Analysis

  • max time kernel
    15s
  • max time network
    17s
  • platform
    windows10-1703_x64
  • resource
    win10-20240404-en
  • resource tags

    arch:x64arch:x86image:win10-20240404-enlocale:en-usos:windows10-1703-x64system
  • submitted
    01-07-2024 11:10

General

  • Target

    ketamine.exe

  • Size

    25.8MB

  • MD5

    7b513480b32c6038e61413461664063c

  • SHA1

    e12e1f035da33f435ac5723e59502f2a0a4345de

  • SHA256

    b69a4fef963a0d91d405a3f2094581ef22bfe0e6aa0c67a10eb560a683f6e606

  • SHA512

    b16c36a2bf5587c8b72ec2ff56e20f3b09d1880d6592ce83f9f7442ce1705f7b553c314f2890a7fc1a47c0d0675d7836602d0600ef2627ade83432d9852d3655

  • SSDEEP

    393216:to9DM45UUDtSJurEUWjagZewBm6bjHTw6:S9N6cYdb9ZewBmUHJ

Score
7/10
upx

Malware Config

Signatures

  • Loads dropped DLL 47 IoCs
  • UPX packed file 64 IoCs

    Detects executables packed with UPX/modified UPX open source packer.

  • Looks up external IP address via web service 2 IoCs

    Uses a legitimate IP lookup service to find the infected system's external IP.

  • Suspicious behavior: EnumeratesProcesses 4 IoCs
  • Suspicious use of AdjustPrivilegeToken 43 IoCs
  • Suspicious use of WriteProcessMemory 6 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\ketamine.exe
    "C:\Users\Admin\AppData\Local\Temp\ketamine.exe"
    1⤵
    • Suspicious use of WriteProcessMemory
    PID:1768
    • C:\Users\Admin\AppData\Local\Temp\ketamine.exe
      "C:\Users\Admin\AppData\Local\Temp\ketamine.exe"
      2⤵
      • Loads dropped DLL
      • Suspicious behavior: EnumeratesProcesses
      • Suspicious use of AdjustPrivilegeToken
      • Suspicious use of WriteProcessMemory
      PID:3760
      • C:\Windows\system32\cmd.exe
        C:\Windows\system32\cmd.exe /c "C:\Windows\System32\wbem\WMIC.exe csproduct get uuid"
        3⤵
        • Suspicious use of WriteProcessMemory
        PID:4032
        • C:\Windows\System32\wbem\WMIC.exe
          C:\Windows\System32\wbem\WMIC.exe csproduct get uuid
          4⤵
          • Suspicious use of AdjustPrivilegeToken
          PID:2580

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\Users\Admin\AppData\Local\Temp\_MEI17682\Cryptodome\Cipher\_raw_cbc.pyd
    Filesize

    10KB

    MD5

    f2bf3f3cdce0e6a8a29bd7fad094736b

    SHA1

    7eb4af31b93ee38219eb31c2a867959bb7a3ec53

    SHA256

    d8a9edff4c8cbbd02cc89541cd1a9f8b1ba8381f000a86f910b4d6831bb9a034

    SHA512

    ea3dcdd0218f51bedafe9fb995d84a820d244673086f42276d7cb6c398c67f0e4f79ec343dd0a6fc0af03ae605aabbbd93c8c612cbfd7ddf641b9f8a8db13c83

  • C:\Users\Admin\AppData\Local\Temp\_MEI17682\Cryptodome\Cipher\_raw_cfb.pyd
    Filesize

    10KB

    MD5

    4d651469eff9f0a3f904fcac9b1a41d2

    SHA1

    f9eb0d3ae58b8195e2485c6c378ce84f95c9ee54

    SHA256

    1b835a8c05dcc24c77fcf21ae0091ce34aca3b6b3d153415e3f0cf0142c53f9b

    SHA512

    0c10c6a52e2fa9bdf89229ad9964cfff6f3621eaad6f3aacebbbc8da6ff742e087c79af2d2d152c433160f25a9e45a2c41e13349cba758640163832569d37cfd

  • C:\Users\Admin\AppData\Local\Temp\_MEI17682\Cryptodome\Cipher\_raw_ecb.pyd
    Filesize

    9KB

    MD5

    b47c542168546fb875e74e49c84325b6

    SHA1

    2aecab080cc0507f9380756478eadad2d3697503

    SHA256

    55657830c9ab79875af923b5a92e7ee30e0560affc3baa236c38039b4ef987f2

    SHA512

    fc25087c859c76dff1126bbfe956ea6811dc3ca79e9bbfd237893144db8b7ce3cae3aeb0923f69e0bfffa5575b5442ad1891d7088dd3857b62be12b5326be50d

