14AFA233000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3022779938.0000014AFA233000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA233000
|
Size: |
4096
|
|
25B92A41000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2622296717.0000025B92A41000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92A41000
|
Size: |
4096
|
|
1C610EE0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2869079537.000001C610EE0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610EE0000
|
Size: |
8192
|
|
14AFA3B9000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3378202121.0000014AFA3B9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA3B9000
|
Size: |
4096
|
|
25B92A6D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2614927663.0000025B92A6D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92A6D000
|
Size: |
4096
|
|
25B92AEE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2614377874.0000025B92AEE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AEE000
|
Size: |
135168
|
|
14AF6A1D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2987566086.0000014AF6A1D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6A1D000
|
Size: |
8192
|
|
14AFA58A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3889368368.0000014AFA58A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA58A000
|
Size: |
8192
|
|
14AFA2EA000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3882037559.0000014AFA2EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA2EA000
|
Size: |
4096
|
|
7FE16000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2593051763.000000007FE16000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
7FE16000
|
Size: |
208896
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
25B92ADB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2615607051.0000025B92ADB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92ADB000
|
Size: |
36864
|
|
25B92AF7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2615607051.0000025B92AF7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AF7000
|
Size: |
12288
|
|
14AF6F7B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3877141298.0000014AF6F7B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6F7B000
|
Size: |
20480
|
|
23FDF8F8000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3864380329.0000023FDF8F8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDF8F8000
|
Size: |
16384
|
|
14AF4720000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2983276679.0000014AF4720000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF4720000
|
Size: |
16384
|
|
1C610DFB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2865850100.000001C610DFB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610DFB000
|
Size: |
57344
|
|
25B9365C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2619127902.0000025B9365C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B9365C000
|
Size: |
8192
|
|
58C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2974810528.00000000058C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
58C1000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
12D9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2618528609.00000000012D9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12D9000
|
Size: |
4096
|
|
14AFA21F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3878988876.0000014AFA21F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA21F000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
23FDF8BA000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3860959703.0000023FDF8BA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDF8BA000
|
Size: |
36864
|
|
25B92A71000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2614927663.0000025B92A71000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92A71000
|
Size: |
69632
|
|
1C610BE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2827718509.000001C610BE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610BE4000
|
Size: |
24576
|
|
14AFA2F4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3263766967.0000014AFA2F4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA2F4000
|
Size: |
204800
|
|
14AFA41E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3884951730.0000014AFA41E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA41E000
|
Size: |
28672
|
|
22EF000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3002450710.00000000022EF000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
22EF000
|
Size: |
4096
|
|
1C60EDAF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2861872465.000001C60EDAF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C60EDAF000
|
Size: |
4096
|
|
3788000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2979434887.0000000003788000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3788000
|
Size: |
8192
|
|
7458A7F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3845534263.0000007458A7F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7458A7F000
|
Size: |
4096
|
|
14AFA35B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3270831776.0000014AFA35B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA35B000
|
Size: |
8192
|
|
14AFA49E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3768824745.0000014AFA49E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA49E000
|
Size: |
4096
|
|
14AFA235000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3878988876.0000014AFA235000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA235000
|
Size: |
16384
|
|
14AFA43F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3367743010.0000014AFA43F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA43F000
|
Size: |
8192
|
|
23C31C6C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3851976269.0000023C31C6C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23C31C6C000
|
Size: |
65536
|
|
14AF671C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2982424778.0000014AF671C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF671C000
|
Size: |
8192
|
|
65F0FF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3845837109.000000065F0FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
65F0FF000
|
Size: |
4096
|
|
2592000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2982522590.0000000002592000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2592000
|
Size: |
28672
|
|
14AFA40D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3884951730.0000014AFA40D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA40D000
|
Size: |
8192
|
|
9AE54FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2861468221.0000009AE54FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9AE54FE000
|
Size: |
8192
|
|
14AFA22E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3271104935.0000014AFA22E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA22E000
|
Size: |
122880
|
|
14AFA270000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3018239583.0000014AFA270000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA270000
|
Size: |
143360
|
|
14AFA1A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3878793284.0000014AFA1A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
14AFA1A0000
|
Size: |
4096
|
|
59B9BFB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3844615131.00000059B9BFB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
59B9BFB000
|
Size: |
20480
|
|
14AF6F9C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3877141298.0000014AF6F9C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6F9C000
|
Size: |
57344
|
|
14AF6A5C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2994786907.0000014AF6A5C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6A5C000
|
Size: |
2134016
|
|
23FE3AC0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3865398292.0000023FE3AC0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23FE3AC0000
|
Size: |
4096
|
|
2328000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3002450710.0000000002328000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2328000
|
Size: |
4096
|
|
14AFA261000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3376079948.0000014AFA261000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA261000
|
Size: |
81920
|
|
23FE3B70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3865497268.0000023FE3B70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23FE3B70000
|
Size: |
4096
|
|
23FE3AA8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3605034546.0000023FE3AA8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23FE3AA8000
|
Size: |
28672
|
|
25B935F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2619475747.0000025B935F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B935F0000
|
Size: |
4096
|
|
8E2000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2873032443.00000000008E2000.00000004.00000001.01000000.00000009.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
8E2000
|
Size: |
8192
|
|
9F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2993782755.00000000009F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9F0000
|
Size: |
4096
|
|
14AFA29B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3880400710.0000014AFA29B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA29B000
|
Size: |
4096
|
|
1C610C31000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2826999647.000001C610C31000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610C31000
|
Size: |
4096
|
|
7FB30000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2593051763.000000007FB30000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
7FB30000
|
Size: |
3031040
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
23FDF902000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3864380329.0000023FDF902000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDF902000
|
Size: |
28672
|
|
14AFA2F2000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3764667833.0000014AFA2F2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA2F2000
|
Size: |
4096
|
|
CD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2618349257.0000000000CD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CD0000
|
Size: |
4096
|
|
25B93644000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2619627883.0000025B93644000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B93644000
|
Size: |
4096
|
|
14AF69EF000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3869220124.0000014AF69EF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF69EF000
|
Size: |
110592
|
|
14AFA2FC000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3764667833.0000014AFA2FC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA2FC000
|
Size: |
20480
|
|
7458D7E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3846174216.0000007458D7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7458D7E000
|
Size: |
8192
|
|
14AFA3D3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3774034901.0000014AFA3D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA3D3000
|
Size: |
4096
|
|
14AFA2FC000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3370386257.0000014AFA2FC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA2FC000
|
Size: |
20480
|
|
14AF6D4D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3874939422.0000014AF6D4D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D4D000
|
Size: |
8192
|
|
2F09000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2618859366.0000000002F09000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F09000
|
Size: |
24576
|
|
9EF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2993734082.00000000009EF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9EF000
|
Size: |
4096
|
|
1C60ED6D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2861872465.000001C60ED6D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C60ED6D000
|
Size: |
253952
|
|
14AF6714000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3859631789.0000014AF6714000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6714000
|
Size: |
20480
|
|
7FF62CF11000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.2821853231.00007FF62CF11000.00000002.00000001.01000000.0000000A.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF62CF11000
|
Size: |
479232
|
|
14AF6F9C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3543888438.0000014AF6F9C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6F9C000
|
Size: |
57344
|
|
23FDE270000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3848651000.0000023FDE270000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDE270000
|
Size: |
4096
|
|
C7BD57E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3847509089.000000C7BD57E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C7BD57E000
|
Size: |
8192
|
|
9AE4FFD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2861204664.0000009AE4FFD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9AE4FFD000
|
Size: |
12288
|
|
58B9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2974860767.00000000058B9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
58B9000
|
Size: |
4096
|
|
58BC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2999444832.00000000058BC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
58BC000
|
Size: |
8192
|
|
14AFA413000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3768824745.0000014AFA413000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA413000
|
Size: |
4096
|
|
C7BD97E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3848160334.000000C7BD97E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C7BD97E000
|
Size: |
8192
|
|
14AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2618701544.00000000014AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
14AE000
|
Size: |
8192
|
|
14AFA51E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3366647948.0000014AFA51E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA51E000
|
Size: |
86016
|
|
14AF6CCE000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3874409388.0000014AF6CCE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6CCE000
|
Size: |
4096
|
|
3300000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2619173467.0000000003300000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3300000
|
Size: |
4096
|
|
1C610F01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2832860330.000001C610F01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610F01000
|
Size: |
1310720
|
|
1390000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2873363687.0000000001390000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1390000
|
Size: |
20480
|
|
B14000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2974959768.0000000000B14000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B14000
|
Size: |
12288
|
|
322F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.2614380488.000000000322F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
322F000
|
Size: |
4096
|
|
23C31A20000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3847101041.0000023C31A20000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23C31A20000
|
Size: |
4096
|
|
9C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3006217864.000000000009C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9C000
|
Size: |
16384
|
|
65EDFE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3845544748.000000065EDFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
65EDFE000
|
Size: |
8192
|
|
7FF62CF8A000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.2821853231.00007FF62CF8A000.00000002.00000001.01000000.0000000A.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF62CF8A000
|
Size: |
557056
|
|
14AFA50A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3366647948.0000014AFA50A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA50A000
|
Size: |
40960
|
|
14AFA451000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3378423313.0000014AFA451000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA451000
|
Size: |
4096
|
|
2570000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2592168834.0000000002570000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2570000
|
Size: |
950272
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
25B933C4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2617078257.0000025B933C4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B933C4000
|
Size: |
24576
|
|
14AF6725000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3859631789.0000014AF6725000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6725000
|
Size: |
118784
|
|
7FF62C9A1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000009.00000000.2800651942.00007FF62C9A1000.00000020.00000001.01000000.0000000A.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF62C9A1000
|
Size: |
925696
|
|
324B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.2616337638.000000000324B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
324B000
|
Size: |
24576
|
|
1C610EF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2832547758.000001C610EF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610EF4000
|
Size: |
16384
|
|
14AFA1F0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3878919191.0000014AFA1F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA1F0000
|
Size: |
4096
|
|
14AFA208000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3022779938.0000014AFA208000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA208000
|
Size: |
69632
|
|
1A37728E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3850810912.000001A37728E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A37728E000
|
Size: |
8192
|
|
1A377318000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3853166848.000001A377318000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A377318000
|
Size: |
16384
|
|
7FF62CEFF000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2872368686.00007FF62CEFF000.00000004.00000001.01000000.0000000A.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF62CEFF000
|
Size: |
32768
|
|
25B92AF5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2615607051.0000025B92AF5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AF5000
|
Size: |
4096
|
|
1C610EFF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2832547758.000001C610EFF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610EFF000
|
Size: |
8192
|
|
14AFA5AB000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3758288615.0000014AFA5AB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA5AB000
|
Size: |
98304
|
|
AAC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2987248644.0000000000AAC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AAC000
|
Size: |
4096
|
|
677847E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2621997752.000000677847E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
677847E000
|
Size: |
8192
|
|
14AF6781000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3003933977.0000014AF6781000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6781000
|
Size: |
4096
|
|
25B92B09000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2615607051.0000025B92B09000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92B09000
|
Size: |
24576
|
|
14AFA54B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3768824745.0000014AFA54B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA54B000
|
Size: |
4096
|
|
3100000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2618985553.0000000003100000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3100000
|
Size: |
8192
|
|
14AF67FA000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3863448666.0000014AF67FA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF67FA000
|
Size: |
122880
|
|
25B92ACB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2615607051.0000025B92ACB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92ACB000
|
Size: |
32768
|
|
9AE53FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2861415292.0000009AE53FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9AE53FE000
|
Size: |
8192
|
|
25B92AB5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2615607051.0000025B92AB5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AB5000
|
Size: |
40960
|
|
C7BDB7F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3848549502.000000C7BDB7F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C7BDB7F000
|
Size: |
4096
|
|
2861000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3000038312.0000000002861000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2861000
|
Size: |
4096
|
|
AC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2995563752.0000000000AC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AC0000
|
Size: |
40960
|
|
14AFA3C0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3884063493.0000014AFA3C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA3C0000
|
Size: |
12288
|
|
14AF9E40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3427280424.0000014AF9E40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
14AF9E40000
|
Size: |
155648
|
|
14AF6880000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3863448666.0000014AF6880000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6880000
|
Size: |
4096
|
|
4B7000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.2588720116.00000000004B7000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
4B7000
|
Size: |
16384
|
|
23FDF460000
|
trusted library section
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.3859846053.0000023FDF460000.00000002.08000000.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page readonly
|
Base address: |
23FDF460000
|
Size: |
4096
|
|
14AFA34F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3370386257.0000014AFA34F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA34F000
|
Size: |
4096
|
|
14AFA2D0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3370386257.0000014AFA2D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA2D0000
|
Size: |
40960
|
|
65EEFF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3845655358.000000065EEFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
65EEFF000
|
Size: |
4096
|
|
14AFA345000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3764667833.0000014AFA345000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA345000
|
Size: |
12288
|
|
23FDF854000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3860541877.0000023FDF854000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDF854000
|
Size: |
4096
|
|
14AFA5C3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3757527512.0000014AFA5C3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA5C3000
|
Size: |
28672
|
|
59B9EFF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3845644287.00000059B9EFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
59B9EFF000
|
Size: |
4096
|
|
1A37726F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3850810912.000001A37726F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A37726F000
|
Size: |
122880
|
|
C7BD17E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3846606225.000000C7BD17E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C7BD17E000
|
Size: |
8192
|
|
14AFA4F2000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3758288615.0000014AFA4F2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA4F2000
|
Size: |
188416
|
|
A86000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2975546779.0000000000A86000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A86000
|
Size: |
212992
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
9AE52FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2861368555.0000009AE52FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9AE52FE000
|
Size: |
8192
|
|
1C610C25000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2835287498.000001C610C25000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610C25000
|
Size: |
4096
|
|
1C611520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2845181926.000001C611520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1C611520000
|
Size: |
65536
|
|
14AFA219000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3774222782.0000014AFA219000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA219000
|
Size: |
12288
|
|
14AFA346000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3022779938.0000014AFA346000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA346000
|
Size: |
4096
|
|
23FE3C00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3604924601.0000023FE3C00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23FE3C00000
|
Size: |
4096
|
|
150D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2873893392.000000000150D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
150D000
|
Size: |
12288
|
|
14AF6A19000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2989846467.0000014AF6A19000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6A19000
|
Size: |
16384
|
|
14AF6D92000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3876793087.0000014AF6D92000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D92000
|
Size: |
16384
|
|
1C610F40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2837064403.000001C610F40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610F40000
|
Size: |
909312
|
|
25B92AA1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2617118097.0000025B92AA1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AA1000
|
Size: |
16384
|
|
25B92AAC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2614377874.0000025B92AAC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AAC000
|
Size: |
57344
|
|
14AFA5EE000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3890223901.0000014AFA5EE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA5EE000
|
Size: |
16384
|
|
23FDF8FF000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3864380329.0000023FDF8FF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDF8FF000
|
Size: |
8192
|
|
677877D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2622213835.000000677877D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
677877D000
|
Size: |
12288
|
|
23FE3AE4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3605034546.0000023FE3AE4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23FE3AE4000
|
Size: |
28672
|
|
14AFA4F3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3367333289.0000014AFA4F3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA4F3000
|
Size: |
4096
|
|
23FDED02000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3859071445.0000023FDED02000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDED02000
|
Size: |
32768
|
|
14AFA42C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3768824745.0000014AFA42C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA42C000
|
Size: |
4096
|
|
14AFA3D9000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3370386257.0000014AFA3D9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA3D9000
|
Size: |
81920
|
|
14AF6D60000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3769746035.0000014AF6D60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D60000
|
Size: |
8192
|
|
14AFA35E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3883304507.0000014AFA35E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA35E000
|
Size: |
4096
|
|
1A377243000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3849149940.000001A377243000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A377243000
|
Size: |
81920
|
|
3780000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2979434887.0000000003780000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3780000
|
Size: |
4096
|
|
7FF62CEF7000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2872368686.00007FF62CEF7000.00000004.00000001.01000000.0000000A.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF62CEF7000
|
Size: |
4096
|
|
25B92AD6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2617118097.0000025B92AD6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AD6000
|
Size: |
8192
|
|
25B9364B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2619153044.0000025B9364B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B9364B000
|
Size: |
16384
|
|
65FEFD000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3849236122.000000065FEFD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
65FEFD000
|
Size: |
12288
|
|
14AFA4A0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3886934188.0000014AFA4A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA4A0000
|
Size: |
4096
|
|
23FE3BD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3865647915.0000023FE3BD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23FE3BD0000
|
Size: |
4096
|
|
14AF6CEE000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3874409388.0000014AF6CEE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6CEE000
|
Size: |
4096
|
|
14AFA4B2000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3886934188.0000014AFA4B2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA4B2000
|
Size: |
4096
|
|
23FDEC15000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3858981004.0000023FDEC15000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDEC15000
|
Size: |
4096
|
|
14AF6879000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2985383781.0000014AF6879000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6879000
|
Size: |
16384
|
|
7FDB0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2720733813.000000007FDB0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
7FDB0000
|
Size: |
610304
|
|
23FDF87D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3860959703.0000023FDF87D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDF87D000
|
Size: |
172032
|
|
14AFA2BA000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3018239583.0000014AFA2BA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA2BA000
