iscrypt.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Temp\is-QQKS0.tmp\_isetup\_setup64.tmp
PE32+ executable (console) x86-64, for MS Windows
dropped
malicious
C:\ProgramData\dr1025it46.dat
Non-ISO extended-ASCII text, with CR line terminators, with escape sequences
dropped
C:\ProgramData\dr1025rc46.dat
data
dropped
C:\ProgramData\dr1025resa.dat
ASCII text, with no line terminators
dropped
C:\ProgramData\dr1025resb.dat
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Sigma Video Converter\is-1P378.tmp
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
C:\Users\user\AppData\Local\Sigma Video Converter\is-4833F.tmp
data
dropped
C:\Users\user\AppData\Local\Sigma Video Converter\is-72LFL.tmp
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
C:\Users\user\AppData\Local\Sigma Video Converter\is-91IE0.tmp
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
C:\Users\user\AppData\Local\Sigma Video Converter\is-LBB0B.tmp
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
C:\Users\user\AppData\Local\Sigma Video Converter\is-MVIR3.tmp
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
C:\Users\user\AppData\Local\Sigma Video Converter\is-Q1B1J.tmp
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
C:\Users\user\AppData\Local\Sigma Video Converter\is-STBIF.tmp
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
C:\Users\user\AppData\Local\Sigma Video Converter\libgraphite2.dll (copy)
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
C:\Users\user\AppData\Local\Sigma Video Converter\libharfbuzz-0.dll (copy)
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
C:\Users\user\AppData\Local\Sigma Video Converter\liblzma-5.dll (copy)
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
C:\Users\user\AppData\Local\Sigma Video Converter\libpcre-1.dll (copy)
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
C:\Users\user\AppData\Local\Sigma Video Converter\libpng16-16.dll (copy)
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
C:\Users\user\AppData\Local\Sigma Video Converter\libwinpthread-1.dll (copy)
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
C:\Users\user\AppData\Local\Sigma Video Converter\uninstall\unins000.dat
InnoSetup Log Sigma Video Converter, version 0x30, 5911 bytes, 506407\user, "C:\Users\user\AppData\Local\Sigma Video Converter"
dropped
C:\Users\user\AppData\Local\Sigma Video Converter\zlib1.dll (copy)
PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\is-QQKS0.tmp\_isetup\_shfoldr.dll
PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
dropped
There are 60 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\gi5qOqqypd.exe
"C:\Users\user\Desktop\gi5qOqqypd.exe"
malicious
C:\Users\user\AppData\Local\Sigma Video Converter\sigmavideoconverter32.exe
"C:\Users\user\AppData\Local\Sigma Video Converter\sigmavideoconverter32.exe" -i
malicious
C:\Users\user\AppData\Local\Temp\is-6UIF0.tmp\gi5qOqqypd.tmp
"C:\Users\user\AppData\Local\Temp\is-6UIF0.tmp\gi5qOqqypd.tmp" /SL5="$1045A,4093012,54272,C:\Users\user\Desktop\gi5qOqqypd.exe"

URLs

Name
IP
Malicious
http://bbkwwly.com/search/?q=67e28dd86d55f128470aac1a7c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4ce8889b5e4fa9281ae978f271ea771795af8e05c445db22f31dfe339426fa11af66c156adb719a9577e55b8603e983a608cf619c5e990983e
185.208.158.202
malicious
bbkwwly.com
malicious
http://bbkwwly.com/search/?q=67e28dd86d55f128470aac1a7c27d78406abdd88be4b12eab517aa5c96bd86e89d874f845a8bbc896c58e713bc90c91936b5281fc235a925ed3e51d6bd974a95129070b416e96cc92be510b866db52b2e34ae84c2b14a82966836f23d7f210c7ed9c923ecb6a9413
185.208.158.202
malicious
http://www.innosetup.com/
unknown
http://tukaani.org/
unknown
http://www.remobjects.com/psU
unknown
http://tukaani.org/xz/
unknown
http://mingw-w64.sourceforge.net/X
unknown
http://www.remobjects.com/ps
unknown
http://fsf.org/
unknown
http://185.208.158.202/search/?q=67e28dd86d55f128470aac1a7c27d78406abdd88be4b12ebb517aa5c96bd86ed82d
unknown
http://185.208.158.202/search/?q=67e28dd86d55f128470aac1a7c27d78406abdd88be4b12eab517aa5c96bd86e89d8
unknown
http://www.gnu.org/licenses/
unknown
There are 3 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
bbkwwly.com
185.208.158.202
malicious