  • C:\Users\Admin\AppData\Local\Temp\_MEI17682\Cryptodome\Cipher\_raw_ofb.pyd
    Filesize

    10KB

    MD5

    6315a891ea3f996fc4b5ec384841f10c

    SHA1

    ed76ef57517e35b7b721a8b1a3e1ffa7873aec57

    SHA256

    087c238e1aa9038f53f8c92e7255f7adc9cd9a60a895256962dc39a73d596382

    SHA512

    083859a84ff84e865cfc255ff1674134940c5a64cc703c4ae7815501d586005b6b6cabc28e52239ae24cd38a1253d634d8de87d98a4a65f45df2b34bc24c2483

  • C:\Users\Admin\AppData\Local\Temp\_MEI17682\VCRUNTIME140.dll
    Filesize

    116KB

    MD5

    be8dbe2dc77ebe7f88f910c61aec691a

    SHA1

    a19f08bb2b1c1de5bb61daf9f2304531321e0e40

    SHA256

    4d292623516f65c80482081e62d5dadb759dc16e851de5db24c3cbb57b87db83

    SHA512

    0da644472b374f1da449a06623983d0477405b5229e386accadb154b43b8b083ee89f07c3f04d2c0c7501ead99ad95aecaa5873ff34c5eeb833285b598d5a655

  • C:\Users\Admin\AppData\Local\Temp\_MEI17682\_asyncio.pyd
    Filesize

    37KB

    MD5

    ff0cd3ed9552d0cf747f2c1f5dcefb27

    SHA1

    3131712c460b42b6e5b0aa4b9534fbf64592bc58

    SHA256

    a181a0c2bdb9d9adb610cd188e41a03d4e61c0bea68ec0d7978658e5aa754910

    SHA512

    b0c49eef1d78c4c43da83dc0fcacc3407b1583c26e684e05d5c820b023dbf154b16c7f9844e9e9887b04db3f034e562058e7aa81ea922164bc2e110859f3455f

  • C:\Users\Admin\AppData\Local\Temp\_MEI17682\_bz2.pyd
    Filesize

    48KB

    MD5

    5cd942486b252213763679f99c920260

    SHA1

    abd370aa56b0991e4bfee065c5f34b041d494c68

    SHA256

    88087fef2cff82a3d2d2d28a75663618271803017ea8a6fcb046a23e6cbb6ac8

    SHA512

    6cd703e93ebccb0fd896d3c06ca50f8cc2e782b6cc6a7bdd12786fcfb174c2933d39ab7d8e674119faeca5903a0bfac40beffb4e3f6ca1204aaffefe1f30642c

  • C:\Users\Admin\AppData\Local\Temp\_MEI17682\_cffi_backend.cp312-win_amd64.pyd
    Filesize

    71KB

    MD5

    26624b2ea2b9ec0e6ddec72f064c181a

    SHA1

    2658bae86a266def37cce09582874c2da5c8f6fa

    SHA256

    9fcab2f71b7b58636a613043387128394e29fe6e0c7ed698abdc754ba35e6279

    SHA512

    a5315700af222cdb343086fd4a4e8a4768050fdf36e1f8041770a131fc6f45fefe806291efc1cfb383f975e123d378a029d9884244a420523fc58b8178e8571f

  • C:\Users\Admin\AppData\Local\Temp\_MEI17682\_ctypes.pyd
    Filesize

    59KB

    MD5

    4878ad72e9fbf87a1b476999ee06341e

    SHA1

    9e25424d9f0681398326252f2ae0be55f17e3540

    SHA256

    d699e09727eefe5643e0fdf4be4600a1d021af25d8a02906ebf98c2104d3735d

    SHA512

    6d465ae4a222456181441d974a5bb74d8534a39d20dca6c55825ebb0aa678e2ea0d6a6853bfa0888a7fd6be36f70181f367a0d584fccaa8daa940859578ab2b8

  • C:\Users\Admin\AppData\Local\Temp\_MEI17682\_decimal.pyd
    Filesize

    107KB

    MD5

    d60e08c4bf3be928473139fa6dcb3354

    SHA1

    e819b15b95c932d30dafd7aa4e48c2eea5eb5fcb

    SHA256

    e21b0a031d399ffb7d71c00a840255d436887cb761af918f5501c10142987b7b

    SHA512

    6cac905f58c1f25cb91ea0a307cc740575bf64557f3cd57f10ad7251865ddb88965b2ad0777089b77fc27c6d9eb9a1f87456ddf57b7d2d717664c07af49e7b58