|
Size: |
126976
|
|
14AFA5C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3889368368.0000014AFA5C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA5C1000
|
Size: |
4096
|
|
23FE3AD7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3605034546.0000023FE3AD7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23FE3AD7000
|
Size: |
49152
|
|
2E50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2618806520.0000000002E50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E50000
|
Size: |
4096
|
|
1C610BB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2864102015.000001C610BB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610BB0000
|
Size: |
221184
|
|
25B92AE2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2617118097.0000025B92AE2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AE2000
|
Size: |
8192
|
|
1A3771F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3846417693.000001A3771F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1A3771F0000
|
Size: |
4096
|
|
14AFA3E0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3884951730.0000014AFA3E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA3E0000
|
Size: |
8192
|
|
58C2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2974584235.00000000058C2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
58C2000
|
Size: |
94208
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1C61115C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2851709549.000001C61115C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C61115C000
|
Size: |
524288
|
|
14AFA275000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3375292147.0000014AFA275000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA275000
|
Size: |
12288
|
|
A9F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2995130497.0000000000A9F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A9F000
|
Size: |
8192
|
|
14AFA516000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3366647948.0000014AFA516000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA516000
|
Size: |
4096
|
|
14AFA262000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3880267392.0000014AFA262000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA262000
|
Size: |
8192
|
|
12D9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.2617490056.00000000012D9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12D9000
|
Size: |
4096
|
|
14AF4649000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3850235690.0000014AF4649000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF4649000
|
Size: |
73728
|
|
14AFA2C6000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3880400710.0000014AFA2C6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA2C6000
|
Size: |
8192
|
|
14AFA324000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3370386257.0000014AFA324000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA324000
|
Size: |
61440
|
|
14AF691C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3863448666.0000014AF691C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF691C000
|
Size: |
57344
|
|
14AF6F70000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3877141298.0000014AF6F70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6F70000
|
Size: |
32768
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
25B92A87000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2620425975.0000025B92A87000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92A87000
|
Size: |
69632
|
|
14AFA632000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3756605551.0000014AFA632000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA632000
|
Size: |
8192
|
|
14AFA3D3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3758288615.0000014AFA3D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA3D3000
|
Size: |
16384
|
|
23FDE422000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3850050123.0000023FDE422000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDE422000
|
Size: |
32768
|
|
23FDE3E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3848998668.0000023FDE3E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23FDE3E0000
|
Size: |
4096
|
|
1C610C05000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2864102015.000001C610C05000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610C05000
|
Size: |
16384
|
|
1A377213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3847312110.000001A377213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A377213000
|
Size: |
86016
|
|
14AF6789000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3003933977.0000014AF6789000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6789000
|
Size: |
4096
|
|
14AF6D9E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3022671062.0000014AF6D9E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D9E000
|
Size: |
24576
|
|
14AF6A8C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3869220124.0000014AF6A8C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6A8C000
|
Size: |
90112
|
|
3200000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2619016699.0000000003200000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3200000
|
Size: |
4096
|
|
14AFA222000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3878988876.0000014AFA222000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA222000
|
Size: |
8192
|
|
14AFA4A5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3758288615.0000014AFA4A5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA4A5000
|
Size: |
8192
|
|
DF0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3845195154.0000000000DF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DF0000
|
Size: |
4096
|
|
14AF46E4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2987642469.0000014AF46E4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF46E4000
|
Size: |
270336
|
|
14AFA327000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3764667833.0000014AFA327000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA327000
|
Size: |
49152
|
|
14AFA60F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3542348616.0000014AFA60F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA60F000
|
Size: |
12288
|
|
14AFA474000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3375759313.0000014AFA474000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA474000
|
Size: |
4096
|
|
14AFA290000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3880400710.0000014AFA290000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA290000
|
Size: |
4096
|
|
14AF6DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3769746035.0000014AF6DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6DA4000
|
Size: |
28672
|
|
23FDF8F1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3864287929.0000023FDF8F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDF8F1000
|
Size: |
12288
|
|
23FDE400000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3849237567.0000023FDE400000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDE400000
|
Size: |
73728
|
|
14AFA3AC000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3370386257.0000014AFA3AC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA3AC000
|
Size: |
151552
|
|
7FF62BFA0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.2800604531.00007FF62BFA0000.00000002.00000001.01000000.0000000A.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF62BFA0000
|
Size: |
4096
|
|
23FDE47B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3853707315.0000023FDE47B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDE47B000
|
Size: |
12288
|
|
C7BDA7B000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3848306728.000000C7BDA7B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C7BDA7B000
|
Size: |
20480
|
|
14AF6D3F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3769746035.0000014AF6D3F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D3F000
|
Size: |
8192
|
|
20000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2990089209.0000000000020000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
20000
|
Size: |
8192
|
|
65FDFC000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3849020252.000000065FDFC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
65FDFC000
|
Size: |
16384
|
|
AB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2995130497.0000000000AB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AB0000
|
Size: |
4096
|
|
25B92AC5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2615607051.0000025B92AC5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AC5000
|
Size: |
4096
|
|
14AF6D2D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3874939422.0000014AF6D2D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D2D000
|
Size: |
4096
|
|
14AFA67B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3542348616.0000014AFA67B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA67B000
|
Size: |
4096
|
|
14AF6F87000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3877141298.0000014AF6F87000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6F87000
|
Size: |
4096
|
|
25B92ACC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2620425975.0000025B92ACC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92ACC000
|
Size: |
36864
|
|
25B933C3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2617822702.0000025B933C3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B933C3000
|
Size: |
4096
|
|
14AFA2B7000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3263766967.0000014AFA2B7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA2B7000
|
Size: |
86016
|
|
59BA0FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3845927262.00000059BA0FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
59BA0FE000
|
Size: |
8192
|
|
2F00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2618859366.0000000002F00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F00000
|
Size: |
28672
|
|
230C000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3002450710.000000000230C000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
230C000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
23C31C7F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3851976269.0000023C31C7F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23C31C7F000
|
Size: |
40960
|
|
14AFA22B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3022779938.0000014AFA22B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA22B000
|
Size: |
28672
|
|
14AFA090000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3456728114.0000014AFA090000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
14AFA090000
|
Size: |
65536
|
|
3740000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2964225633.0000000003740000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3740000
|
Size: |
16384
|
|
AED000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2975294222.0000000000AED000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AED000
|
Size: |
61440
|
|
14AFA409000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3884951730.0000014AFA409000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA409000
|
Size: |
4096
|
|
23FDE48F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3854585217.0000023FDE48F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDE48F000
|
Size: |
4096
|
|
1C610C65000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2835287498.000001C610C65000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610C65000
|
Size: |
4096
|
|
67784FB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2622044511.00000067784FB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
67784FB000
|
Size: |
20480
|
|
14AFA35C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3375614107.0000014AFA35C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA35C000
|
Size: |
4096
|
|
1C610C55000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2827913624.000001C610C55000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610C55000
|
Size: |
151552
|
|
1C611147000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2869079537.000001C611147000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C611147000
|
Size: |
36864
|
|
AF7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2989345024.0000000000AF7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AF7000
|
Size: |
12288
|
|
23FE3AE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3607897573.0000023FE3AE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23FE3AE0000
|
Size: |
4096
|
|
367E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2978529630.000000000367E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
367E000
|
Size: |
20480
|
|
14AFA288000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3370386257.0000014AFA288000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA288000
|
Size: |
4096
|
|
14AF6F90000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3543888438.0000014AF6F90000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6F90000
|
Size: |
20480
|
|
65FBF7000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3848290875.000000065FBF7000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
65FBF7000
|
Size: |
36864
|
|
14AF9E5F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3428340956.0000014AF9E5F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
14AF9E5F000
|
Size: |
28672
|
|
A6C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2602698494.0000000000A6C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A6C000
|
Size: |
114688
|
|
1C611040000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2835585714.000001C611040000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C611040000
|
Size: |
20480
|
|
C7BD07F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3846392636.000000C7BD07F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C7BD07F000
|
Size: |
4096
|
|
25B93661000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2618908306.0000025B93661000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B93661000
|
Size: |
8192
|
|
14AFA29D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3880400710.0000014AFA29D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA29D000
|
Size: |
4096
|
|
14AF6D99000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3376420565.0000014AF6D99000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D99000
|
Size: |
73728
|
|
1C610BE9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2864102015.000001C610BE9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610BE9000
|
Size: |
8192
|
|
25B92AA1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2614377874.0000025B92AA1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AA1000
|
Size: |
28672
|
|
7458DFB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3846379357.0000007458DFB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7458DFB000
|
Size: |
20480
|
|
1C610C07000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2826999647.000001C610C07000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610C07000
|
Size: |
61440
|
|
14AFA4F6000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3367333289.0000014AFA4F6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA4F6000
|
Size: |
69632
|
|
14AF6D8D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3769746035.0000014AF6D8D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D8D000
|
Size: |
36864
|
|
14AFA28A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3370386257.0000014AFA28A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA28A000
|
Size: |
4096
|
|
27FA000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3000038312.00000000027FA000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
27FA000
|
Size: |
73728
|
|
A9C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2987248644.0000000000A9C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A9C000
|
Size: |
8192
|
|
14AF681F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3863448666.0000014AF681F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF681F000
|
Size: |
61440
|
|
14AFA358000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3370386257.0000014AFA358000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA358000
|
Size: |
20480
|
|
678000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3006869531.0000000000678000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
678000
|
Size: |
94208
|
|
14AFA1B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3878851662.0000014AFA1B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
14AFA1B0000
|
Size: |
4096
|
|
A40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3007936837.0000000000A40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A40000
|
Size: |
8192
|
|
14AFA287000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3263766967.0000014AFA287000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA287000
|
Size: |
184320
|
|
14AF6DBB000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3376420565.0000014AF6DBB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6DBB000
|
Size: |
16384
|
|
14AFA3C4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3375939699.0000014AFA3C4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA3C4000
|
Size: |
4096
|
|
25B8000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2982522590.00000000025B8000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
25B8000
|
Size: |
110592
|
|
14AFA467000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3886547689.0000014AFA467000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA467000
|
Size: |
4096
|
|
AE0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2975546779.0000000000AE0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AE0000
|
Size: |
32768
|
|
4C4000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.2588837676.00000000004C4000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
4C4000
|
Size: |
4096
|
|
25B92AAE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2615607051.0000025B92AAE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AAE000
|
Size: |
8192
|
|
25B92AB9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2615102548.0000025B92AB9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AB9000
|
Size: |
4096
|
|
2584000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2982522590.0000000002584000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2584000
|
Size: |
16384
|
|
14AF6D21000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3874939422.0000014AF6D21000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D21000
|
Size: |
40960
|
|
5070000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2964361872.0000000005070000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
5070000
|
Size: |
5029888
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
65FAF8000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3847899244.000000065FAF8000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
65FAF8000
|
Size: |
32768
|
|
25B92AF5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2620425975.0000025B92AF5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AF5000
|
Size: |
4096
|
|
3201000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.2616337638.0000000003201000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3201000
|
Size: |
143360
|
|
2871000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3000038312.0000000002871000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2871000
|
Size: |
4096
|
|
5B0E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2999764197.0000000005B0E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5B0E000
|
Size: |
8192
|
|
14AF6D6C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3769746035.0000014AF6D6C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D6C000
|
Size: |
61440
|
|
1C6113B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2871648807.000001C6113B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C6113B0000
|
Size: |
4096
|
|
12DB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.2616978038.00000000012DB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12DB000
|
Size: |
4096
|
|
192E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2874130618.000000000192E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
192E000
|
Size: |
8192
|
|
14AFA57F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3889368368.0000014AFA57F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA57F000
|
Size: |
4096
|
|
25B92AE5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2617118097.0000025B92AE5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AE5000
|
Size: |
12288
|
|
22E8000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3002450710.00000000022E8000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
22E8000
|
Size: |
4096
|
|
8C9000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000008.00000000.2798234498.00000000008C9000.00000002.00000001.01000000.00000009.sdmp
|
TargetID: |
8
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8C9000
|
Size: |
16384
|
|
23C31A80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3847176607.0000023C31A80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23C31A80000
|
Size: |
12288
|
|
14AFA42A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3884951730.0000014AFA42A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA42A000
|
Size: |
12288
|
|
172E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2874050921.000000000172E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
172E000
|
Size: |
8192
|
|
25B92AB1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2620425975.0000025B92AB1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AB1000
|
Size: |
12288
|
|
14AFA3B5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3884063493.0000014AFA3B5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA3B5000
|
Size: |
16384
|
|
14AFA3AC000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3884063493.0000014AFA3AC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA3AC000
|
Size: |
4096
|
|
AAC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2995130497.0000000000AAC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AAC000
|
Size: |
4096
|
|
14AFA451000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3884951730.0000014AFA451000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA451000
|
Size: |
4096
|
|
8E6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2993559640.00000000008E6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E6000
|
Size: |
12288
|
|
14AF6D66000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3874939422.0000014AF6D66000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D66000
|
Size: |
12288
|
|
7FF62BFA1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000009.00000000.2800651942.00007FF62BFA1000.00000020.00000001.01000000.0000000A.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF62BFA1000
|
Size: |
10485760
|
|
65F4F8000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3846763762.000000065F4F8000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
65F4F8000
|
Size: |
32768
|
|
25B92A95000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2617118097.0000025B92A95000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92A95000
|
Size: |
4096
|
|
23FDFA00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3865068959.0000023FDFA00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23FDFA00000
|
Size: |
4096
|
|
14AFA390000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3370386257.0000014AFA390000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA390000
|
Size: |
24576
|
|
14AF6726000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2988583801.0000014AF6726000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6726000
|
Size: |
409600
|
|
7458B7B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3845643003.0000007458B7B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7458B7B000
|
Size: |
20480
|
|
14AFA3F6000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3884951730.0000014AFA3F6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA3F6000
|
Size: |
12288
|
|
2850000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2997333873.0000000002850000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2850000
|
Size: |
4096
|
|
23FDE45E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3853707315.0000023FDE45E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDE45E000
|
Size: |
65536
|
|
1C610D76000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2865850100.000001C610D76000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610D76000
|
Size: |
36864
|
|
14AFA480000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3270953089.0000014AFA480000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA480000
|
Size: |
4096
|
|
14AFA353000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3883304507.0000014AFA353000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA353000
|
Size: |
4096
|
|
1C610EC2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2829296921.000001C610EC2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610EC2000
|
Size: |
12288
|
|
1C610C03000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2826999647.000001C610C03000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610C03000
|
Size: |
8192
|
|
14AFA1D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3472329769.0000014AFA1D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
14AFA1D0000
|
Size: |
4096
|
|
25B92AFD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2617118097.0000025B92AFD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AFD000
|
Size: |
12288
|
|
C7BCBFE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3845641230.000000C7BCBFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C7BCBFE000
|
Size: |
8192
|
|
14AFA346000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3883304507.0000014AFA346000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA346000
|
Size: |
8192
|
|
1A377A02000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3853621683.000001A377A02000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1A377A02000
|
Size: |
4096
|
|
25B933D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2620245314.0000025B933D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B933D0000
|
Size: |
12288
|
|
1C60EDAB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2826747182.000001C60EDAB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C60EDAB000
|
Size: |
20480
|
|
25B93640000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2619627883.0000025B93640000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B93640000
|
Size: |
4096
|
|
14AF675E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3003933977.0000014AF675E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF675E000
|
Size: |
4096
|
|
25B933C3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2616771071.0000025B933C3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B933C3000
|
Size: |
4096
|
|
25B92A9B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2614377874.0000025B92A9B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92A9B000
|
Size: |
12288
|
|
14AF6C68000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3869220124.0000014AF6C68000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6C68000
|
Size: |
405504
|
|
25D4000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2982522590.00000000025D4000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
25D4000
|
Size: |
155648
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
C7BD4FB000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3847217148.000000C7BD4FB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C7BD4FB000
|
Size: |
20480
|
|
23FDF8EA000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3863188664.0000023FDF8EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDF8EA000
|
Size: |
12288
|
|
1C611153000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2869079537.000001C611153000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C611153000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
14AF6DBB000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3876793087.0000014AF6DBB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6DBB000
|
Size: |
12288
|
|
1C610C2F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2831740785.000001C610C2F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610C2F000
|
Size: |
307200
|
|
A9F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2987248644.0000000000A9F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A9F000
|
Size: |
8192
|
|
14AFA617000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3542348616.0000014AFA617000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA617000
|
Size: |
12288
|
|
1C611525000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2845349701.000001C611525000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1C611525000
|
Size: |
147456
|
|
14AF6D8A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3025247628.0000014AF6D8A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D8A000
|
Size: |
32768
|
|
65FFFA000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3849394553.000000065FFFA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
65FFFA000
|
Size: |
24576
|
|
25B92AA1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2615607051.0000025B92AA1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AA1000
|
Size: |
24576
|
|
14AFA246000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3878988876.0000014AFA246000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA246000