IPs

IP
Domain
Country
Malicious
185.208.158.202
bbkwwly.com
Switzerland
malicious
89.105.201.183
unknown
Netherlands

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Owner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
SessionHash
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Sequence
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
RegFiles0000
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
RegFilesHash
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Sigma Video Converter_is1
Inno Setup: Setup Version
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Sigma Video Converter_is1
Inno Setup: App Path
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Sigma Video Converter_is1
InstallLocation
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Sigma Video Converter_is1
Inno Setup: Icon Group
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Sigma Video Converter_is1
Inno Setup: User
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Sigma Video Converter_is1
Inno Setup: Language
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Sigma Video Converter_is1
DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Sigma Video Converter_is1
UninstallString
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Sigma Video Converter_is1
QuietUninstallString
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Sigma Video Converter_is1
NoModify
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Sigma Video Converter_is1
NoRepair
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Sigma Video Converter_is1
InstallDate
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Sigma Video Converter_is1
EstimatedSize
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\SmallTour
draw_panel_cleaner_i46_7
There are 9 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
2BA1000
direct allocation
page execute and read and write
malicious
2AF6000
heap
page read and write
malicious
3565000
heap
page read and write
674000
heap
page read and write
4E0000
heap
page read and write
3543000
heap
page read and write
8E2000
heap
page read and write
2208000
direct allocation
page read and write
32AE000
stack
page read and write
35A8000
heap
page read and write
27A0000
heap
page read and write
326F000
stack
page read and write
840000
heap
page read and write
8B3000
heap
page read and write
10000000
unkown
page readonly
674000
heap
page read and write
5AA0000
heap
page read and write
830000
direct allocation
page read and write
780000
direct allocation
page execute and read and write
674000
heap
page read and write
5781000
heap
page read and write
674000
heap
page read and write
222C000
direct allocation
page read and write
5781000
heap
page read and write
32EE000
stack
page read and write
8DB000
heap
page read and write
820000
heap
page read and write
880000
heap
page read and write
33EF000
stack
page read and write
840000
direct allocation
page read and write
313E000
direct allocation
page read and write
9CC000
heap
page read and write
860000
direct allocation
page read and write
2E8E000
stack
page read and write
400000
unkown
page readonly
314E000
stack
page read and write
5781000
heap
page read and write
6D0000
heap
page read and write
85A000
heap
page read and write
8A6000
heap
page read and write
674000
heap
page read and write
4D0000
heap
page read and write
674000
heap
page read and write
2131000
direct allocation
page read and write
675000
heap
page read and write
651000
unkown
page readonly
674000
heap
page read and write
89E000
heap
page read and write
674000
heap
page read and write
23B9000
heap
page read and write
2120000
direct allocation
page read and write
352F000
stack
page read and write
2144000
direct allocation
page read and write
674000
heap
page read and write
30FF000
stack
page read and write
8D0000
heap
page read and write
420000
heap
page read and write
27F0000
trusted library allocation
page read and write
674000
heap
page read and write
674000
heap
page read and write
24A0000
heap
page read and write
7C0000
heap
page read and write
71E000
stack
page read and write
57C0000
direct allocation
page read and write
674000
heap
page read and write
8B3000
heap
page read and write
674000
heap
page read and write
253B000
direct allocation
page read and write
674000
heap
page read and write
7E4000
heap
page read and write
674000
heap
page read and write
2381000
heap
page read and write
23B5000
heap
page read and write
3130000
direct allocation
page read and write
BCD000
stack
page read and write
8AE000
heap
page read and write
9AB000
heap
page read and write
8B0000
heap
page read and write
8AE000
heap
page read and write
675000
heap
page read and write
740000
heap
page read and write
8E0000
heap
page read and write
674000
heap
page read and write
58DF000
heap
page read and write
40D000
unkown
page write copy
2360000
direct allocation
page read and write
411000
unkown
page readonly
674000
heap
page read and write
8DB000
heap
page read and write
674000
heap
page read and write
674000
heap
page read and write
2124000
direct allocation
page read and write
49A000
unkown
page write copy
730000
heap
page read and write
49D000
unkown