  • C:\Users\Admin\AppData\Local\Temp\_MEI17682\_lzma.pyd
    Filesize

    86KB

    MD5

    25b96925b6b4ea5dd01f843ecf224c26

    SHA1

    69ba7c4c73c45124123a07018fa62f6f86948e81

    SHA256

    2fbc631716ffd1fd8fd3c951a1bd9ba00cc11834e856621e682799ba2ab430fd

    SHA512

    97c56ce5040fb7d5785a4245ffe08817b02926da77c79e7e665a4cfa750afdcb7d93a88104831944b1fe3262c0014970ca50a332b51030eb602bb7fb29b56ae3

  • C:\Users\Admin\AppData\Local\Temp\_MEI17682\_multiprocessing.pyd
    Filesize

    27KB

    MD5

    2fa19c90ad762614ded548166e127ea5

    SHA1

    4d2313893d7980137c56034f8f8fa7e9a8de96a6

    SHA256

    2a3d8866bd7a901ab1784cc99565e8278db567f46dce0bce96e99762dd129bec

    SHA512

    fe1bd009a63138c30dec7976f0154f8ff41bfab8ecd5d15405dd95295167eba152e7dc4ab47968bac7cd5531bdf27b6ae75b5c1f788f0a3581b368d4cab74c97

  • C:\Users\Admin\AppData\Local\Temp\_MEI17682\_overlapped.pyd
    Filesize

    33KB

    MD5

    ec59bf2a9e2da4291ea924bb86ab7362

    SHA1

    01dfdbc73bbe46f7cebd65a96d5021c0f195b81c

    SHA256

    a8a3f04ee4298f1b136d70c04d5c7aaa5785c41f9a0a23de39726ee3962fe5fd

    SHA512

    105c03d0cea327a003993e404b8479d739342d5102eabfd373ab6413049985c537c24bab3c632306b9e15bc588eda4a50fe29146dca4dcf8da5f54d06e330579

  • C:\Users\Admin\AppData\Local\Temp\_MEI17682\_sqlite3.pyd
    Filesize

    57KB

    MD5

    81a43e60fc9e56f86800d8bb920dbe58

    SHA1

    0dc3ffa0ccbc0d8be7c7cbae946257548578f181

    SHA256

    79977cbda8d6b54868d9cfc50159a2970f9b3b0f8df0ada299c3c1ecfdc6deb0

    SHA512

    d3a773f941f1a726826d70db4235f4339036ee5e67667a6c63631ff6357b69ba90b03f44fd0665210ee243c1af733c84d2694a1703ebb290f45a7e4b1fc001c7

  • C:\Users\Admin\AppData\Local\Temp\_MEI17682\_ssl.pyd
    Filesize

    66KB

    MD5

    c0512ca159b58473feadc60d3bd85654

    SHA1

    ac30797e7c71dea5101c0db1ac47d59a4bf08756

    SHA256

    66a0e06cce76b1e332278f84eda4c032b4befbd6710c7c7eb6f5e872a7b83f43

    SHA512

    3999fc4e673cf2ce9938df5850270130247f4a96c249e01258a25b125d64c42c8683a85aec64ed9799d79b50f261bcfac6ee9de81f1c5252e044d02ac372e5c4

  • C:\Users\Admin\AppData\Local\Temp\_MEI17682\_uuid.pyd
    Filesize

    25KB

    MD5

    50521b577719195d7618a23b3103d8aa

    SHA1

    7020d2e107000eaf0eddde74bc3809df2c638e22

    SHA256

    acbf831004fb8b8d5340fe5debd9814c49bd282dd765c78faeb6bb5116288c78

    SHA512

    4ee950da8bbbd36932b488ec62fa046ac8fc35783a146edadbe063b8419a63d4dfb5bbd8c45e9e008fe708e6fc4a1fee1202fce92ffc95320547ba714fed95e1

  • C:\Users\Admin\AppData\Local\Temp\_MEI17682\_wmi.pyd
    Filesize

    28KB

    MD5

    0682a42141ad8e981d839a5d0da81c55

    SHA1

    6752a15877329ff9fd62a95908a77f0daca2eed3

    SHA256

    42442d889fb51755fc4a6e528a1e015e946d3a37e932479e0f806ea738dae89c

    SHA512

    881bc77c39813274f092642edd6c52184f50f71676019e534af23c5b81e7b9a43aef08d18e503b92dbb967db395e7aa71b122670feb2f06bed0e2a72d59a4a9b

  • C:\Users\Admin\AppData\Local\Temp\_MEI17682\base_library.zip
    Filesize

    1.3MB

    MD5

    43935f81d0c08e8ab1dfe88d65af86d8

    SHA1

    abb6eae98264ee4209b81996c956a010ecf9159b

    SHA256

    c611943f0aeb3292d049437cb03500cc2f8d12f23faf55e644bca82f43679bc0

    SHA512

    06a9dcd310aa538664b08f817ec1c6cfa3f748810d76559c46878ea90796804904d41ac79535c7f63114df34c0e5de6d0452bb30df54b77118d925f21cfa1955