|
Size: |
12288
|
|
5870000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2997870355.0000000005870000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5870000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
23FDEC02000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3858789282.0000023FDEC02000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDEC02000
|
Size: |
4096
|
|
2820000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3000038312.0000000002820000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2820000
|
Size: |
8192
|
|
14AFA62A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3891031904.0000014AFA62A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA62A000
|
Size: |
16384
|
|
74588FF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3845089363.00000074588FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
74588FF000
|
Size: |
4096
|
|
14AFA54B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3886934188.0000014AFA54B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA54B000
|
Size: |
4096
|
|
14AFA27A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3880400710.0000014AFA27A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA27A000
|
Size: |
16384
|
|
14AF6D92000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3376420565.0000014AF6D92000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D92000
|
Size: |
16384
|
|
86F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3007747579.000000000086F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
86F000
|
Size: |
4096
|
|
14AF6D63000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3769746035.0000014AF6D63000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D63000
|
Size: |
24576
|
|
ABC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2975546779.0000000000ABC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
ABC000
|
Size: |
86016
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
25B92A34000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2622296717.0000025B92A34000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92A34000
|
Size: |
4096
|
|
14AF45B0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3849818831.0000014AF45B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF45B0000
|
Size: |
24576
|
|
1C60ED9E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2840733959.000001C60ED9E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C60ED9E000
|
Size: |
4096
|
|
23FE3B13000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3605034546.0000023FE3B13000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23FE3B13000
|
Size: |
28672
|
|
326B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.2616337638.000000000326B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
326B000
|
Size: |
4096
|
|
7458FFF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3846908491.0000007458FFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7458FFF000
|
Size: |
4096
|
|
14AFA286000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3880400710.0000014AFA286000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA286000
|
Size: |
36864
|
|
14AFA63D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3891031904.0000014AFA63D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA63D000
|
Size: |
4096
|
|
1C61115B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2869079537.000001C61115B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C61115B000
|
Size: |
4096
|
|
23FE3B32000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3605034546.0000023FE3B32000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23FE3B32000
|
Size: |
155648
|
|
25B93645000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2619064374.0000025B93645000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B93645000
|
Size: |
12288
|
|
14AF6767000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3003933977.0000014AF6767000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6767000
|
Size: |
4096
|
|
23C31CD9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3854506019.0000023C31CD9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23C31CD9000
|
Size: |
118784
|
|
1C60EE55000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2863969596.000001C60EE55000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C60EE55000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
23FDE4A5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3854585217.0000023FDE4A5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDE4A5000
|
Size: |
106496
|
|
25B92A88000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2615607051.0000025B92A88000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92A88000
|
Size: |
12288
|
|
381C000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2979434887.000000000381C000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
381C000
|
Size: |
36864
|
|
116C000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3845571166.000000000116C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
116C000
|
Size: |
16384
|
|
14AFA27D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3375292147.0000014AFA27D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA27D000
|
Size: |
40960
|
|
14AF6882000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3863448666.0000014AF6882000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6882000
|
Size: |
28672
|
|
14AF67BA000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3859631789.0000014AF67BA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF67BA000
|
Size: |
20480
|
|
14AFA31C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3764667833.0000014AFA31C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA31C000
|
Size: |
40960
|
|
587E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2997870355.000000000587E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
587E000
|
Size: |
4096
|
|
14AFA3E1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3768824745.0000014AFA3E1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA3E1000
|
Size: |
4096
|
|
25B933DA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2618593059.0000025B933DA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B933DA000
|
Size: |
4096
|
|
11E0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3845743317.00000000011E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11E0000
|
Size: |
20480
|
|
14AFA465000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3367743010.0000014AFA465000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA465000
|
Size: |
12288
|
|
14AFA150000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3455587925.0000014AFA150000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
14AFA150000
|
Size: |
151552
|
|
14AFA316000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3882037559.0000014AFA316000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA316000
|
Size: |
16384
|
|
14AFA615000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3764527651.0000014AFA615000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA615000
|
Size: |
4096
|
|
14AFA2CA000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3880400710.0000014AFA2CA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA2CA000
|
Size: |
4096
|
|
12B7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2618528609.00000000012B7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12B7000
|
Size: |
126976
|
|
23C32402000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3856373819.0000023C32402000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23C32402000
|
Size: |
4096
|
|
1C610EB1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2829296921.000001C610EB1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610EB1000
|
Size: |
8192
|
|
6C7000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2992447779.00000000006C7000.00000004.00000001.01000000.00000005.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
6C7000
|
Size: |
4096
|
|
14AFA3F6000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3758288615.0000014AFA3F6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA3F6000
|
Size: |
294912
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
14AFA38C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3773566833.0000014AFA38C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA38C000
|
Size: |
4096
|
|
14AFA2F2000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3370386257.0000014AFA2F2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA2F2000
|
Size: |
4096
|
|
14AFA617000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3764527651.0000014AFA617000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA617000
|
Size: |
4096
|
|
14AFA46A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3768824745.0000014AFA46A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA46A000
|
Size: |
8192
|
|
14AF6D36000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3874939422.0000014AF6D36000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D36000
|
Size: |
4096
|
|
25B92AAA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2620425975.0000025B92AAA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AAA000
|
Size: |
4096
|
|
3839000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2979434887.0000000003839000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3839000
|
Size: |
12288
|
|
14AFA2F4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3764667833.0000014AFA2F4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA2F4000
|
Size: |
20480
|
|
14AF465C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3850235690.0000014AF465C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF465C000
|
Size: |
544768
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
14AFA25B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3878988876.0000014AFA25B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA25B000
|
Size: |
16384
|
|
11F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2618473885.00000000011F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11F0000
|
Size: |
24576
|
|
25B92AA1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2620425975.0000025B92AA1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AA1000
|
Size: |
28672
|
|
7FF62CA83000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000C.00000002.3891653320.00007FF62CA83000.00000002.00000001.01000000.0000000A.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF62CA83000
|
Size: |
4096
|
|
23FDF8CE000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3863188664.0000023FDF8CE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDF8CE000
|
Size: |
36864
|
|
3692000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2978529630.0000000003692000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3692000
|
Size: |
4096
|
|
1C610F7E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2829296921.000001C610F7E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610F7E000
|
Size: |
16384
|
|
14AFA3E3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3884951730.0000014AFA3E3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA3E3000
|
Size: |
8192
|
|
65F8FA000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3847609651.000000065F8FA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
65F8FA000
|
Size: |
24576
|
|
2844000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3000038312.0000000002844000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2844000
|
Size: |
8192
|
|
14AF69C0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3869220124.0000014AF69C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF69C0000
|
Size: |
188416
|
|
B1E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2996841123.0000000000B1E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B1E000
|
Size: |
4096
|
|
1C610FC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2835585714.000001C610FC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610FC0000
|
Size: |
4096
|
|
14AFA2CA000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3270996559.0000014AFA2CA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA2CA000
|
Size: |
4096
|
|
14AFA60B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3890223901.0000014AFA60B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA60B000
|
Size: |
20480
|
|
25B92A32000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2622296717.0000025B92A32000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92A32000
|
Size: |
4096
|
|
C7BD77E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3847907264.000000C7BD77E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C7BD77E000
|
Size: |
8192
|
|
258B000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2982522590.000000000258B000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
258B000
|
Size: |
8192
|
|
12B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2618528609.00000000012B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12B0000
|
Size: |
24576
|
|
133C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2873299951.000000000133C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
133C000
|
Size: |
16384
|
|
14AF6B5C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2994340866.0000014AF6B5C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6B5C000
|
Size: |
20480
|
|
C7BD87E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3848041598.000000C7BD87E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C7BD87E000
|
Size: |
8192
|
|
14AFA35C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3271040394.0000014AFA35C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA35C000
|
Size: |
4096
|
|
25B933BB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2617822702.0000025B933BB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B933BB000
|
Size: |
8192
|
|
5870000
|
remote allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2954602056.0000000005870000.00000004.00000400.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
remote allocation
|
Protect: |
page read and write
|
Base address: |
5870000
|
Size: |
4096
|
|
22FD000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3002450710.00000000022FD000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
22FD000
|
Size: |
4096
|
|
14AF6C64000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3869220124.0000014AF6C64000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6C64000
|
Size: |
8192
|
|
23FE3A00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3865148693.0000023FE3A00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23FE3A00000
|
Size: |
4096
|
|
65F6FF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3847340344.000000065F6FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
65F6FF000
|
Size: |
4096
|
|
14AFA329000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3263766967.0000014AFA329000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA329000
|
Size: |
98304
|
|
14AFA3C5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3758288615.0000014AFA3C5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA3C5000
|
Size: |
28672
|
|
1C610D04000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2865850100.000001C610D04000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610D04000
|
Size: |
53248
|
|
1C610D86000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2865850100.000001C610D86000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610D86000
|
Size: |
413696
|
|
1C610BF1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2826999647.000001C610BF1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610BF1000
|
Size: |
12288
|
|
14AFA232000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3878988876.0000014AFA232000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA232000
|
Size: |
4096
|
|
9AE56FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2861570627.0000009AE56FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9AE56FE000
|
Size: |
8192
|
|
14AFA358000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3764667833.0000014AFA358000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA358000
|
Size: |
20480
|
|
23FDF8CB000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3863188664.0000023FDF8CB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDF8CB000
|
Size: |
8192
|
|
14AF6931000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3863448666.0000014AF6931000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6931000
|
Size: |
12288
|
|
14AF6CDD000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3874409388.0000014AF6CDD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6CDD000
|
Size: |
4096
|
|
14AFA49E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3367743010.0000014AFA49E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA49E000
|
Size: |
20480
|
|
14AFA635000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3756605551.0000014AFA635000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA635000
|
Size: |
4096
|
|
14AFA020000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3878499279.0000014AFA020000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
14AFA020000
|
Size: |
40960
|
|
23C32532000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3856422038.0000023C32532000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23C32532000
|
Size: |
12288
|
|
C7BCEFC000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3846021183.000000C7BCEFC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C7BCEFC000
|
Size: |
16384
|
|
1C610C6E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2835287498.000001C610C6E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610C6E000
|
Size: |
4096
|
|
7FF62CE72000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3891819941.00007FF62CE72000.00000004.00000001.01000000.0000000A.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF62CE72000
|
Size: |
16384
|
|
25B92AF5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2617118097.0000025B92AF5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AF5000
|
Size: |
4096
|
|
1C610EB4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2829296921.000001C610EB4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610EB4000
|
Size: |
53248
|
|
256D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2982522590.000000000256D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
256D000
|
Size: |
81920
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
14AF6729000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2983483868.0000014AF6729000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6729000
|
Size: |
4096
|
|
14AFA2A9000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3764667833.0000014AFA2A9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA2A9000
|
Size: |
143360
|
|
A71000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2604380467.0000000000A71000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A71000
|
Size: |
36864
|
|
14AFA358000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3883304507.0000014AFA358000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA358000
|
Size: |
4096
|
|
1C610C32000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2827913624.000001C610C32000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610C32000
|
Size: |
131072
|
|
25B9365E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2618908306.0000025B9365E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B9365E000
|
Size: |
8192
|
|
5870000
|
remote allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2954648388.0000000005870000.00000004.00000400.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
remote allocation
|
Protect: |
page read and write
|
Base address: |
5870000
|
Size: |
4096
|
|
14AF6D7F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3874939422.0000014AF6D7F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D7F000
|
Size: |
4096
|
|
14AF6914000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3863448666.0000014AF6914000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6914000
|
Size: |
4096
|
|
14AFA1F3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3878988876.0000014AFA1F3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA1F3000
|
Size: |
8192
|
|
23FE3A80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3865310181.0000023FE3A80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23FE3A80000
|
Size: |
4096
|
|
37A7000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2979434887.00000000037A7000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
37A7000
|
Size: |
4096
|
|
C7BC7AD000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3844972419.000000C7BC7AD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C7BC7AD000
|
Size: |
12288
|
|
65F5FE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3847209783.000000065F5FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
65F5FE000
|
Size: |
8192
|
|
25B92A5C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2620425975.0000025B92A5C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92A5C000
|
Size: |
73728
|
|
B07000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2996841123.0000000000B07000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B07000
|
Size: |
4096
|
|
14AFA624000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3891031904.0000014AFA624000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA624000
|
Size: |
4096
|
|
14AF6D12000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3874939422.0000014AF6D12000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D12000
|
Size: |
4096
|
|
36B6000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2600688470.00000000036B6000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
36B6000
|
Size: |
77824
|
|
14AFA2F2000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3882037559.0000014AFA2F2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA2F2000
|
Size: |
8192
|
|
65EFFF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3845750443.000000065EFFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
65EFFF000
|
Size: |
4096
|
|
14AFA430000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3884951730.0000014AFA430000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA430000
|
Size: |
12288
|
|
14AFA3FE000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3370386257.0000014AFA3FE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA3FE000
|
Size: |
192512
|
|
14AFA31F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3882037559.0000014AFA31F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA31F000
|
Size: |
4096
|
|
25B92AE5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2620425975.0000025B92AE5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AE5000
|
Size: |
32768
|
|
14AFA2E5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3882037559.0000014AFA2E5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA2E5000
|
Size: |
8192
|
|
265A000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2592168834.000000000265A000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
265A000
|
Size: |
1155072
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
ACB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2995563752.0000000000ACB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
ACB000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
130B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.2616978038.000000000130B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
130B000
|
Size: |
229376
|
|
8DD000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2872986631.00000000008DD000.00000004.00000001.01000000.00000009.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
8DD000
|
Size: |
4096
|
|
C64000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000000.2613044973.0000000000C64000.00000002.00000001.01000000.00000008.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
C64000
|
Size: |
372736
|
|
890000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000008.00000000.2797972036.0000000000890000.00000002.00000001.01000000.00000009.sdmp
|
TargetID: |
8
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
890000
|
Size: |
4096
|
|
3D6E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2997803324.0000000003D6E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3D6E000
|
Size: |
8192
|
|
23C32500000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3856422038.0000023C32500000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23C32500000
|
Size: |
4096
|
|
14AF6829000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2985383781.0000014AF6829000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6829000
|
Size: |
147456
|
|
14AFA22E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3774222782.0000014AFA22E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA22E000
|
Size: |
126976
|
|
25B9364A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2619309449.0000025B9364A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B9364A000
|
Size: |
4096
|
|
1C610EB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2869079537.000001C610EB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610EB0000
|
Size: |
77824
|
|
14AFA553000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3888677127.0000014AFA553000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA553000
|
Size: |
28672
|
|
A77000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2987989955.0000000000A77000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A77000
|
Size: |
24576
|
|
ABE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2995563752.0000000000ABE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
ABE000
|
Size: |
4096
|
|
14AFA254000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3774222782.0000014AFA254000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA254000
|
Size: |
53248
|
|
14AFA2A3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3880400710.0000014AFA2A3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA2A3000
|
Size: |
4096
|
|
1C610C68000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2864102015.000001C610C68000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610C68000
|
Size: |
8192
|
|
39000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2990142028.0000000000039000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
39000
|
Size: |
24576
|
|
14AF6785000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3003933977.0000014AF6785000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6785000
|
Size: |
4096
|
|
8E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2993559640.00000000008E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E0000
|
Size: |
16384
|
|
25B92AA9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2614377874.0000025B92AA9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AA9000
|
Size: |
8192
|
|
14AF6D02000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3774159469.0000014AF6D02000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D02000
|
Size: |
4096
|
|
14AFA34C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3764667833.0000014AFA34C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA34C000
|
Size: |
45056
|
|
1C610D59000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2828466109.000001C610D59000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610D59000
|
Size: |
12288
|
|
B03000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2996841123.0000000000B03000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B03000
|
Size: |
8192
|
|
14AF4706000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2993577729.0000014AF4706000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF4706000
|
Size: |
4096
|
|
14AFA48B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3886934188.0000014AFA48B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA48B000
|
Size: |
8192
|
|
23FDED59000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3662678823.0000023FDED59000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDED59000
|
Size: |
8192
|
|
25B933CC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2620245314.0000025B933CC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B933CC000
|
Size: |
4096
|
|
3667000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000003.2978468396.0000000003667000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3667000
|
Size: |
4096
|
|
14AF6FEA000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3728307597.0000014AF6FEA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6FEA000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
22F6000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3002450710.00000000022F6000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
22F6000
|
Size: |
4096
|
|
25B92AC6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2620425975.0000025B92AC6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AC6000
|
Size: |
12288
|
|
7FF62CA83000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.2815067252.00007FF62CA83000.00000002.00000001.01000000.0000000A.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF62CA83000
|
Size: |
4124672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) |
Malware Analysis System Evasion |
Security Software Discovery
|
Public key (encryption) found |
Cryptography |
|
URLs found in memory or binary data |
Networking |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
A72000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2605490907.0000000000A72000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A72000
|
Size: |
24576
|
|
A78000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2605402277.0000000000A78000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A78000