page write copy
8D7000
heap
page read and write
222F000
direct allocation
page read and write
19D000
stack
page read and write
21F0000
direct allocation
page read and write
4E9000
heap
page read and write
24B0000
direct allocation
page read and write
674000
heap
page read and write
8EA000
heap
page read and write
674000
heap
page read and write
8DB000
heap
page read and write
2D4B000
stack
page read and write
674000
heap
page read and write
9B000
stack
page read and write
8E0000
heap
page read and write
674000
heap
page read and write
35F1000
heap
page read and write
7B0000
heap
page read and write
401000
unkown
page execute and write copy
4AB000
unkown
page readonly
25B0000
direct allocation
page read and write
4C0000
heap
page read and write
40B000
unkown
page execute and read and write
8E0000
heap
page read and write
680000
heap
page read and write
5A0000
heap
page read and write
674000
heap
page read and write
674000
heap
page read and write
353E000
heap
page read and write
9C5000
heap
page read and write
8B3000
heap
page read and write
400000
unkown
page readonly
10001000
unkown
page execute read
265B000
heap
page read and write
4AB000
unkown
page readonly
8E0000
heap
page read and write
400000
unkown
page readonly
674000
heap
page read and write
10002000
unkown
page readonly
56C0000
heap
page read and write
7E0000
heap
page read and write
3130000
direct allocation
page read and write
5781000
heap
page read and write
65F000
unkown
page readonly
19C000
stack
page read and write
5AA1000
heap
page read and write
2FFE000
stack
page read and write
670000
heap
page read and write
62E000
unkown
page readonly
674000
heap
page read and write
8AE000
heap
page read and write
8CE000
stack
page read and write
8B3000
heap
page read and write
8B3000
heap
page read and write
870000
direct allocation
page read and write
99C000
heap
page read and write
674000
heap
page read and write
3630000
heap
page read and write
674000
heap
page read and write
400000
unkown
page readonly
85E000
heap
page read and write
23B0000
heap
page read and write
674000
heap
page read and write
674000
heap
page read and write
674000
heap
page read and write
2208000
direct allocation
page read and write
2130000
direct allocation
page read and write
840000
direct allocation
page read and write
862000
direct allocation
page read and write
401000
unkown
page execute read
411000
unkown
page readonly
674000
heap
page read and write
674000
heap
page read and write
633000
unkown
page write copy
40B000
unkown
page read and write
5781000
heap
page read and write
316E000
stack
page read and write
401000
unkown
page execute read
2110000
heap
page read and write
850000
heap
page read and write
96000
stack
page read and write
21F4000
direct allocation
page read and write
400000
unkown
page readonly
674000
heap
page read and write
21FC000
direct allocation
page read and write
674000
heap
page read and write
324E000
stack
page read and write
8AE000
heap
page read and write
8E0000
heap
page read and write
674000
heap
page read and write
401000
unkown
page execute read
27E0000
heap
page read and write
8DB000
heap
page read and write
850000
direct allocation
page read and write
8DB000
heap
page read and write
401000
unkown
page execute read
674000
heap
page read and write
56C0000
trusted library allocation
page read and write
342E000
stack
page read and write
674000
heap
page read and write
9B000
stack
page read and write
58A0000
heap
page read and write
8E0000
heap
page read and write
33AF000
stack
page read and write
8E0000
heap
page read and write
36B4000
heap
page read and write
2F8F000
stack
page read and write
674000
heap
page read and write
674000
heap
page read and write
430000
heap
page read and write
674000
heap
page read and write
8A7000
heap
page read and write
499000
unkown
page read and write
2530000
direct allocation
page read and write
2210000
direct allocation
page read and write
21F8000
direct allocation
page read and write
8DB000
heap
page read and write
400000
unkown
page execute and read and write
499000
unkown
page write copy
674000
heap
page read and write
89A000
heap
page read and write
221C000
direct allocation
page read and write
2672000
heap
page read and write
23A0000
direct allocation
page read and write
21F7000
direct allocation
page read and write
2BDA000
direct allocation
page execute and read and write
8B3000
heap
page read and write
2138000
direct allocation
page read and write
988000
heap
page read and write
674000
heap
page read and write
4EE000
heap
page read and write
2629000
heap
page read and write
674000
heap
page read and write
2360000
direct allocation
page read and write
674000
heap
page read and write
8B3000
heap
page read and write
18D000
stack
page read and write
40B000
unkown
page write copy
631000
unkown
page write copy
63B000
unkown
page readonly
674000
heap
page read and write
271E000
stack
page read and write
8DB000
heap
page read and write
5781000
heap
page read and write
49B000
unkown
page read and write
674000
heap
page read and write
674000
heap
page read and write
275C000
stack
page read and write
There are 232 hidden memdumps, click here to show them.