  • C:\Users\Admin\AppData\Local\Temp\_MEI17682\certifi\cacert.pem
    Filesize

    287KB

    MD5

    2a6bef11d1f4672f86d3321b38f81220

    SHA1

    b4146c66e7e24312882d33b16b2ee140cb764b0e

    SHA256

    1605d0d39c5e25d67e7838da6a17dcf2e8c6cfa79030e8fb0318e35f5495493c

    SHA512

    500dfff929d803b0121796e8c1a30bdfcb149318a4a4de460451e093e4cbd568cd12ab20d0294e0bfa7efbd001de968cca4c61072218441d4fa7fd9edf7236d9

  • C:\Users\Admin\AppData\Local\Temp\_MEI17682\charset_normalizer\md.cp312-win_amd64.pyd
    Filesize

    9KB

    MD5

    ea68b13d83a5c7521453120dd7bd4dfc

    SHA1

    182d77f89ceb44b524b9d53d6480343f9670fc9c

    SHA256

    c3d31f8842c002085e2d7aa43856c2297d6740f70450c2c4bf80dc1d8360cbc7

    SHA512

    41d3eddc57ee9c643ab28a6e0286cd39c2724a9d1bdf24d75d1dd3ec7900396768e6afa4702272b051627855bdcb12fac8d8834d1d1ddf1638c769c89c2b488d

  • C:\Users\Admin\AppData\Local\Temp\_MEI17682\charset_normalizer\md__mypyc.cp312-win_amd64.pyd
    Filesize

    39KB

    MD5

    4b81e1518d8fc26804b26fa0099ee5b6

    SHA1

    b152ee2d7b843b883f830e69af629a49e2909dcf

    SHA256

    f00565d8909029ce00bc04048a551975db20eb8aa39d1e4a65b7e659c0945100

    SHA512

    09ad69911959418e458cf25c972b4d14983d58c4a48ae739c31d981125442673e66d935bf9c2ea0aa8fbfa20ba4434cf9aac6e6a3b0bd776cf4e46cb80b93949

  • C:\Users\Admin\AppData\Local\Temp\_MEI17682\libssl-3.dll
    Filesize

    222KB

    MD5

    264be59ff04e5dcd1d020f16aab3c8cb

    SHA1

    2d7e186c688b34fdb4c85a3fce0beff39b15d50e

    SHA256

    358b59da9580e7102adfc1be9400acea18bc49474db26f2f8bacb4b8839ce49d

    SHA512

    9abb96549724affb2e69e5cb2c834ecea3f882f2f7392f2f8811b8b0db57c5340ab21be60f1798c7ab05f93692eb0aeab077caf7e9b7bb278ad374ff3c52d248

  • C:\Users\Admin\AppData\Local\Temp\_MEI17682\psutil\_psutil_windows.pyd
    Filesize

    31KB

    MD5

    c6b58473112940b1c51daab751ad600f

    SHA1

    f0653bbec27277efbd783a3b5fb5b2ae38ca53ae

    SHA256

    6c8d5a4ad401d3994dc8609dfd356382f3e3e1ab51225a8cad21434f9b75276a

    SHA512

    45e4ed13b924f9fb2073c4fd0f551394eefc962971e63473ab6d3b0e1dbfdf604af5591d53b92890b10904dc310ce71d12c99b6e53063f6c8c5ab1a70adcf20c

  • C:\Users\Admin\AppData\Local\Temp\_MEI17682\pyexpat.pyd
    Filesize

    88KB

    MD5

    d75d0abe353df292809535015888deb1

    SHA1

    3c1dfbc5f4ddc943cfe0fcba165fc5f269882854

    SHA256

    a9014ff4f0fc370a3a810fb82707d7d160d912c4f8998fd20c4c29547dd02299

    SHA512

    8cc4be2dbec8c27b27670e87d4ab5d2292770b0f808a7e7394189e44d46ba480057a615613445b086d9626fa8b53b0bfea8655c0e2fe6ef29ebd1baba4fce741

  • C:\Users\Admin\AppData\Local\Temp\_MEI17682\python3.DLL
    Filesize

    66KB

    MD5

    a07661c5fad97379cf6d00332999d22c

    SHA1

    dca65816a049b3cce5c4354c3819fef54c6299b0

    SHA256

    5146005c36455e7ede4b8ecc0dc6f6fa8ea6b4a99fedbabc1994ae27dfab9d1b

    SHA512

    6ddeb9d89ccb4d2ec5d994d85a55e5e2cc7af745056dae030ab8d72ee7830f672003f4675b6040f123fc64c19e9b48cabd0da78101774dafacf74a88fbd74b4d