|
Size: |
24576
|
|
14AFA28E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3370386257.0000014AFA28E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA28E000
|
Size: |
266240
|
|
A42000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2994259274.0000000000A42000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A42000
|
Size: |
12288
|
|
35AE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2976746976.00000000035AE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
35AE000
|
Size: |
311296
|
|
14AF6789000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2987449419.0000014AF6789000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6789000
|
Size: |
4096
|
|
25B92A95000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2615607051.0000025B92A95000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92A95000
|
Size: |
12288
|
|
123D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2873247790.000000000123D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
123D000
|
Size: |
12288
|
|
3252000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.2614380488.0000000003252000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3252000
|
Size: |
552960
|
|
14AFA27A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3270461517.0000014AFA27A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA27A000
|
Size: |
53248
|
|
25B92A2F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2622296717.0000025B92A2F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92A2F000
|
Size: |
4096
|
|
65F1FF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3845915326.000000065F1FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
65F1FF000
|
Size: |
4096
|
|
67786FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2622187420.00000067786FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
67786FE000
|
Size: |
8192
|
|
A50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2994259274.0000000000A50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A50000
|
Size: |
4096
|
|
14AFA502000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3768824745.0000014AFA502000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA502000
|
Size: |
4096
|
|
14AFA2B0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3880400710.0000014AFA2B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA2B0000
|
Size: |
12288
|
|
14AFA23D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3878988876.0000014AFA23D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA23D000
|
Size: |
4096
|
|
6CE000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2992747823.00000000006CE000.00000004.00000001.01000000.00000005.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
6CE000
|
Size: |
8192
|
|
59B9D7B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3845239822.00000059B9D7B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
59B9D7B000
|
Size: |
20480
|
|
65FCF8000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3848658936.000000065FCF8000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
65FCF8000
|
Size: |
32768
|
|
16AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2618763785.00000000016AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
16AE000
|
Size: |
8192
|
|
8DD000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000008.00000000.2798542013.00000000008DD000.00000008.00000001.01000000.00000009.sdmp
|
TargetID: |
8
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
8DD000
|
Size: |
8192
|
|
B19000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2974959768.0000000000B19000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B19000
|
Size: |
24576
|
|
14AFA58E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3889368368.0000014AFA58E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA58E000
|
Size: |
8192
|
|
A56000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2994259274.0000000000A56000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A56000
|
Size: |
16384
|
|
25B92AF8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2617118097.0000025B92AF8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AF8000
|
Size: |
4096
|
|
65E79F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3844445569.000000065E79F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
65E79F000
|
Size: |
69632
|
|
14AFA2C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3880400710.0000014AFA2C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA2C1000
|
Size: |
16384
|
|
25B933C5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2620245314.0000025B933C5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B933C5000
|
Size: |
12288
|
|
14AF6799000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3002736658.0000014AF6799000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6799000
|
Size: |
139264
|
|
14AFA244000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3878988876.0000014AFA244000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA244000
|
Size: |
4096
|
|
14AFA260000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3878988876.0000014AFA260000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA260000
|
Size: |
4096
|
|
14AFA358000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3263766967.0000014AFA358000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA358000
|
Size: |
53248
|
|
14AF6F96000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3877141298.0000014AF6F96000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6F96000
|
Size: |
12288
|
|
23FDED19000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3662678823.0000023FDED19000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDED19000
|
Size: |
4096
|
|
25B92B02000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2620425975.0000025B92B02000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92B02000
|
Size: |
53248
|
|
1C610ED2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2829296921.000001C610ED2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610ED2000
|
Size: |
696320
|
|
14AFA2E2000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3882037559.0000014AFA2E2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA2E2000
|
Size: |
8192
|
|
14AFA327000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3263766967.0000014AFA327000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA327000
|
Size: |
4096
|
|
14AFA3C4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3884063493.0000014AFA3C4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA3C4000
|
Size: |
4096
|
|
14AFA516000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3768824745.0000014AFA516000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA516000
|
Size: |
4096
|
|
AE6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2995563752.0000000000AE6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AE6000
|
Size: |
8192
|
|
1C610EFD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2832547758.000001C610EFD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610EFD000
|
Size: |
4096
|
|
14AF4711000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2994250692.0000014AF4711000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF4711000
|
Size: |
4096
|
|
23FDEC00000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3858789282.0000023FDEC00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDEC00000
|
Size: |
4096
|
|
3685000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2978529630.0000000003685000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3685000
|
Size: |
8192
|
|
3580000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2997612501.0000000003580000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3580000
|
Size: |
4096
|
|
14AFA2C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3271996550.0000014AFA2C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA2C1000
|
Size: |
4096
|
|
21F0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3002450710.00000000021F0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
21F0000
|
Size: |
4096
|
|
14AFA280000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3880400710.0000014AFA280000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA280000
|
Size: |
4096
|
|
14AF4724000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3850235690.0000014AF4724000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF4724000
|
Size: |
110592
|
|
14AF6767000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3859631789.0000014AF6767000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6767000
|
Size: |
4096
|
|
1C60ED91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2834956472.000001C60ED91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C60ED91000
|
Size: |
4096
|
|
14AF9E5D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3428340956.0000014AF9E5D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
14AF9E5D000
|
Size: |
4096
|
|
25B92AD4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2622547098.0000025B92AD4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AD4000
|
Size: |
4096
|
|
14AF6765000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2984346351.0000014AF6765000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6765000
|
Size: |
151552
|
|
59B9CFC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3845073941.00000059B9CFC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
59B9CFC000
|
Size: |
16384
|
|
C7BCFFB000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3846232955.000000C7BCFFB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C7BCFFB000
|
Size: |
20480
|
|
14AFA62E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3756605551.0000014AFA62E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA62E000
|
Size: |
12288
|
|
1C610D6B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2865850100.000001C610D6B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610D6B000
|
Size: |
4096
|
|
1227000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3846003823.0000000001227000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1227000
|
Size: |
110592
|
|
14AFA45D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3367743010.0000014AFA45D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA45D000
|
Size: |
28672
|
|
401000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000000.2588596851.0000000000401000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
401000
|
Size: |
745472
|
|
14AF675B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3003933977.0000014AF675B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF675B000
|
Size: |
4096
|
|
1C61103E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2869079537.000001C61103E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C61103E000
|
Size: |
69632
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
DBE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2618397275.0000000000DBE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
DBE000
|
Size: |
8192
|
|
3696000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2978529630.0000000003696000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3696000
|
Size: |
8192
|
|
14AFA26F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3880267392.0000014AFA26F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA26F000
|
Size: |
4096
|
|
23FDE47F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3854585217.0000023FDE47F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDE47F000
|
Size: |
4096
|
|
A28000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2993816821.0000000000A28000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A28000
|
Size: |
94208
|
|
1C611151000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2869079537.000001C611151000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C611151000
|
Size: |
4096
|
|
23FE3AA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3605034546.0000023FE3AA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23FE3AA0000
|
Size: |
28672
|
|
1C610F9B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2829296921.000001C610F9B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610F9B000
|
Size: |
12288
|
|
23C31C94000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3853737586.0000023C31C94000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23C31C94000
|
Size: |
16384
|
|
1C610F01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2831255548.000001C610F01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610F01000
|
Size: |
8192
|
|
14AFA406000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3884951730.0000014AFA406000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA406000
|
Size: |
4096
|
|
2521000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2982522590.0000000002521000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2521000
|
Size: |
106496
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
14AF6D8B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3769746035.0000014AF6D8B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D8B000
|
Size: |
4096
|
|
25B92AA6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2617118097.0000025B92AA6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AA6000
|
Size: |
4096
|
|
23FE3B1B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3605034546.0000023FE3B1B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23FE3B1B000
|
Size: |
86016
|
|
14AFA524000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3758288615.0000014AFA524000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA524000
|
Size: |
20480
|
|
65F7FD000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3847424953.000000065F7FD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
65F7FD000
|
Size: |
12288
|
|
182E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2874092068.000000000182E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
182E000
|
Size: |
8192
|
|
14AF6D50000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3874939422.0000014AF6D50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D50000
|
Size: |
4096
|
|
25B92A38000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2622296717.0000025B92A38000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92A38000
|
Size: |
8192
|
|
14AFA52E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3758288615.0000014AFA52E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA52E000
|
Size: |
442368
|
|
14AF6735000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2983483868.0000014AF6735000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6735000
|
Size: |
4096
|
|
23C31C13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3848293251.0000023C31C13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23C31C13000
|
Size: |
94208
|
|
14AFA3F6000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3263766967.0000014AFA3F6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA3F6000
|
Size: |
294912
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
14AFA397000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3370386257.0000014AFA397000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA397000
|
Size: |
4096
|
|
14AFA5C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3773300520.0000014AFA5C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA5C1000
|
Size: |
4096
|
|
A7D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2987673903.0000000000A7D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A7D000
|
Size: |
4096
|
|
1A377229000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3848196108.000001A377229000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A377229000
|
Size: |
102400
|
|
520000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3006746070.0000000000520000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
520000
|
Size: |
20480
|
|
23FE3A10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3865238654.0000023FE3A10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23FE3A10000
|
Size: |
4096
|
|
1C60EC90000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2861769305.000001C60EC90000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C60EC90000
|
Size: |
8192
|
|
25B933B9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2614898161.0000025B933B9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B933B9000
|
Size: |
16384
|
|
36BD000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2978529630.00000000036BD000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
36BD000
|
Size: |
102400
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
6F4000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000000.2598562660.00000000006F4000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
6F4000
|
Size: |
200704
|
|
14AFA4D2000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3367743010.0000014AFA4D2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA4D2000
|
Size: |
49152
|
|
2549000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2982522590.0000000002549000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2549000
|
Size: |
4096
|
|
14AFA2DA000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3018239583.0000014AFA2DA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA2DA000
|
Size: |
1093632
|
|
23FDE4F0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3857800049.0000023FDE4F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDE4F0000
|
Size: |
69632
|
|
1C610FA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2829296921.000001C610FA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610FA0000
|
Size: |
4096
|
|
25B92A95000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2622547098.0000025B92A95000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92A95000
|
Size: |
4096
|
|
12E1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.2615167648.00000000012E1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12E1000
|
Size: |
94208
|
|
1A377200000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3846489498.000001A377200000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A377200000
|
Size: |
40960
|
|
25B92C05000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2622697688.0000025B92C05000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92C05000
|
Size: |
40960
|
|
14AFA445000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3758288615.0000014AFA445000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA445000
|
Size: |
4096
|
|
23FDF85E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3860541877.0000023FDF85E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDF85E000
|
Size: |
12288
|
|
23FE3B70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3608658105.0000023FE3B70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23FE3B70000
|
Size: |
4096
|
|
7FF62CEF7000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3892227764.00007FF62CEF7000.00000004.00000001.01000000.0000000A.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF62CEF7000
|
Size: |
4096
|
|
6DE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000000.2598525878.00000000006DE000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
6DE000
|
Size: |
4096
|
|
14AF4721000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3850235690.0000014AF4721000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF4721000
|
Size: |
8192
|
|
5E6D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2999872987.0000000005E6D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5E6D000
|
Size: |
12288
|
|
A66000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2987989955.0000000000A66000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A66000
|
Size: |
61440
|
|
14AFA46A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3886547689.0000014AFA46A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA46A000
|
Size: |
4096
|
|
23FE3B59000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3605034546.0000023FE3B59000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23FE3B59000
|
Size: |
4096
|
|
1300000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.2615167648.0000000001300000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1300000
|
Size: |
16384
|
|
2853000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3000038312.0000000002853000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2853000
|
Size: |
4096
|
|
23FDE4C0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3856283026.0000023FDE4C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDE4C0000
|
Size: |
61440
|
|
14AFA4F2000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3367743010.0000014AFA4F2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA4F2000
|
Size: |
4096
|
|
25B92A18000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2622296717.0000025B92A18000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92A18000
|
Size: |
73728
|
|
3570000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2600648049.0000000003570000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3570000
|
Size: |
16384
|
|
14AFA21F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3022779938.0000014AFA21F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA21F000
|
Size: |
24576
|
|
14AF4540000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3849710268.0000014AF4540000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF4540000
|
Size: |
4096
|
|
14AFA208000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3878988876.0000014AFA208000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA208000
|
Size: |
4096
|
|
14AFA5CC000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3757527512.0000014AFA5CC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA5CC000
|
Size: |
98304
|
|
14AFA21D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3774222782.0000014AFA21D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA21D000
|
Size: |
65536
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
23FDE493000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3854585217.0000023FDE493000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDE493000
|
Size: |
12288
|
|
14AFA2CA000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3375811777.0000014AFA2CA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA2CA000
|
Size: |
4096
|
|
1C60ED94000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2834956472.000001C60ED94000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C60ED94000
|
Size: |
94208
|
|
3201000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.2614380488.0000000003201000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3201000
|
Size: |
102400
|
|
14AF6FEA000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3543888438.0000014AF6FEA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6FEA000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1306000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.2616978038.0000000001306000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1306000
|
Size: |
16384
|
|
23FDF8C6000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3659787469.0000023FDF8C6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDF8C6000
|
Size: |
32768
|
|
25B92B02000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2617118097.0000025B92B02000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92B02000
|
Size: |
24576
|
|
25B92AFD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2620425975.0000025B92AFD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AFD000
|
Size: |
12288
|
|
14AFA5EB000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3890223901.0000014AFA5EB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA5EB000
|
Size: |
4096
|
|
3570000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2601391098.0000000003570000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3570000
|
Size: |
16384
|
|
14AFA351000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3263766967.0000014AFA351000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA351000
|
Size: |
4096
|
|
22B1000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3002450710.00000000022B1000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
22B1000
|
Size: |
77824
|
|
9AE55FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2861521823.0000009AE55FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9AE55FE000
|
Size: |
8192
|
|
14AF6DA0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3876793087.0000014AF6DA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6DA0000
|
Size: |
8192
|
|
14AF6CF2000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3874862906.0000014AF6CF2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6CF2000
|
Size: |
4096
|
|
255F000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2982522590.000000000255F000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
255F000
|
Size: |
8192
|
|
A5D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2994259274.0000000000A5D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A5D000
|
Size: |
4096
|
|
32D7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2619112879.00000000032D7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32D7000
|
Size: |
4096
|
|
25B92AAA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2617118097.0000025B92AAA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AAA000
|
Size: |
4096
|
|
14AFA5F3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3542348616.0000014AFA5F3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA5F3000
|
Size: |
16384
|
|
65EBFE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3845302554.000000065EBFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
65EBFE000
|
Size: |
8192
|
|
23FDF913000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3864962066.0000023FDF913000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDF913000
|
Size: |
12288
|
|
154E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2873943546.000000000154E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
154E000
|
Size: |
8192
|
|
AA4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2987248644.0000000000AA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AA4000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
14AFA426000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3884951730.0000014AFA426000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA426000
|
Size: |
8192
|
|
C5D000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000005.00000000.2612959583.0000000000C5D000.00000008.00000001.01000000.00000008.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
C5D000
|
Size: |
8192
|
|
3301000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.2616015292.0000000003301000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3301000
|
Size: |
438272
|
|
1A37720B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3846489498.000001A37720B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A37720B000
|
Size: |
28672
|
|
14AF6D8F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3774091680.0000014AF6D8F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D8F000
|
Size: |
4096
|
|
14AF6FA7000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3728377952.0000014AF6FA7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6FA7000
|
Size: |
12288
|
|
23FE4000000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3865839526.0000023FE4000000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FE4000000
|
Size: |
4096
|
|
14AFA56B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3888677127.0000014AFA56B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA56B000
|
Size: |
8192
|
|
25B92AF2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2617118097.0000025B92AF2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AF2000
|
Size: |
4096
|
|
6778137000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2621876399.0000006778137000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6778137000
|
Size: |
36864
|
|
6E0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000000.2598562660.00000000006E0000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
6E0000
|
Size: |
73728
|
|
14AF66FF000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2983483868.0000014AF66FF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF66FF000
|
Size: |
40960
|
|
14AF6D3C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3769746035.0000014AF6D3C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D3C000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
C1F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2997245140.0000000000C1F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C1F000
|
Size: |
4096
|
|
6C7000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000002.00000000.2598394540.00000000006C7000.00000008.00000001.01000000.00000005.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
6C7000
|
Size: |
40960
|
|
1C6113D2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2835729551.000001C6113D2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C6113D2000
|
Size: |
544768
|
|
8AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3007819016.00000000008AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8AE000
|
Size: |
8192
|
|
14AFA3A7000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3370386257.0000014AFA3A7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA3A7000
|
Size: |
4096
|
|
745897B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3845212239.000000745897B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
745897B000
|
Size: |
20480
|
|
1C610CB1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2825610229.000001C610CB1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610CB1000