  • C:\Users\Admin\AppData\Local\Temp\_MEI17682\python312.dll
    Filesize

    1.7MB

    MD5

    18677d48ba556e529b73d6e60afaf812

    SHA1

    68f93ed1e3425432ac639a8f0911c144f1d4c986

    SHA256

    8e2c03e1ee5068c16e61d3037a10371f2e9613221a165150008bef04474a8af8

    SHA512

    a843ab3a180684c4f5cae0240da19291e7ed9ae675c9356334386397561c527ab728d73767459350fa67624f389411d03665f69637c5f5c268011d1b103d0b02

  • C:\Users\Admin\AppData\Local\Temp\_MEI17682\sqlite3.dll
    Filesize

    644KB

    MD5

    8a6c2b015c11292de9d556b5275dc998

    SHA1

    4dcf83e3b50970374eef06b79d323a01f5364190

    SHA256

    ad9afd1225847ae694e091b833b35aa03445b637e35fb2873812db358d783f29

    SHA512

    819f4e888831524ceeed875161880a830794a748add2bf887895d682db1cec29eaddc5eddf1e90d982f4c78a9747f960d75f7a87bdda3b4f63ea2f326db05387

  • C:\Users\Admin\AppData\Local\Temp\_MEI17682\unicodedata.pyd
    Filesize

    295KB

    MD5

    3f2da3ed690327ae6b320daa82d9be27

    SHA1

    32aebd8e8e17d6b113fc8f693259eba8b6b45ea5

    SHA256

    7dc64867f466b666ff1a209b0ef92585ffb7b0cac3a87c27e6434a2d7b85594f

    SHA512

    a4e6d58477baa35100aa946dfad42ad234f8affb26585d09f91cab89bbef3143fc45307967c9dbc43749ee06e93a94d87f436f5a390301823cd09e221cac8a10

  • \Users\Admin\AppData\Local\Temp\_MEI17682\VCRUNTIME140_1.dll
    Filesize

    48KB

    MD5

    f8dfa78045620cf8a732e67d1b1eb53d

    SHA1

    ff9a604d8c99405bfdbbf4295825d3fcbc792704

    SHA256

    a113f192195f245f17389e6ecbed8005990bcb2476ddad33f7c4c6c86327afe5

    SHA512

    ba7f8b7ab0deb7a7113124c28092b543e216ca08d1cf158d9f40a326fb69f4a2511a41a59ea8482a10c9ec4ec8ac69b70dfe9ca65e525097d93b819d498da371

  • \Users\Admin\AppData\Local\Temp\_MEI17682\_hashlib.pyd
    Filesize

    35KB

    MD5

    edfb41ad93bc40757a0f0e8fdf1d0d6c

    SHA1

    155f574eef1c89fd038b544778970a30c8ab25ad

    SHA256

    09a0be93d58ce30fa7fb8503e9d0f83b10d985f821ce8a9659fd0bbc5156d81e

    SHA512

    3ba7d225828b37a141ed2232e892dad389147ca4941a1a85057f04c0ed6c0eab47b427bd749c565863f2d6f3a11f3eb34b6ee93506dee92ec56d7854e3392b10

  • \Users\Admin\AppData\Local\Temp\_MEI17682\_queue.pyd
    Filesize

    26KB

    MD5

    c2ba2b78e35b0ab037b5f969549e26ac

    SHA1

    cb222117dda9d9b711834459e52c75d1b86cbb6e

    SHA256

    d8b60222732bdcedddbf026f96bddda028c54f6ae6b71f169a4d0c35bc911846

    SHA512

    da2bf31eb6fc87a606cbaa53148407e9368a6c3324648cb3df026a4fe06201bbaab1b0e1a6735d1f1d3b90ea66f5a38d47daac9686520127e993ecb02714181f

  • \Users\Admin\AppData\Local\Temp\_MEI17682\_socket.pyd
    Filesize

    44KB

    MD5

    aa8435614d30cee187af268f8b5d394b

    SHA1

    6e218f3ad8ac48a1dde6b3c46ff463659a22a44e

    SHA256

    5427daade880df81169245ea2d2cc68355d34dbe907bc8c067975f805d062047

    SHA512

    3ccf7ec281c1dc68f782a39f339e191a251c9a92f6dc2df8df865e1d7796cf32b004ea8a2de96fe75fa668638341786eb515bac813f59a0d454fc91206fee632

  • \Users\Admin\AppData\Local\Temp\_MEI17682\libcrypto-3.dll
    Filesize

    1.6MB

    MD5

    7f1b899d2015164ab951d04ebb91e9ac

    SHA1

    1223986c8a1cbb57ef1725175986e15018cc9eab

    SHA256

    41201d2f29cf3bc16bf32c8cecf3b89e82fec3e5572eb38a578ae0fb0c5a2986

    SHA512

    ca227b6f998cacca3eb6a8f18d63f8f18633ab4b8464fb8b47caa010687a64516181ad0701c794d6bfe3f153662ea94779b4f70a5a5a94bb3066d8a011b4310d

  • \Users\Admin\AppData\Local\Temp\_MEI17682\libffi-8.dll
    Filesize

    29KB

    MD5

    08b000c3d990bc018fcb91a1e175e06e

    SHA1

    bd0ce09bb3414d11c91316113c2becfff0862d0d

    SHA256

    135c772b42ba6353757a4d076ce03dbf792456143b42d25a62066da46144fece

    SHA512

    8820d297aeda5a5ebe1306e7664f7a95421751db60d71dc20da251bcdfdc73f3fd0b22546bd62e62d7aa44dfe702e4032fe78802fb16ee6c2583d65abc891cbf

  • \Users\Admin\AppData\Local\Temp\_MEI17682\select.pyd
    Filesize

    25KB

    MD5

    f5540323c6bb870b3a94e1b3442e597b

    SHA1

    2581887ffc43fa4a6cbd47f5d4745152ce40a5a7

    SHA256

    b3ff47c71e1023368e94314b6d371e01328dae9f6405398c72639129b89a48d2

    SHA512

    56ee1da2fb604ef9f30eca33163e3f286540d3f738ed7105fc70a2bccef7163e0e5afd0aeb68caf979d9493cd5a6a286e6943f6cd59c8e18902657807aa652e3