|
Size: |
356352
|
|
7FF62CF0C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2872368686.00007FF62CF0C000.00000004.00000001.01000000.0000000A.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF62CF0C000
|
Size: |
16384
|
|
14AFA346000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3370386257.0000014AFA346000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA346000
|
Size: |
8192
|
|
1C610D5B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2865850100.000001C610D5B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610D5B000
|
Size: |
8192
|
|
2FD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2618963301.0000000002FD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FD0000
|
Size: |
4096
|
|
3D2D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2997730953.0000000003D2D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3D2D000
|
Size: |
12288
|
|
14AFA24A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3878988876.0000014AFA24A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA24A000
|
Size: |
8192
|
|
25B92AC8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2615607051.0000025B92AC8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AC8000
|
Size: |
8192
|
|
1C60EC50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2861728818.000001C60EC50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C60EC50000
|
Size: |
4096
|
|
C7BD67B000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3847653570.000000C7BD67B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C7BD67B000
|
Size: |
20480
|
|
25B933CB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2618616736.0000025B933CB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B933CB000
|
Size: |
32768
|
|
25B93647000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2619627883.0000025B93647000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B93647000
|
Size: |
4096
|
|
1C610CFF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2828466109.000001C610CFF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610CFF000
|
Size: |
184320
|
|
1C60ED01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2861872465.000001C60ED01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C60ED01000
|
Size: |
262144
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
23FDF8C4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3863188664.0000023FDF8C4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDF8C4000
|
Size: |
12288
|
|
23C31CF7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3854506019.0000023C31CF7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23C31CF7000
|
Size: |
32768
|
|
14AF8B70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3427025495.0000014AF8B70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
14AF8B70000
|
Size: |
65536
|
|
A52000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2994259274.0000000000A52000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A52000
|
Size: |
8192
|
|
B14000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2996841123.0000000000B14000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B14000
|
Size: |
4096
|
|
14AFA3D3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3370386257.0000014AFA3D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA3D3000
|
Size: |
16384
|
|
14AFA4BE000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3758288615.0000014AFA4BE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA4BE000
|
Size: |
16384
|
|
14AFA100000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3878717491.0000014AFA100000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
14AFA100000
|
Size: |
4096
|
|
14AF6D0C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3874939422.0000014AF6D0C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D0C000
|
Size: |
8192
|
|
14AFA4A8000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3758288615.0000014AFA4A8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA4A8000
|
Size: |
8192
|
|
2868000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3000038312.0000000002868000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2868000
|
Size: |
4096
|
|
14AFA360000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3883304507.0000014AFA360000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA360000
|
Size: |
12288
|
|
25B92A4F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2621586525.0000025B92A4F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92A4F000
|
Size: |
4096
|
|
14AFA431000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3768824745.0000014AFA431000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA431000
|
Size: |
4096
|
|
1C610F85000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2829296921.000001C610F85000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610F85000
|
Size: |
73728
|
|
23FDE513000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3858489999.0000023FDE513000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDE513000
|
Size: |
8192
|
|
7FF62CF0C000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3892227764.00007FF62CF0C000.00000004.00000001.01000000.0000000A.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF62CF0C000
|
Size: |
16384
|
|
28E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2997369947.00000000028E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
28E0000
|
Size: |
4096
|
|
25B92AD2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2622547098.0000025B92AD2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AD2000
|
Size: |
4096
|
|
14AF671A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3859631789.0000014AF671A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF671A000
|
Size: |
8192
|
|
23C31B80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3847387250.0000023C31B80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23C31B80000
|
Size: |
4096
|
|
C46000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000002.2618242626.0000000000C46000.00000002.00000001.01000000.00000008.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
C46000
|
Size: |
4096
|
|
3847000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2979434887.0000000003847000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3847000
|
Size: |
12288
|
|
14AF6D3A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3874939422.0000014AF6D3A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D3A000
|
Size: |
4096
|
|
322F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.2616337638.000000000322F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
322F000
|
Size: |
110592
|
|
2886000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3000038312.0000000002886000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2886000
|
Size: |
237568
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1344000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.2616978038.0000000001344000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1344000
|
Size: |
12288
|
|
23FE3AEC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3605034546.0000023FE3AEC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23FE3AEC000
|
Size: |
155648
|
|
1C60EE50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2863969596.000001C60EE50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C60EE50000
|
Size: |
16384
|
|
14AFA354000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3263766967.0000014AFA354000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA354000
|
Size: |
12288
|
|
8E2000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3844943152.00000000008E2000.00000004.00000001.01000000.00000009.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
8E2000
|
Size: |
8192
|
|
C10000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000000.2612456600.0000000000C10000.00000002.00000001.01000000.00000008.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
C10000
|
Size: |
4096
|
|
AFE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2989345024.0000000000AFE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AFE000
|
Size: |
4096
|
|
14AF687C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3863448666.0000014AF687C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF687C000
|
Size: |
4096
|
|
14AFA38C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3764667833.0000014AFA38C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA38C000
|
Size: |
40960
|
|
14AF6F90000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3322983776.0000014AF6F90000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6F90000
|
Size: |
36864
|
|
1A377300000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3852250882.000001A377300000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A377300000
|
Size: |
4096
|
|
2304000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3002450710.0000000002304000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2304000
|
Size: |
8192
|
|
14AFA46A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3758288615.0000014AFA46A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA46A000
|
Size: |
143360
|
|
DFD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2618421399.0000000000DFD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
DFD000
|
Size: |
12288
|
|
23FDED00000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3859071445.0000023FDED00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDED00000
|
Size: |
4096
|
|
23FDE502000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3857800049.0000023FDE502000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDE502000
|
Size: |
49152
|
|
C7BCDFC000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3845882374.000000C7BCDFC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C7BCDFC000
|
Size: |
16384
|
|
B1A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2996841123.0000000000B1A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B1A000
|
Size: |
4096
|
|
14AFA216000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3774222782.0000014AFA216000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA216000
|
Size: |
8192
|
|
6D9000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000002.00000000.2598394540.00000000006D9000.00000008.00000001.01000000.00000005.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
6D9000
|
Size: |
20480
|
|
1C60EC30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2861670376.000001C60EC30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C60EC30000
|
Size: |
12288
|
|
14AFA573000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3888677127.0000014AFA573000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA573000
|
Size: |
4096
|
|
14AF6D56000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3874939422.0000014AF6D56000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D56000
|
Size: |
16384
|
|
14AF6720000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3859631789.0000014AF6720000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6720000
|
Size: |
8192
|
|
14AF68A7000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3863448666.0000014AF68A7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF68A7000
|
Size: |
413696
|
|
22D8000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3002450710.00000000022D8000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
22D8000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
59B987B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3844417132.00000059B987B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
59B987B000
|
Size: |
20480
|
|
14AF6725000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2982424778.0000014AF6725000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6725000
|
Size: |
118784
|
|
65F3F8000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3846307225.000000065F3F8000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
65F3F8000
|
Size: |
32768
|
|
365B000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2976746976.000000000365B000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
365B000
|
Size: |
4096
|
|
12D6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.2615653699.00000000012D6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12D6000
|
Size: |
16384
|
|
C46000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000000.2612828260.0000000000C46000.00000002.00000001.01000000.00000008.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
C46000
|
Size: |
94208
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
14AF6F9A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3877141298.0000014AF6F9A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6F9A000
|
Size: |
4096
|
|
14AFA329000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3882037559.0000014AFA329000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA329000
|
Size: |
24576
|
|
14AF6D36000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3376420565.0000014AF6D36000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D36000
|
Size: |
372736
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
231A000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3002450710.000000000231A000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
231A000
|
Size: |
4096
|
|
23FDF90C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3864380329.0000023FDF90C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDF90C000
|
Size: |
4096
|
|
23FDED5A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3859514495.0000023FDED5A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDED5A000
|
Size: |
4096
|
|
14AF6FB1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3543888438.0000014AF6FB1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6FB1000
|
Size: |
221184
|
|
23FDE3F0000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3849129630.0000023FDE3F0000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
23FDE3F0000
|
Size: |
4096
|
|
14AF6F8E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3728377952.0000014AF6F8E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6F8E000
|
Size: |
24576
|
|
1C610CB8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2826877779.000001C610CB8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610CB8000
|
Size: |
28672
|
|
23FDF380000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3859745309.0000023FDF380000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23FDF380000
|
Size: |
4096
|
|
67781BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2621953592.00000067781BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
67781BE000
|
Size: |
8192
|
|
8BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2993490359.00000000008BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8BE000
|
Size: |
8192
|
|
23FDF8EE000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3863188664.0000023FDF8EE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDF8EE000
|
Size: |
4096
|
|
1C610C12000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2864102015.000001C610C12000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610C12000
|
Size: |
131072
|
|
12DF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.2615167648.00000000012DF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12DF000
|
Size: |
4096
|
|
23C31CD4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3853737586.0000023C31CD4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23C31CD4000
|
Size: |
16384
|
|
284C000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3000038312.000000000284C000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
284C000
|
Size: |
4096
|
|
30F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.2618020316.00000000030F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F0000
|
Size: |
16384
|
|
14AFA35F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3370386257.0000014AFA35F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA35F000
|
Size: |
20480
|
|
1C610EC7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2869079537.000001C610EC7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610EC7000
|
Size: |
94208
|
|
8D6000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000008.00000000.2798234498.00000000008D6000.00000002.00000001.01000000.00000009.sdmp
|
TargetID: |
8
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8D6000
|
Size: |
24576
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
322A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.2614380488.000000000322A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
322A000
|
Size: |
16384
|
|
25B92AFB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2615607051.0000025B92AFB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AFB000
|
Size: |
20480
|
|
25B929F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2622269068.0000025B929F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B929F0000
|
Size: |
8192
|
|
23FDED5A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3656699104.0000023FDED5A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDED5A000
|
Size: |
4096
|
|
AF9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2996679404.0000000000AF9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AF9000
|
Size: |
12288
|
|
14AF6F9C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3728377952.0000014AF6F9C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6F9C000
|
Size: |
28672
|
|
14AFA47C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3768824745.0000014AFA47C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA47C000
|
Size: |
4096
|
|
14AF6742000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2984346351.0000014AF6742000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6742000
|
Size: |
131072
|
|
1C610C79000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2831136963.000001C610C79000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610C79000
|
Size: |
4096
|
|
10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3006138226.0000000000010000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10000
|
Size: |
4096
|
|
14AFA46A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3367743010.0000014AFA46A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA46A000
|
Size: |
143360
|
|
14AFA48E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3263766967.0000014AFA48E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA48E000
|
Size: |
4096
|
|
130F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.2615167648.000000000130F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
130F000
|
Size: |
118784
|
|
25B93642000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2619627883.0000025B93642000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B93642000
|
Size: |
4096
|
|
14AF6CCB000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3769746035.0000014AF6CCB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6CCB000
|
Size: |
458752
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
14AFA5E6000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3757527512.0000014AFA5E6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA5E6000
|
Size: |
12288
|
|
14AF6D09000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3874939422.0000014AF6D09000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D09000
|
Size: |
8192
|
|
14AFA5B0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3889368368.0000014AFA5B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA5B0000
|
Size: |
12288
|
|
14AFA294000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3018239583.0000014AFA294000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA294000
|
Size: |
16384
|
|
A86000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2604652931.0000000000A86000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A86000
|
Size: |
36864
|
|
14AF67CF000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3863448666.0000014AF67CF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF67CF000
|
Size: |
4096
|
|
6D6000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2993039881.00000000006D6000.00000004.00000001.01000000.00000005.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
6D6000
|
Size: |
20480
|
|
1C61102D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2837064403.000001C61102D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C61102D000
|
Size: |
73728
|
|
14AF6DBB000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3769746035.0000014AF6DBB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6DBB000
|
Size: |
16384
|
|
23FE3AA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3627997881.0000023FE3AA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23FE3AA0000
|
Size: |
4096
|
|
14AF6A8A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3869220124.0000014AF6A8A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6A8A000
|
Size: |
4096
|
|
14AFA43F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3758288615.0000014AFA43F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA43F000
|
Size: |
8192
|
|
14AF6CD7000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3874409388.0000014AF6CD7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6CD7000
|
Size: |
12288
|
|
14AFA560000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3888677127.0000014AFA560000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA560000
|
Size: |
36864
|
|
14AFA47E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3768824745.0000014AFA47E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA47E000
|
Size: |
8192
|
|
24C0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2982522590.00000000024C0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
24C0000
|
Size: |
376832
|
|
321B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.2614380488.000000000321B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
321B000
|
Size: |
16384
|
|
25B92A51000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2620425975.0000025B92A51000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92A51000
|
Size: |
40960
|
|
14AF6D9C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3876793087.0000014AF6D9C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D9C000
|
Size: |
4096
|
|
1C610D2F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2828466109.000001C610D2F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610D2F000
|
Size: |
143360
|
|
14CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2873846404.00000000014CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
14CE000
|
Size: |
8192
|
|
25B92B10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2622674601.0000025B92B10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92B10000
|
Size: |
4096
|
|
14AF6D7C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3874939422.0000014AF6D7C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D7C000
|
Size: |
8192
|
|
1C610C72000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2835287498.000001C610C72000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610C72000
|
Size: |
8192
|
|
23C32512000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3856422038.0000023C32512000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23C32512000
|
Size: |
32768
|
|
22CA000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3002450710.00000000022CA000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
22CA000
|
Size: |
8192
|
|
94000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2990372523.0000000000094000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
94000
|
Size: |
49152
|
|
3252000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.2616337638.0000000003252000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3252000
|
Size: |
98304
|
|
2550000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2982522590.0000000002550000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2550000
|
Size: |
8192
|
|
14AF9E40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3428340956.0000014AF9E40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
14AF9E40000
|
Size: |
98304
|
|
65EAFD000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3845083338.000000065EAFD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
65EAFD000
|
Size: |
12288
|
|
C7BD3FF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3847125481.000000C7BD3FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C7BD3FF000
|
Size: |
4096
|
|
14AFA235000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3022779938.0000014AFA235000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA235000
|
Size: |
229376
|
|
1305000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.2615167648.0000000001305000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1305000
|
Size: |
16384
|
|
14AFA4B8000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3367743010.0000014AFA4B8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA4B8000
|
Size: |
16384
|
|
23FDF910000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3864380329.0000023FDF910000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDF910000
|
Size: |
8192
|
|
14AFA526000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3376003137.0000014AFA526000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA526000
|
Size: |
4096
|
|
23FDE498000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3854585217.0000023FDE498000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDE498000
|
Size: |
40960
|
|
14AFA22A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3878988876.0000014AFA22A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA22A000
|
Size: |
8192
|
|
670000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3006869531.0000000000670000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
670000
|
Size: |
24576
|
|
1C610C2F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2826999647.000001C610C2F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610C2F000
|
Size: |
4096
|
|
7FF62CE7B000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2872242591.00007FF62CE7B000.00000004.00000001.01000000.0000000A.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF62CE7B000
|
Size: |
32768
|
|
14AF4700000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2993577729.0000014AF4700000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF4700000
|
Size: |
20480
|
|
25B93657000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2619401509.0000025B93657000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B93657000
|
Size: |
20480
|
|
14AFA202000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3878988876.0000014AFA202000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA202000
|
Size: |
4096
|
|
25B92B02000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2615607051.0000025B92B02000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92B02000
|
Size: |
24576
|
|
25B92A10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2622296717.0000025B92A10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92A10000
|
Size: |
28672
|
|
AE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2796864368.0000000000AE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AE4000
|
Size: |
81920
|
|
287F000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3000038312.000000000287F000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
287F000
|
Size: |
4096
|
|
14AFA212000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3878988876.0000014AFA212000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA212000
|
Size: |
4096
|
|
D1F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2997289544.0000000000D1F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
D1F000
|
Size: |
4096
|
|
AB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2987248644.0000000000AB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AB0000
|
Size: |
4096
|
|
14AFA261000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3773639858.0000014AFA261000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA261000
|
Size: |
12288
|
|
14AFA5AB000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3889368368.0000014AFA5AB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA5AB000
|
Size: |
4096
|
|
14AF6DB4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3376420565.0000014AF6DB4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6DB4000
|
Size: |
16384
|
|
14AF9230000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3878160659.0000014AF9230000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
14AF9230000
|
Size: |
4096
|
|
1345000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.2617550384.0000000001345000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1345000
|
Size: |
4096
|
|
7FF62CE72000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000009.00000000.2820964088.00007FF62CE72000.00000008.00000001.01000000.0000000A.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF62CE72000
|
Size: |
401408
|
|
14AFA272000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3773639858.0000014AFA272000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA272000
|
Size: |
12288
|
|
25B9365B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2619509804.0000025B9365B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B9365B000
|
Size: |
4096
|
|
8DD000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3844811877.00000000008DD000.00000004.00000001.01000000.00000009.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
8DD000
|
Size: |
4096
|
|
19C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3006321930.000000000019C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
19C000
|
Size: |
16384
|
|
12D6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.2617490056.00000000012D6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12D6000
|
Size: |
8192
|
|
3231000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.2614380488.0000000003231000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3231000
|
Size: |
90112
|
|
14AFA42D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3367743010.0000014AFA42D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA42D000
|
Size: |
69632
|
|
1C610C6E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2864102015.000001C610C6E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610C6E000
|
Size: |
4096
|
|
32D8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.2617465262.00000000032D8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32D8000
|
Size: |
12288
|
|
14AFA474000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3768824745.0000014AFA474000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA474000
|
Size: |
4096
|
|
14AFA521000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3758288615.0000014AFA521000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA521000
|
Size: |
8192
|
|
14AF8B70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3428067871.0000014AF8B70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
14AF8B70000
|
Size: |
65536
|
|
22D1000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3002450710.00000000022D1000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
22D1000
|
Size: |
12288
|
|
25B933BD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2614325372.0000025B933BD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B933BD000
|
Size: |
49152
|
|
9AE51FF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2861319627.0000009AE51FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9AE51FF000
|
Size: |
4096
|
|
14AFA5FC000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3756605551.0000014AFA5FC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA5FC000
|
Size: |
167936
|
|
14AFA48E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3758288615.0000014AFA48E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA48E000
|
Size: |
40960
|
|
14AFA44E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3367743010.0000014AFA44E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA44E000
|
Size: |
49152
|
|
14AFA090000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3457001586.0000014AFA090000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
14AFA090000
|
Size: |
16384
|
|
4C0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3006489462.00000000004C0000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4C0000
|
Size: |
12288
|
|
14AFA206000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3022779938.0000014AFA206000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA206000
|
Size: |
4096
|
|
20000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3006180281.0000000000020000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
20000
|
Size: |
4096
|
|
C62000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2618293986.0000000000C62000.00000004.00000001.01000000.00000008.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
C62000
|
Size: |
8192
|
|
FB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2873159986.0000000000FB0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FB0000
|
Size: |
4096
|
|
14AFA506000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3886934188.0000014AFA506000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA506000
|
Size: |
4096
|
|
25B92AE9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2617118097.0000025B92AE9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AE9000
|
Size: |
16384
|
|
3840000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2979434887.0000000003840000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3840000
|
Size: |
12288
|
|
14AFA577000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3889368368.0000014AFA577000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA577000
|
Size: |
4096
|
|
1C60ED8E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2841053492.000001C60ED8E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C60ED8E000
|
Size: |
8192
|
|
14AFA30C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3370386257.0000014AFA30C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA30C000
|
Size: |
4096
|
|
14AF67D2000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2983407021.0000014AF67D2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF67D2000
|
Size: |
8192
|
|
87E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2993414243.000000000087E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
87E000
|
Size: |
8192
|
|
1C610EED000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2869079537.000001C610EED000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610EED000
|
Size: |
122880
|
|
14AFCF90000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3726920456.0000014AFCF90000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFCF90000
|
Size: |
16384
|
|
3225000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.2616337638.0000000003225000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3225000
|
Size: |
16384
|
|
23FE3AB1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3605034546.0000023FE3AB1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23FE3AB1000
|
Size: |
4096
|
|
25B933B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2622768718.0000025B933B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B933B0000
|
Size: |
86016
|
|
35FB000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2976746976.00000000035FB000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
35FB000
|
Size: |
331776
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1C610C68000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2835287498.000001C610C68000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610C68000
|
Size: |
4096
|
|
1C610BF9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2826999647.000001C610BF9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610BF9000
|
Size: |
32768
|
|
14AFA50D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3768824745.0000014AFA50D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA50D000
|
Size: |
4096
|
|
1C610C16000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2832467805.000001C610C16000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610C16000
|
Size: |
16384
|
|
14AFA3C0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3270713801.0000014AFA3C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA3C0000
|
Size: |
4096
|
|
14AFAE80000
|
remote allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3030071170.0000014AFAE80000.00000004.00000400.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
remote allocation
|
Protect: |
page read and write
|
Base address: |
14AFAE80000
|
Size: |
4096
|
|
14AFA4A6000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3367743010.0000014AFA4A6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA4A6000
|
Size: |
4096
|
|
14AF46F8000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3003685609.0000014AF46F8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF46F8000
|
Size: |
32768
|
|
14AF6D04000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3874939422.0000014AF6D04000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D04000
|
Size: |
16384
|
|
23FDE2E0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3848825005.0000023FDE2E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDE2E0000
|
Size: |
12288
|
|
3248000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.2614380488.0000000003248000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3248000
|
Size: |
16384
|
|
3666000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2976746976.0000000003666000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3666000
|
Size: |
4096
|
|
14AF6F96000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3728377952.0000014AF6F96000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6F96000
|
Size: |
8192
|
|
25B92AE5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2615607051.0000025B92AE5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AE5000
|
Size: |
40960
|
|
14AFA23A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3878988876.0000014AFA23A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA23A000
|
Size: |
8192
|
|
3580000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2600688470.0000000003580000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3580000
|
Size: |
1167360
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
14AF6DB5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3769746035.0000014AF6DB5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6DB5000
|
Size: |
12288
|
|
23FDF140000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3859664138.0000023FDF140000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23FDF140000
|
Size: |
4096
|
|
A71000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2604747824.0000000000A71000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A71000
|
Size: |
86016
|
|
37AF000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2979434887.00000000037AF000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
37AF000
|
Size: |
258048
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
14AFA28C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3370386257.0000014AFA28C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA28C000
|
Size: |
4096
|
|
25B92AD6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2620425975.0000025B92AD6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AD6000
|
Size: |
16384
|
|
12F5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.2616978038.00000000012F5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12F5000
|
Size: |
24576
|
|
14AFA22B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3271104935.0000014AFA22B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA22B000
|
Size: |
8192
|
|
14AFA3FC000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3884951730.0000014AFA3FC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA3FC000
|
Size: |
4096
|
|
322A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.2616337638.000000000322A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
322A000
|
Size: |
16384
|
|
23FDF858000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3860541877.0000023FDF858000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDF858000
|
Size: |
12288
|
|
23FE3BE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3865692335.0000023FE3BE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23FE3BE0000
|
Size: |
4096
|
|
14AFA3BC000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3884063493.0000014AFA3BC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA3BC000
|
Size: |
12288
|
|
25B92AF1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2615607051.0000025B92AF1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AF1000
|
Size: |
12288
|
|
14AF6D45000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3874939422.0000014AF6D45000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D45000
|
Size: |
4096
|
|
14AFA516000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3886934188.0000014AFA516000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA516000
|
Size: |
20480
|
|
23C31C8A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3853298147.0000023C31C8A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23C31C8A000
|
Size: |
36864
|
|
14AFA55B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3888677127.0000014AFA55B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA55B000
|
Size: |
12288
|
|
1C60EAF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2861624585.000001C60EAF0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C60EAF0000
|
Size: |
4096
|
|
14AFA44F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3884951730.0000014AFA44F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA44F000
|
Size: |
4096
|
|
14AFA4F2000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3886934188.0000014AFA4F2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA4F2000
|
Size: |
36864
|
|
25B92ADB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2620425975.0000025B92ADB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92ADB000
|
Size: |
36864
|
|
14AF9E5A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3428340956.0000014AF9E5A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
14AF9E5A000
|
Size: |
4096
|
|
AB6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2995563752.0000000000AB6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AB6000
|
Size: |
16384
|
|
65F2FB000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3846006562.000000065F2FB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
65F2FB000
|
Size: |
20480
|
|
1C610EA8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2849396421.000001C610EA8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610EA8000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1C610C00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2864102015.000001C610C00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610C00000
|
Size: |
8192
|
|
25B92C00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2622697688.0000025B92C00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92C00000
|
Size: |
8192
|
|
1348000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.2615167648.0000000001348000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1348000
|
Size: |
4096
|
|
A00000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000003.2976692715.0000000000A00000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
A00000
|
Size: |
4096
|
|
14AFA3EC000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3884951730.0000014AFA3EC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA3EC000
|
Size: |
4096
|
|
14AF6DB1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3270162678.0000014AF6DB1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6DB1000
|
Size: |
57344
|
|
1C610DF3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2865850100.000001C610DF3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610DF3000
|
Size: |
4096
|
|
14AFA299000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3018239583.0000014AFA299000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA299000
|
Size: |
16384
|
|
14AFA44D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3758288615.0000014AFA44D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA44D000
|
Size: |
69632
|
|
1C60ECD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2861872465.000001C60ECD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C60ECD0000
|
Size: |
24576
|
|
2313000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3002450710.0000000002313000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2313000
|
Size: |
4096
|
|
14AFA4D2000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3758288615.0000014AFA4D2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA4D2000
|
Size: |
77824
|
|
23FE3B80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3865568743.0000023FE3B80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23FE3B80000
|
Size: |
4096
|
|
1C610C2B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2826999647.000001C610C2B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610C2B000
|
Size: |
4096
|
|
AFF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2974959768.0000000000AFF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AFF000
|
Size: |
57344
|
|
23C31C7D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3851976269.0000023C31C7D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23C31C7D000
|
Size: |
4096
|
|
2293000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3002450710.0000000002293000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2293000
|
Size: |
98304
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
14AFA5AB000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3773300520.0000014AFA5AB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA5AB000
|
Size: |
12288
|
|
14AFA5BF000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3889368368.0000014AFA5BF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA5BF000
|
Size: |
4096
|
|
A61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2994259274.0000000000A61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A61000
|
Size: |
16384
|
|
23FDF8D8000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3863188664.0000023FDF8D8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDF8D8000
|
Size: |
69632
|
|
1C610F0C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2869079537.000001C610F0C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610F0C000
|
Size: |
319488
|
|
14AFA095000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3457001586.0000014AFA095000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
14AFA095000
|
Size: |
131072
|
|
130A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.2615167648.000000000130A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
130A000
|
Size: |
16384
|
|
5880000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2997870355.0000000005880000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5880000
|
Size: |
233472
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
23C31C2B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3849232971.0000023C31C2B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23C31C2B000
|
Size: |
77824
|
|
14AFA2D0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3263766967.0000014AFA2D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA2D0000
|
Size: |
143360
|
|
A80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2987673903.0000000000A80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A80000
|
Size: |
24576
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1A37725A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3849965384.000001A37725A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A37725A000
|
Size: |
81920
|
|
14AF6FA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3728377952.0000014AF6FA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6FA4000
|
Size: |
8192
|
|
14AF6F8E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3877141298.0000014AF6F8E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6F8E000
|
Size: |
24576
|
|
384E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2979434887.000000000384E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
384E000
|
Size: |
466944
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1A377302000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3852250882.000001A377302000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A377302000
|
Size: |
57344
|
|
106C000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3845307186.000000000106C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
106C000
|
Size: |
16384
|
|
400000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.2588569479.0000000000400000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
400000
|
Size: |
4096
|
|
14AF471E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3850235690.0000014AF471E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF471E000
|
Size: |
8192
|
|
25B92ADB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2617118097.0000025B92ADB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92ADB000
|
Size: |
12288
|
|
1C610C72000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2864102015.000001C610C72000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610C72000
|
Size: |
8192
|
|
4C2000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.2588720116.00000000004C2000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
4C2000
|
Size: |
8192
|
|
8D1000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000008.00000000.2798234498.00000000008D1000.00000002.00000001.01000000.00000009.sdmp
|
TargetID: |
8
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8D1000
|
Size: |
4096
|
|
7FF62CE72000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2872102494.00007FF62CE72000.00000004.00000001.01000000.0000000A.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF62CE72000
|
Size: |
32768
|
|
14AF6D95000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3025066090.0000014AF6D95000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D95000
|
Size: |
53248
|
|
8C6000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000008.00000002.2872933112.00000000008C6000.00000002.00000001.01000000.00000009.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8C6000
|
Size: |
4096
|
|
58BC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2974860767.00000000058BC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
58BC000
|
Size: |
8192
|
|
14AFA2A2000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3764667833.0000014AFA2A2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA2A2000
|
Size: |
24576
|
|
12F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.2616978038.00000000012F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12F0000
|
Size: |
16384
|
|
1A377313000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3853166848.000001A377313000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A377313000
|
Size: |
16384
|
|
A3F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2987989955.0000000000A3F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A3F000
|
Size: |
114688
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
AF2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2989345024.0000000000AF2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AF2000
|
Size: |
8192
|
|
5ACF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2999721108.0000000005ACF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5ACF000
|
Size: |
4096
|
|
C7BD37F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3847048020.000000C7BD37F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C7BD37F000
|
Size: |
4096
|
|
36CA000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2600688470.00000000036CA000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
36CA000
|
Size: |
12288
|
|
14AF6D3C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3874939422.0000014AF6D3C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D3C000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
14AFA3DC000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3758288615.0000014AFA3DC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA3DC000
|
Size: |
24576
|
|
23C31D00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3855783283.0000023C31D00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23C31D00000
|
Size: |
4096
|
|
23FDE476000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3853707315.0000023FDE476000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDE476000
|
Size: |
4096
|
|
14AFA4B2000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3758288615.0000014AFA4B2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA4B2000
|
Size: |
16384
|
|
67785FB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2622119279.00000067785FB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
67785FB000
|
Size: |
20480
|
|
14AFA42C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3270772372.0000014AFA42C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA42C000
|
Size: |
4096
|
|
1C610C65000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2864102015.000001C610C65000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610C65000
|
Size: |
8192
|
|
14AFAE80000
|
remote allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3030138210.0000014AFAE80000.00000004.00000400.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
remote allocation
|
Protect: |
page read and write
|
Base address: |
14AFAE80000
|
Size: |
4096
|
|
A81000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2994959903.0000000000A81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A81000
|
Size: |
16384
|
|
5C0E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2999822583.0000000005C0E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5C0E000
|
Size: |
8192
|
|
23FDE528000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3858647065.0000023FDE528000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDE528000
|
Size: |
8192
|
|
14AFA3EC000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3758288615.0000014AFA3EC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA3EC000
|
Size: |
4096
|
|
25B92ABB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2614377874.0000025B92ABB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92ABB000
|
Size: |
204800
|
|
745877C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3844808815.000000745877C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
745877C000
|
Size: |
16384
|
|
1C610C79000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2864102015.000001C610C79000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610C79000
|
Size: |
221184
|
|
C7BD2FE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3846888691.000000C7BD2FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C7BD2FE000
|
Size: |
8192
|
|
14AF6FEA000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3878084834.0000014AF6FEA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6FEA000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
63E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3006820931.000000000063E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
63E000
|
Size: |
8192
|
|
14AF6A1D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2990007298.0000014AF6A1D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6A1D000
|
Size: |
1310720
|
|
14AF6D99000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3769746035.0000014AF6D99000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D99000
|
Size: |
36864
|
|
25B92A8D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2615607051.0000025B92A8D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92A8D000
|
Size: |
28672
|
|
14AFA61B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3542348616.0000014AFA61B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA61B000
|
Size: |
266240
|
|
25B92AC8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2617118097.0000025B92AC8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AC8000
|
Size: |
4096
|
|
C7BC6AB000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3844476858.000000C7BC6AB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C7BC6AB000
|
Size: |
20480
|
|
1C61115A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2849459320.000001C61115A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C61115A000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1C610C28000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2831740785.000001C610C28000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610C28000
|
Size: |
24576
|
|
14AFA336000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3883304507.0000014AFA336000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA336000
|
Size: |
16384
|
|
14AFA3E5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3024758372.0000014AFA3E5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA3E5000
|
Size: |
94208
|
|
400000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000000.2597053530.0000000000400000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
400000
|
Size: |
4096
|
|
12FC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.2616978038.00000000012FC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12FC000
|
Size: |
16384
|
|
36B6000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2978529630.00000000036B6000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
36B6000
|
Size: |
8192
|
|
25B92A97000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2617118097.0000025B92A97000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92A97000
|
Size: |
4096
|
|
14AF692C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3863448666.0000014AF692C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF692C000
|
Size: |
12288
|
|
2812000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3000038312.0000000002812000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2812000
|
Size: |
4096
|
|
14AF6706000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3859631789.0000014AF6706000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6706000
|
Size: |
8192
|
|
14AFA46E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3886547689.0000014AFA46E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA46E000
|
Size: |
4096
|
|
1C610C1A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2831740785.000001C610C1A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610C1A000
|
Size: |
53248
|
|
14AFA5EB000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3757527512.0000014AFA5EB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA5EB000
|
Size: |
69632
|
|
14AF6A11000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3869220124.0000014AF6A11000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6A11000
|
Size: |
413696
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
14AFA2D2000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3882037559.0000014AFA2D2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA2D2000
|
Size: |
12288
|
|
25B933B9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2616771071.0000025B933B9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B933B9000
|
Size: |
16384
|
|
25B92AB5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2620425975.0000025B92AB5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AB5000