  • memory/3760-190-0x00007FFFF44A0000-0x00007FFFF44AC000-memory.dmp
    Filesize

    48KB

  • memory/3760-208-0x00007FFFE5910000-0x00007FFFE5B55000-memory.dmp
    Filesize

    2.3MB

  • memory/3760-113-0x00007FFFF8950000-0x00007FFFF8975000-memory.dmp
    Filesize

    148KB

  • memory/3760-155-0x00007FFFF5020000-0x00007FFFF50ED000-memory.dmp
    Filesize

    820KB

  • memory/3760-154-0x00007FFFF5E70000-0x00007FFFF5EA3000-memory.dmp
    Filesize

    204KB

  • memory/3760-159-0x00007FFFF5AA0000-0x00007FFFF5AB2000-memory.dmp
    Filesize

    72KB

  • memory/3760-158-0x00007FFFF5AC0000-0x00007FFFF5AD6000-memory.dmp
    Filesize

    88KB

  • memory/3760-162-0x00007FFFF5650000-0x00007FFFF5686000-memory.dmp
    Filesize

    216KB

  • memory/3760-166-0x00007FFFF3AB0000-0x00007FFFF3C2F000-memory.dmp
    Filesize

    1.5MB

  • memory/3760-165-0x00007FFFF4FF0000-0x00007FFFF5014000-memory.dmp
    Filesize

    144KB

  • memory/3760-161-0x00007FFFE5D40000-0x00007FFFE6404000-memory.dmp
    Filesize

    6.8MB

  • memory/3760-137-0x00007FFFF8500000-0x00007FFFF851A000-memory.dmp
    Filesize

    104KB

  • memory/3760-169-0x00007FFFF4FD0000-0x00007FFFF4FE8000-memory.dmp
    Filesize

    96KB

  • memory/3760-138-0x00007FFFF84D0000-0x00007FFFF84FD000-memory.dmp
    Filesize

    180KB

  • memory/3760-173-0x00007FFFF84C0000-0x00007FFFF84CF000-memory.dmp
    Filesize

    60KB

  • memory/3760-174-0x00007FFFF5640000-0x00007FFFF564B000-memory.dmp
    Filesize

    44KB

  • memory/3760-141-0x00007FFFF84C0000-0x00007FFFF84CF000-memory.dmp
    Filesize

    60KB

  • memory/3760-176-0x00007FFFF44D0000-0x00007FFFF44F7000-memory.dmp
    Filesize

    156KB

  • memory/3760-178-0x00007FFFF36A0000-0x00007FFFF37BB000-memory.dmp
    Filesize

    1.1MB

  • memory/3760-144-0x00007FFFF8490000-0x00007FFFF84A9000-memory.dmp
    Filesize

    100KB

  • memory/3760-151-0x00007FFFF50F0000-0x00007FFFF5619000-memory.dmp
    Filesize

    5.2MB

  • memory/3760-150-0x00007FFFF8450000-0x00007FFFF8464000-memory.dmp
    Filesize

    80KB

  • memory/3760-183-0x00007FFFF8450000-0x00007FFFF8464000-memory.dmp
    Filesize

    80KB

  • memory/3760-146-0x00007FFFF8480000-0x00007FFFF848D000-memory.dmp
    Filesize

    52KB

  • memory/3760-147-0x00007FFFF8470000-0x00007FFFF847D000-memory.dmp
    Filesize

    52KB

  • memory/3760-188-0x00007FFFF50F0000-0x00007FFFF5619000-memory.dmp
    Filesize

    5.2MB

  • memory/3760-191-0x00007FFFF4490000-0x00007FFFF449B000-memory.dmp
    Filesize

    44KB

  • memory/3760-103-0x00007FFFE5D40000-0x00007FFFE6404000-memory.dmp
    Filesize

    6.8MB

  • memory/3760-189-0x00007FFFF44C0000-0x00007FFFF44CB000-memory.dmp
    Filesize

    44KB

  • memory/3760-193-0x00007FFFF3690000-0x00007FFFF369B000-memory.dmp
    Filesize

    44KB

  • memory/3760-197-0x00007FFFF5E70000-0x00007FFFF5EA3000-memory.dmp
    Filesize

    204KB

  • memory/3760-200-0x00007FFFF3650000-0x00007FFFF365C000-memory.dmp
    Filesize

    48KB

  • memory/3760-199-0x00007FFFF3660000-0x00007FFFF366E000-memory.dmp
    Filesize

    56KB

  • memory/3760-198-0x00007FFFF5020000-0x00007FFFF50ED000-memory.dmp
    Filesize

    820KB

  • memory/3760-196-0x00007FFFF44B0000-0x00007FFFF44BB000-memory.dmp
    Filesize

    44KB

  • memory/3760-195-0x00007FFFF3670000-0x00007FFFF367C000-memory.dmp
    Filesize

    48KB

  • memory/3760-194-0x00007FFFF3680000-0x00007FFFF368C000-memory.dmp
    Filesize

    48KB

  • memory/3760-192-0x00007FFFF3AA0000-0x00007FFFF3AAC000-memory.dmp
    Filesize

    48KB

  • memory/3760-207-0x00007FFFF34F0000-0x00007FFFF34FC000-memory.dmp
    Filesize

    48KB

  • memory/3760-206-0x00007FFFF3500000-0x00007FFFF3512000-memory.dmp
    Filesize

    72KB

  • memory/3760-205-0x00007FFFF3520000-0x00007FFFF352D000-memory.dmp
    Filesize

    52KB

  • memory/3760-204-0x00007FFFF3530000-0x00007FFFF353C000-memory.dmp
    Filesize

    48KB

  • memory/3760-203-0x00007FFFF3540000-0x00007FFFF354C000-memory.dmp
    Filesize

    48KB

  • memory/3760-202-0x00007FFFF3630000-0x00007FFFF363B000-memory.dmp
    Filesize

    44KB

  • memory/3760-201-0x00007FFFF3640000-0x00007FFFF364B000-memory.dmp
    Filesize

    44KB