|
Size: |
40960
|
|
23FDE526000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3858588816.0000023FDE526000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDE526000
|
Size: |
4096
|
|
4B9000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3006489462.00000000004B9000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4B9000
|
Size: |
20480
|
|
4C6000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.2588907517.00000000004C6000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
4C6000
|
Size: |
143360
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
259A000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2982522590.000000000259A000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
259A000
|
Size: |
90112
|
|
2878000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3000038312.0000000002878000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2878000
|
Size: |
4096
|
|
14AFA150000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3455282613.0000014AFA150000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
14AFA150000
|
Size: |
65536
|
|
14AF6ADC000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2994340866.0000014AF6ADC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6ADC000
|
Size: |
4096
|
|
3580000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2601429558.0000000003580000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3580000
|
Size: |
8192
|
|
23FDE491000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3854585217.0000023FDE491000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDE491000
|
Size: |
4096
|
|
8C6000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.3844671657.00000000008C6000.00000002.00000001.01000000.00000009.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8C6000
|
Size: |
4096
|
|
1C611147000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2840616791.000001C611147000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C611147000
|
Size: |
4096
|
|
83E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2993339998.000000000083E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
83E000
|
Size: |
8192
|
|
A7A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2994259274.0000000000A7A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A7A000
|
Size: |
4096
|
|
10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2990050845.0000000000010000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10000
|
Size: |
4096
|
|
14AFA3B2000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3764667833.0000014AFA3B2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA3B2000
|
Size: |
77824
|
|
14AFA587000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3773300520.0000014AFA587000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA587000
|
Size: |
8192
|
|
14AFA5B0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3773300520.0000014AFA5B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA5B0000
|
Size: |
4096
|
|
14AFA2F6000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3882037559.0000014AFA2F6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA2F6000
|
Size: |
4096
|
|
14AFA1F1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3774222782.0000014AFA1F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA1F1000
|
Size: |
147456
|
|
7FF62CED3000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2872368686.00007FF62CED3000.00000004.00000001.01000000.0000000A.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF62CED3000
|
Size: |
20480
|
|
1C61104E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2837064403.000001C61104E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C61104E000
|
Size: |
1024000
|
|
14AFA4DF000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3367743010.0000014AFA4DF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA4DF000
|
Size: |
24576
|
|
14AFA45F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3758288615.0000014AFA45F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA45F000
|
Size: |
36864
|
|
14AFA3DC000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3884891369.0000014AFA3DC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA3DC000
|
Size: |
4096
|
|
23C31D02000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3855783283.0000023C31D02000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23C31D02000
|
Size: |
32768
|
|
14AF45D0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3850128366.0000014AF45D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF45D0000
|
Size: |
8192
|
|
23FDE413000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3850050123.0000023FDE413000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDE413000
|
Size: |
57344
|
|
14AFA461000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3884951730.0000014AFA461000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA461000
|
Size: |
4096
|
|
AAD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2620164643.0000000000AAD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AAD000
|
Size: |
155648
|
|
14AF4990000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3859314756.0000014AF4990000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF4990000
|
Size: |
16384
|
|
14AFA3AF000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3884063493.0000014AFA3AF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA3AF000
|
Size: |
4096
|
|
CC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2618327585.0000000000CC0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CC0000
|
Size: |
4096
|
|
14AFA30E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3370386257.0000014AFA30E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA30E000
|
Size: |
86016
|
|
23C31C00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3847501067.0000023C31C00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23C31C00000
|
Size: |
73728
|
|
7FF62CA83000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.2871929738.00007FF62CA83000.00000002.00000001.01000000.0000000A.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF62CA83000
|
Size: |
8192
|
|
1C60ED8B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2834956472.000001C60ED8B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C60ED8B000
|
Size: |
20480
|
|
14AFA2DB000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3882037559.0000014AFA2DB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA2DB000
|
Size: |
4096
|
|
23FDF865000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3860959703.0000023FDF865000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDF865000
|
Size: |
94208
|
|
14AFA2D0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3764667833.0000014AFA2D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA2D0000
|
Size: |
53248
|
|
14AF6DAB000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3270162678.0000014AF6DAB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6DAB000
|
Size: |
16384
|
|
25B92AAE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2620425975.0000025B92AAE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AAE000
|
Size: |
8192
|
|
12F9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.2615167648.00000000012F9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12F9000
|
Size: |
24576
|
|
36A5000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2978529630.00000000036A5000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
36A5000
|
Size: |
12288
|
|
14AFA254000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3271104935.0000014AFA254000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA254000
|
Size: |
135168
|
|
C11000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000005.00000000.2612545499.0000000000C11000.00000020.00000001.01000000.00000008.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
C11000
|
Size: |
217088
|
|
2828000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3000038312.0000000002828000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2828000
|
Size: |
4096
|
|
5870000
|
remote allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2954548283.0000000005870000.00000004.00000400.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
remote allocation
|
Protect: |
page read and write
|
Base address: |
5870000
|
Size: |
4096
|
|
25B92AAA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2615607051.0000025B92AAA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AAA000
|
Size: |
4096
|
|
9AE4EF9000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2861103579.0000009AE4EF9000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9AE4EF9000
|
Size: |
28672
|
|
14AF6D43000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3874939422.0000014AF6D43000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D43000
|
Size: |
4096
|
|
14AFA3CF000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3758288615.0000014AFA3CF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA3CF000
|
Size: |
8192
|
|
25B92A8B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2614377874.0000025B92A8B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92A8B000
|
Size: |
53248
|
|
1550000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2873985066.0000000001550000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1550000
|
Size: |
20480
|
|
14AFA626000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3756605551.0000014AFA626000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA626000
|
Size: |
8192
|
|
255C000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2982522590.000000000255C000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
255C000
|
Size: |
4096
|
|
25B93659000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2619509804.0000025B93659000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B93659000
|
Size: |
4096
|
|
14AFA48E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3367743010.0000014AFA48E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA48E000
|
Size: |
40960
|
|
C7BCAF8000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3845203492.000000C7BCAF8000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C7BCAF8000
|
Size: |
32768
|
|
1C610C07000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2826309523.000001C610C07000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610C07000
|
Size: |
8192
|
|
14AFA5FB000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3890223901.0000014AFA5FB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA5FB000
|
Size: |
4096
|
|
677867E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2622156873.000000677867E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
677867E000
|
Size: |
8192
|
|
1C610C2D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2835287498.000001C610C2D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610C2D000
|
Size: |
12288
|
|
1C60EDAF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2840733959.000001C60EDAF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C60EDAF000
|
Size: |
4096
|
|
14AF6D99000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3876793087.0000014AF6D99000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D99000
|
Size: |
8192
|
|
14AFA354000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3370386257.0000014AFA354000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA354000
|
Size: |
12288
|
|
14AFA603000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3542348616.0000014AFA603000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA603000
|
Size: |
8192
|
|
25B92A4F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2622523833.0000025B92A4F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92A4F000
|
Size: |
4096
|
|
AE9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2975294222.0000000000AE9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AE9000
|
Size: |
4096
|
|
7FF62CED3000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3892227764.00007FF62CED3000.00000004.00000001.01000000.0000000A.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF62CED3000
|
Size: |
20480
|
|
25B9364A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2619064374.0000025B9364A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B9364A000
|
Size: |
20480
|
|
1C610DF7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2865850100.000001C610DF7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610DF7000
|
Size: |
8192
|
|
14AF6D72000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3874939422.0000014AF6D72000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D72000
|
Size: |
4096
|
|
14AF4702000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3003685609.0000014AF4702000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF4702000
|
Size: |
8192
|
|
366D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2978529630.000000000366D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
366D000
|
Size: |
12288
|
|
14AFA501000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3886934188.0000014AFA501000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA501000
|
Size: |
8192
|
|
14AF6D5F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3874939422.0000014AF6D5F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D5F000
|
Size: |
8192
|
|
14AFA366000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3263766967.0000014AFA366000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA366000
|
Size: |
577536
|
|
123E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2618505331.000000000123E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
123E000
|
Size: |
8192
|
|
14AF4709000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2993577729.0000014AF4709000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF4709000
|
Size: |
94208
|
|
30C0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3847523261.00000000030C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C0000
|
Size: |
8192
|
|
65ECFE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3845411874.000000065ECFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
65ECFE000
|
Size: |
8192
|
|
1C610CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2865850100.000001C610CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610CE4000
|
Size: |
102400
|
|
23C3251D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3856422038.0000023C3251D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23C3251D000
|
Size: |
24576
|
|
1C610E10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2865850100.000001C610E10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610E10000
|
Size: |
45056
|
|
3674000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2978529630.0000000003674000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3674000
|
Size: |
16384
|
|
1A3771C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3846300712.000001A3771C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A3771C0000
|
Size: |
8192
|
|
14AFA3CF000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3884063493.0000014AFA3CF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA3CF000
|
Size: |
8192
|
|
12DD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.2616978038.00000000012DD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12DD000
|
Size: |
73728
|
|
A20000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2993816821.0000000000A20000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A20000
|
Size: |
28672
|
|
14AF688B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3863448666.0000014AF688B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF688B000
|
Size: |
4096
|
|
25B92AD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2616864427.0000025B92AD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AD0000
|
Size: |
4096
|
|
14AFA2F4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3370386257.0000014AFA2F4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA2F4000
|
Size: |
20480
|
|
10FC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2618446871.00000000010FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
10FC000
|
Size: |
16384
|
|
14AFA62A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3756605551.0000014AFA62A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA62A000
|
Size: |
12288
|
|
14AF48F0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3859224875.0000014AF48F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF48F0000
|
Size: |
8192
|
|
25B92AF1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2620425975.0000025B92AF1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AF1000
|
Size: |
12288
|
|
C5D000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2618270062.0000000000C5D000.00000004.00000001.01000000.00000008.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
C5D000
|
Size: |
4096
|
|
AA2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2620323665.0000000000AA2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AA2000
|
Size: |
45056
|
|
14AFA080000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3710729040.0000014AFA080000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA080000
|
Size: |
16384
|
|
25B928D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2622243122.0000025B928D0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B928D0000
|
Size: |
4096
|
|
1C610C31000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2835287498.000001C610C31000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610C31000
|
Size: |
4096
|
|
7458EFA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3846595618.0000007458EFA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7458EFA000
|
Size: |
24576
|
|
1C61115A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2852754753.000001C61115A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C61115A000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
23FDE4D0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3856283026.0000023FDE4D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDE4D0000
|
Size: |
61440
|
|
282F000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3000038312.000000000282F000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
282F000
|
Size: |
4096
|
|
14AF4721000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2993577729.0000014AF4721000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF4721000
|
Size: |
8192
|
|
14AF675A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3859631789.0000014AF675A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF675A000
|
Size: |
8192
|
|
14AFA336000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3370386257.0000014AFA336000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA336000
|
Size: |
36864
|
|
14AF670F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2983483868.0000014AF670F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF670F000
|
Size: |
94208
|
|
14AFA44E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3263766967.0000014AFA44E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA44E000
|
Size: |
258048
|
|
3832000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2979434887.0000000003832000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3832000
|
Size: |
8192
|
|
25B92AB7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2617118097.0000025B92AB7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AB7000
|
Size: |
32768
|
|
14AF6D15000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3874939422.0000014AF6D15000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D15000
|
Size: |
4096
|
|
25B92AAE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2617118097.0000025B92AAE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AAE000
|
Size: |
8192
|
|
14AFA518000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3768824745.0000014AFA518000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA518000
|
Size: |
8192
|
|
2566000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2982522590.0000000002566000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2566000
|
Size: |
4096
|
|
7458C7B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3845914263.0000007458C7B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7458C7B000
|
Size: |
20480
|
|
37FF000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2979434887.00000000037FF000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
37FF000
|
Size: |
36864
|
|
14AFA27A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3375292147.0000014AFA27A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA27A000
|
Size: |
8192
|
|
745830B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3844517997.000000745830B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
745830B000
|
Size: |
20480
|
|
23FDE280000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3848755547.0000023FDE280000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDE280000
|
Size: |
4096
|
|
14AF6D7C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3769746035.0000014AF6D7C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D7C000
|
Size: |
57344
|
|
14AFA46A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3378279680.0000014AFA46A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA46A000
|
Size: |
4096
|
|
380E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2979434887.000000000380E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
380E000
|
Size: |
8192
|
|
14AFA30E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3764667833.0000014AFA30E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA30E000
|
Size: |
4096
|
|
14AFA26E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3022779938.0000014AFA26E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA26E000
|
Size: |
8192
|
|
23C31CC8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3853737586.0000023C31CC8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23C31CC8000
|
Size: |
45056
|
|
23FDF847000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3860090942.0000023FDF847000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDF847000
|
Size: |
49152
|
|
23C32584000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3857215983.0000023C32584000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23C32584000
|
Size: |
36864
|
|
14AFA4A2000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3886934188.0000014AFA4A2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA4A2000
|
Size: |
4096
|
|
14AF6F87000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3543888438.0000014AF6F87000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6F87000
|
Size: |
32768
|
|
1C60ED6B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2861872465.000001C60ED6B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C60ED6B000
|
Size: |
4096
|
|
1C61101D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2869079537.000001C61101D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C61101D000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
14AFA265000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3773639858.0000014AFA265000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA265000
|
Size: |
49152
|
|
25B93664000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2618908306.0000025B93664000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B93664000
|
Size: |
16384
|
|
14AF6F9A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3322983776.0000014AF6F9A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6F9A000
|
Size: |
65536
|
|
1C60ECEB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2861872465.000001C60ECEB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C60ECEB000
|
Size: |
86016
|
|
1C60EC93000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2861769305.000001C60EC93000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C60EC93000
|
Size: |
12288
|
|
14AF6A7F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3869220124.0000014AF6A7F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6A7F000
|
Size: |
40960
|
|
2836000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3000038312.0000000002836000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2836000
|
Size: |
4096
|
|
369E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2600688470.000000000369E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
369E000
|
Size: |
90112
|
|
25B9364A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2619627883.0000025B9364A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B9364A000
|
Size: |
4096
|
|
3798000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2979434887.0000000003798000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3798000
|
Size: |
8192
|
|
3C2E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2997662847.0000000003C2E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3C2E000
|
Size: |
8192
|
|
14AF6781000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3859631789.0000014AF6781000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6781000
|
Size: |
102400
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
23FDEE01000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3859564678.0000023FDEE01000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23FDEE01000
|
Size: |
4096
|
|
23FDE4A3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3854585217.0000023FDE4A3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDE4A3000
|
Size: |
4096
|
|
1301000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.2616978038.0000000001301000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1301000
|
Size: |
16384
|
|
14AF66C0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3859631789.0000014AF66C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF66C0000
|
Size: |
274432
|
|
35000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2990142028.0000000000035000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35000
|
Size: |
8192
|
|
14AFA2CD000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3764667833.0000014AFA2CD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA2CD000
|
Size: |
8192
|
|
2570000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2590484835.0000000002570000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2570000
|
Size: |
937984
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
14AFA2D8000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3882037559.0000014AFA2D8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA2D8000
|
Size: |
4096
|
|
C7BD0FE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3846484657.000000C7BD0FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C7BD0FE000
|
Size: |
8192
|
|
25B92ACE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2617118097.0000025B92ACE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92ACE000
|
Size: |
28672
|
|
14AFA3AC000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3764667833.0000014AFA3AC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA3AC000
|
Size: |
20480
|
|
1C610CD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2865850100.000001C610CD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610CD0000
|
Size: |
69632
|
|
3815000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2979434887.0000000003815000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3815000
|
Size: |
4096
|
|
1C60ED90000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2840733959.000001C60ED90000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C60ED90000
|
Size: |
32768
|
|
14AFA3D3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3271933226.0000014AFA3D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA3D3000
|
Size: |
4096
|
|
3280000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2874166429.0000000003280000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3280000
|
Size: |
8192
|
|
14AF673D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3003933977.0000014AF673D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF673D000
|
Size: |
20480
|
|
14AFA3B3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3270831776.0000014AFA3B3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA3B3000
|
Size: |
4096
|
|
59CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2999658713.00000000059CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
59CE000
|
Size: |
8192
|
|
23C31C3F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3850060207.0000023C31C3F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23C31C3F000
|
Size: |
180224
|
|
7FF62CE81000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3892075190.00007FF62CE81000.00000004.00000001.01000000.0000000A.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF62CE81000
|
Size: |
8192
|
|
28E3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2997369947.00000000028E3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
28E3000
|
Size: |
36864
|
|
14AFA275000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3764667833.0000014AFA275000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA275000
|
Size: |
176128
|
|
B0A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2996841123.0000000000B0A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B0A000
|
Size: |
8192
|
|
FC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2873206052.0000000000FC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FC0000
|
Size: |
4096
|
|
14AFA2DE000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3764667833.0000014AFA2DE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA2DE000
|
Size: |
61440
|
|
14AFA2DC000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3370386257.0000014AFA2DC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA2DC000
|
Size: |
69632
|
|