  • memory/3760-114-0x00007FFFF8F90000-0x00007FFFF8F9F000-memory.dmp
    Filesize

    60KB

  • memory/3760-211-0x00007FFFF18C0000-0x00007FFFF18EE000-memory.dmp
    Filesize

    184KB

  • memory/3760-210-0x00007FFFF34B0000-0x00007FFFF34D9000-memory.dmp
    Filesize

    164KB

  • memory/3760-212-0x00007FFFE5D40000-0x00007FFFE6404000-memory.dmp
    Filesize

    6.8MB

  • memory/3760-242-0x00007FFFF8F90000-0x00007FFFF8F9F000-memory.dmp
    Filesize

    60KB

  • memory/3760-241-0x00007FFFF8950000-0x00007FFFF8975000-memory.dmp
    Filesize

    148KB

  • memory/3760-243-0x00007FFFF3660000-0x00007FFFF366E000-memory.dmp
    Filesize

    56KB

  • memory/3760-256-0x00007FFFF18C0000-0x00007FFFF18EE000-memory.dmp
    Filesize

    184KB

  • memory/3760-255-0x00007FFFF34B0000-0x00007FFFF34D9000-memory.dmp
    Filesize

    164KB

  • memory/3760-254-0x00007FFFE5910000-0x00007FFFE5B55000-memory.dmp
    Filesize

    2.3MB

  • memory/3760-253-0x00007FFFF34F0000-0x00007FFFF34FC000-memory.dmp
    Filesize

    48KB

  • memory/3760-252-0x00007FFFF3500000-0x00007FFFF3512000-memory.dmp
    Filesize

    72KB

  • memory/3760-251-0x00007FFFF3520000-0x00007FFFF352D000-memory.dmp
    Filesize

    52KB

  • memory/3760-250-0x00007FFFF3530000-0x00007FFFF353C000-memory.dmp
    Filesize

    48KB

  • memory/3760-249-0x00007FFFF3540000-0x00007FFFF354C000-memory.dmp
    Filesize

    48KB

  • memory/3760-248-0x00007FFFF3630000-0x00007FFFF363B000-memory.dmp
    Filesize

    44KB

  • memory/3760-247-0x00007FFFF3640000-0x00007FFFF364B000-memory.dmp
    Filesize

    44KB

  • memory/3760-246-0x00007FFFF3670000-0x00007FFFF367C000-memory.dmp
    Filesize

    48KB

  • memory/3760-245-0x00007FFFF3680000-0x00007FFFF368C000-memory.dmp
    Filesize

    48KB

  • memory/3760-244-0x00007FFFF3650000-0x00007FFFF365C000-memory.dmp
    Filesize

    48KB

  • memory/3760-240-0x00007FFFF5AA0000-0x00007FFFF5AB2000-memory.dmp
    Filesize

    72KB

  • memory/3760-239-0x00007FFFF3690000-0x00007FFFF369B000-memory.dmp
    Filesize

    44KB

  • memory/3760-238-0x00007FFFF3AA0000-0x00007FFFF3AAC000-memory.dmp
    Filesize

    48KB

  • memory/3760-237-0x00007FFFF4490000-0x00007FFFF449B000-memory.dmp
    Filesize

    44KB

  • memory/3760-236-0x00007FFFF44A0000-0x00007FFFF44AC000-memory.dmp
    Filesize

    48KB

  • memory/3760-235-0x00007FFFF44B0000-0x00007FFFF44BB000-memory.dmp
    Filesize

    44KB

  • memory/3760-234-0x00007FFFF44C0000-0x00007FFFF44CB000-memory.dmp
    Filesize

    44KB

  • memory/3760-233-0x00007FFFF36A0000-0x00007FFFF37BB000-memory.dmp
    Filesize

    1.1MB

  • memory/3760-232-0x00007FFFF44D0000-0x00007FFFF44F7000-memory.dmp
    Filesize

    156KB

  • memory/3760-231-0x00007FFFF5640000-0x00007FFFF564B000-memory.dmp
    Filesize

    44KB

  • memory/3760-230-0x00007FFFF4FD0000-0x00007FFFF4FE8000-memory.dmp
    Filesize

    96KB

  • memory/3760-229-0x00007FFFF3AB0000-0x00007FFFF3C2F000-memory.dmp
    Filesize

    1.5MB

  • memory/3760-228-0x00007FFFF4FF0000-0x00007FFFF5014000-memory.dmp
    Filesize

    144KB

  • memory/3760-227-0x00007FFFF5650000-0x00007FFFF5686000-memory.dmp
    Filesize

    216KB

  • memory/3760-225-0x00007FFFF5AC0000-0x00007FFFF5AD6000-memory.dmp
    Filesize

    88KB

  • memory/3760-224-0x00007FFFF5020000-0x00007FFFF50ED000-memory.dmp
    Filesize

    820KB

  • memory/3760-223-0x00007FFFF5E70000-0x00007FFFF5EA3000-memory.dmp
    Filesize

    204KB

  • memory/3760-222-0x00007FFFF50F0000-0x00007FFFF5619000-memory.dmp
    Filesize

    5.2MB

  • memory/3760-221-0x00007FFFF8450000-0x00007FFFF8464000-memory.dmp
    Filesize

    80KB

  • memory/3760-220-0x00007FFFF8470000-0x00007FFFF847D000-memory.dmp
    Filesize

    52KB

  • memory/3760-219-0x00007FFFF8480000-0x00007FFFF848D000-memory.dmp
    Filesize

    52KB

  • memory/3760-218-0x00007FFFF8490000-0x00007FFFF84A9000-memory.dmp
    Filesize

    100KB

  • memory/3760-217-0x00007FFFF84C0000-0x00007FFFF84CF000-memory.dmp
    Filesize

    60KB

  • memory/3760-216-0x00007FFFF84D0000-0x00007FFFF84FD000-memory.dmp
    Filesize

    180KB

  • memory/3760-215-0x00007FFFF8500000-0x00007FFFF851A000-memory.dmp
    Filesize

    104KB