1C610C19000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2826999647.000001C610C19000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610C19000
|
Size: |
4096
|
|
14AF6896000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3863448666.0000014AF6896000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6896000
|
Size: |
36864
|
|
14AF673A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2983483868.0000014AF673A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF673A000
|
Size: |
4096
|
|
500000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3006703522.0000000000500000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
500000
|
Size: |
4096
|
|
25B9364E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2619237774.0000025B9364E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B9364E000
|
Size: |
4096
|
|
14AF6CD4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3874409388.0000014AF6CD4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6CD4000
|
Size: |
4096
|
|
2819000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3000038312.0000000002819000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2819000
|
Size: |
4096
|
|
1C60ED42000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2861872465.000001C60ED42000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C60ED42000
|
Size: |
163840
|
|
2D70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2997578205.0000000002D70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D70000
|
Size: |
4096
|
|
14AFA38C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3370386257.0000014AFA38C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA38C000
|
Size: |
4096
|
|
1C610C25000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2826999647.000001C610C25000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610C25000
|
Size: |
4096
|
|
AE9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2989345024.0000000000AE9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AE9000
|
Size: |
4096
|
|
1C60EDC5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2861872465.000001C60EDC5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C60EDC5000
|
Size: |
4096
|
|
401000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000002.00000000.2597083830.0000000000401000.00000020.00000001.01000000.00000005.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
401000
|
Size: |
2908160
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
25B92A6D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2622547098.0000025B92A6D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92A6D000
|
Size: |
4096
|
|
14AFA21A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3022779938.0000014AFA21A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA21A000
|
Size: |
16384
|
|
25B92AB2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2615607051.0000025B92AB2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AB2000
|
Size: |
8192
|
|
14AFA4A0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3768824745.0000014AFA4A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA4A0000
|
Size: |
4096
|
|
14AF6EB3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2994571877.0000014AF6EB3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6EB3000
|
Size: |
4096
|
|
14AF46E2000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3850235690.0000014AF46E2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF46E2000
|
Size: |
241664
|
|
1C610CC9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2865850100.000001C610CC9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610CC9000
|
Size: |
12288
|
|
14AFA35F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3764667833.0000014AFA35F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA35F000
|
Size: |
16384
|
|
23C31D13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3856199005.0000023C31D13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23C31D13000
|
Size: |
8192
|
|
58C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2999610902.00000000058C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
58C1000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
14AFA2D0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3882037559.0000014AFA2D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA2D0000
|
Size: |
4096
|
|
1C61103E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2840685341.000001C61103E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C61103E000
|
Size: |
4096
|
|
1C610F63000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2869079537.000001C610F63000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610F63000
|
Size: |
143360
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
14AFA5E3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3890223901.0000014AFA5E3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA5E3000
|
Size: |
4096
|
|
1C61115C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2848416927.000001C61115C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C61115C000
|
Size: |
524288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
14AFA323000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3882037559.0000014AFA323000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA323000
|
Size: |
12288
|
|
15AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2618726362.00000000015AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
15AE000
|
Size: |
8192
|
|
14AFA4A9000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3367743010.0000014AFA4A9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA4A9000
|
Size: |
4096
|
|
14AFA34E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3883304507.0000014AFA34E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA34E000
|
Size: |
12288
|
|
1C610C0C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2826309523.000001C610C0C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610C0C000
|
Size: |
155648
|
|
14AF6740000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2983483868.0000014AF6740000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6740000
|
Size: |
4096
|
|
23FDE4E2000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3856283026.0000023FDE4E2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDE4E2000
|
Size: |
53248
|
|
14AFA470000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3886547689.0000014AFA470000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA470000
|
Size: |
20480
|
|
14AFA292000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3880400710.0000014AFA292000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA292000
|
Size: |
32768
|
|
14AF6F96000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3543888438.0000014AF6F96000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6F96000
|
Size: |
8192
|
|
14AFA34C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3370386257.0000014AFA34C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA34C000
|
Size: |
4096
|
|
14AFA485000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3886934188.0000014AFA485000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA485000
|
Size: |
16384
|
|
14AFA3E7000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3884951730.0000014AFA3E7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA3E7000
|
Size: |
8192
|
|
C7BD1FF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3846768254.000000C7BD1FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C7BD1FF000
|
Size: |
4096
|
|
1C61115C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2847149683.000001C61115C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C61115C000
|
Size: |
524288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
A49000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2994259274.0000000000A49000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A49000
|
Size: |
20480
|
|
14AF9C70000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3878226382.0000014AF9C70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF9C70000
|
Size: |
65536
|
|
1C611522000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2857069513.000001C611522000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C611522000
|
Size: |
1540096
|
|
AD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2995563752.0000000000AD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AD0000
|
Size: |
4096
|
|
14AFA413000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3884951730.0000014AFA413000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA413000
|
Size: |
40960
|
|
25B92AF7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2620425975.0000025B92AF7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AF7000
|
Size: |
12288
|
|
2321000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3002450710.0000000002321000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2321000
|
Size: |
4096
|
|
AFD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2975294222.0000000000AFD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AFD000
|
Size: |
8192
|
|
382A000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2979434887.000000000382A000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
382A000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1C611520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2845349701.000001C611520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1C611520000
|
Size: |
16384
|
|
1C610D53000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2828466109.000001C610D53000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610D53000
|
Size: |
20480
|
|
1C610EA8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2852677915.000001C610EA8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610EA8000
|
Size: |
20480
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
14AFA344000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3263766967.0000014AFA344000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA344000
|
Size: |
36864
|
|
14AFA474000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3773237830.0000014AFA474000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA474000
|
Size: |
4096
|
|
6C9000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2992447779.00000000006C9000.00000004.00000001.01000000.00000005.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
6C9000
|
Size: |
12288
|
|
23FDE42B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3851069633.0000023FDE42B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDE42B000
|
Size: |
98304
|
|
283D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3000038312.000000000283D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
283D000
|
Size: |
4096
|
|
14AFA3E3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3758288615.0000014AFA3E3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA3E3000
|
Size: |
32768
|
|
14AFA519000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3366647948.0000014AFA519000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA519000
|
Size: |
4096
|
|
1C610E0C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2865850100.000001C610E0C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610E0C000
|
Size: |
12288
|
|
23FE3AB4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3605034546.0000023FE3AB4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23FE3AB4000
|
Size: |
139264
|
|
14AFA49E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3758288615.0000014AFA49E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA49E000
|
Size: |
24576
|
|
14AFA3F6000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3370386257.0000014AFA3F6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA3F6000
|
Size: |
28672
|
|
25B92AD6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2615607051.0000025B92AD6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AD6000
|
Size: |
16384
|
|
1C60ECD7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2861872465.000001C60ECD7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C60ECD7000
|
Size: |
77824
|
|
14AFA226000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3022779938.0000014AFA226000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA226000
|
Size: |
16384
|
|
14AFA5E4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3542348616.0000014AFA5E4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA5E4000
|
Size: |
8192
|
|
14AF6917000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3863448666.0000014AF6917000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6917000
|
Size: |
12288
|
|
14AFA465000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3886547689.0000014AFA465000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA465000
|
Size: |
4096
|
|
14AFA20C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3878988876.0000014AFA20C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA20C000
|
Size: |
4096
|
|
1C610BEC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2864102015.000001C610BEC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610BEC000
|
Size: |
28672
|
|
14AF6F78000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3543888438.0000014AF6F78000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6F78000
|
Size: |
12288
|
|
25B92A85000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2614927663.0000025B92A85000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92A85000
|
Size: |
12288
|
|
14AFA29E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3018239583.0000014AFA29E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA29E000
|
Size: |
110592
|
|
14AFA32E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3378343394.0000014AFA32E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA32E000
|
Size: |
4096
|
|
369E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2978529630.000000000369E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
369E000
|
Size: |
12288
|
|
23FDED13000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3859376696.0000023FDED13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDED13000
|
Size: |
24576
|
|
14AF684F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2985383781.0000014AF684F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF684F000
|
Size: |
167936
|
|
7FF62CE7F000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3892075190.00007FF62CE7F000.00000004.00000001.01000000.0000000A.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF62CE7F000
|
Size: |
4096
|
|
14AF6717000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2982424778.0000014AF6717000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6717000
|
Size: |
8192
|
|
7FF62CE77000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3891819941.00007FF62CE77000.00000004.00000001.01000000.0000000A.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF62CE77000
|
Size: |
8192
|
|
14AFA63D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3756605551.0000014AFA63D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA63D000
|
Size: |
4096
|
|
6D1000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2993039881.00000000006D1000.00000004.00000001.01000000.00000005.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
6D1000
|
Size: |
12288
|
|
1C60ED70000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2831327443.000001C60ED70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C60ED70000
|
Size: |
286720
|
|
14AFAE80000
|
remote allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3030193777.0000014AFAE80000.00000004.00000400.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
remote allocation
|
Protect: |
page read and write
|
Base address: |
14AFAE80000
|
Size: |
4096
|
|
25B92A79000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2620425975.0000025B92A79000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92A79000
|
Size: |
36864
|
|
14AF6D0F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3874939422.0000014AF6D0F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D0F000
|
Size: |
8192
|
|
23FE3AA1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3670588553.0000023FE3AA1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23FE3AA1000
|
Size: |
4096
|
|
25B92A8C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2617118097.0000025B92A8C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92A8C000
|
Size: |
32768
|
|
25B93643000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2619197809.0000025B93643000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B93643000
|
Size: |
8192
|
|
1C610BEA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2826999647.000001C610BEA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610BEA000
|
Size: |
24576
|
|
1A377150000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3846053733.000001A377150000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A377150000
|
Size: |
4096
|
|
7FF62CEFF000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3892227764.00007FF62CEFF000.00000004.00000001.01000000.0000000A.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF62CEFF000
|
Size: |
32768
|
|
30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2990142028.0000000000030000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30000
|
Size: |
12288
|
|
1C610C0F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2864102015.000001C610C0F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610C0F000
|
Size: |
8192
|
|
23FE3BF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3865745046.0000023FE3BF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23FE3BF0000
|
Size: |
4096
|
|
25B93647000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2619309449.0000025B93647000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B93647000
|
Size: |
4096
|
|
23C31A10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3847007070.0000023C31A10000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23C31A10000
|
Size: |
4096
|
|
14AFA336000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3764667833.0000014AFA336000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA336000
|
Size: |
32768
|
|
D4C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2618369043.0000000000D4C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
D4C000
|
Size: |
16384
|
|
14AFA507000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3366647948.0000014AFA507000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA507000
|
Size: |
4096
|
|
285A000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3000038312.000000000285A000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
285A000
|
Size: |
4096
|
|
14AFA57B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3889368368.0000014AFA57B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA57B000
|
Size: |
12288
|
|
14AFA50D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3886934188.0000014AFA50D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA50D000
|
Size: |
20480
|
|
65F9FF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3847807326.000000065F9FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
65F9FF000
|
Size: |
4096
|
|
1A377160000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3846133787.000001A377160000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A377160000
|
Size: |
4096
|
|
23FDEBD1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3858723683.0000023FDEBD1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23FDEBD1000
|
Size: |
4096
|
|
C7BC72D000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3844685017.000000C7BC72D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C7BC72D000
|
Size: |
12288
|
|
25B92A8C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2622547098.0000025B92A8C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92A8C000
|
Size: |
4096
|
|
324D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.2614380488.000000000324D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
324D000
|
Size: |
16384
|
|
1C611021000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2869079537.000001C611021000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C611021000
|
Size: |
53248
|
|
1C610BE1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2827718509.000001C610BE1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610BE1000
|
Size: |
4096
|
|
14AFA3D3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3375614107.0000014AFA3D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA3D3000
|
Size: |
4096
|
|
23FDE444000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3852438344.0000023FDE444000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDE444000
|
Size: |
102400
|
|
14AF4995000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3859314756.0000014AF4995000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF4995000
|
Size: |
40960
|
|
A5D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2987989955.0000000000A5D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A5D000
|
Size: |
32768
|
|
A73000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2994259274.0000000000A73000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A73000
|
Size: |
8192
|
|
132D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.2615167648.000000000132D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
132D000
|
Size: |
106496
|
|
C7BCCFE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3845745439.000000C7BCCFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C7BCCFE000
|
Size: |
8192
|
|
21F3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3002450710.00000000021F3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
21F3000
|
Size: |
598016
|
|
14AFA254000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3878988876.0000014AFA254000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA254000
|
Size: |
4096
|
|
8C6000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000008.00000000.2798234498.00000000008C6000.00000002.00000001.01000000.00000009.sdmp
|
TargetID: |
8
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8C6000
|
Size: |
8192
|
|
25B92AB2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2617118097.0000025B92AB2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92AB2000
|
Size: |
8192
|
|
891000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000008.00000000.2798027259.0000000000891000.00000020.00000001.01000000.00000009.sdmp
|
TargetID: |
8
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
891000
|
Size: |
217088
|
|
9AE50FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2861266118.0000009AE50FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9AE50FE000
|
Size: |
8192
|
|
59B9DFF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3845534403.00000059B9DFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
59B9DFF000
|
Size: |
4096
|
|
A9D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2995130497.0000000000A9D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A9D000
|
Size: |
4096
|
|
14AFA47C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3886934188.0000014AFA47C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA47C000
|
Size: |
32768
|
|
DE0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3845148804.0000000000DE0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DE0000
|
Size: |
4096
|
|
1C610C0A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2864102015.000001C610C0A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610C0A000
|
Size: |
12288
|
|
14AFA49E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3886934188.0000014AFA49E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA49E000
|
Size: |
4096
|
|
14AFA275000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3270461517.0000014AFA275000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA275000
|
Size: |
12288
|
|
1397000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2873363687.0000000001397000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1397000
|
Size: |
126976
|
|
1220000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3846003823.0000000001220000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1220000
|
Size: |
20480
|
|
1C610D5F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2865850100.000001C610D5F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610D5F000
|
Size: |
40960
|
|
14AF6D81000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3874939422.0000014AF6D81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D81000
|
Size: |
28672
|
|
AE3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2995563752.0000000000AE3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AE3000
|
Size: |
8192
|
|
14AFA310000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3764667833.0000014AFA310000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA310000
|
Size: |
45056
|
|
14AF6D31000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3874939422.0000014AF6D31000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D31000
|
Size: |
4096
|
|
14AF696F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3863448666.0000014AF696F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF696F000
|
Size: |
327680
|
|
23FDF8A8000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3860959703.0000023FDF8A8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDF8A8000
|
Size: |
69632
|
|
4B7000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3006489462.00000000004B7000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4B7000
|
Size: |
4096
|
|
14AF67E0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3863448666.0000014AF67E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF67E0000
|
Size: |
90112
|
|
14AFA3D3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3884830427.0000014AFA3D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA3D3000
|
Size: |
4096
|
|
14AFA3D9000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3758288615.0000014AFA3D9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA3D9000
|
Size: |
8192
|
|
59B9FFC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3845742272.00000059B9FFC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
59B9FFC000
|
Size: |
16384
|
|
1C60EDB5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2840733959.000001C60EDB5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C60EDB5000
|
Size: |
69632
|
|
14AFA504000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3768824745.0000014AFA504000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA504000
|
Size: |
12288
|
|
25B93650000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2619509804.0000025B93650000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B93650000
|
Size: |
28672
|
|
14AFA51D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3886934188.0000014AFA51D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA51D000
|
Size: |
4096
|
|
AA5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2995130497.0000000000AA5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AA5000
|
Size: |
24576
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
25B92A2A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2620425975.0000025B92A2A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92A2A000
|
Size: |
155648
|
|
AA2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2987248644.0000000000AA2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AA2000
|
Size: |
4096
|
|
14AF6D63000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3874939422.0000014AF6D63000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D63000
|
Size: |
8192
|
|
1C610E57000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.2865850100.000001C610E57000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C610E57000
|
Size: |
331776
|
|
677857E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2622087269.000000677857E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
677857E000
|
Size: |
8192
|
|
14AF48E3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3858784784.0000014AF48E3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF48E3000
|
Size: |
49152
|
|
14AFA5DA000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3890223901.0000014AFA5DA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA5DA000
|
Size: |
24576
|
|
AFB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2989345024.0000000000AFB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AFB000
|
Size: |
4096
|
|
25B92B09000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2617118097.0000025B92B09000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B92B09000
|
Size: |
24576
|
|
25B93666000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.2619026014.0000025B93666000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25B93666000
|
Size: |
8192
|
|
23FDED19000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3656699104.0000023FDED19000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDED19000
|
Size: |
4096
|
|
3220000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.2614380488.0000000003220000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3220000
|
Size: |
36864
|
|
14AFA615000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3890904090.0000014AFA615000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AFA615000
|
Size: |
12288
|
|
9AF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3007890469.00000000009AF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9AF000
|
Size: |
4096
|
|
14AF48E0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3858784784.0000014AF48E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF48E0000
|
Size: |
8192
|
|
23FDF862000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3860541877.0000023FDF862000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDF862000
|
Size: |
8192
|
|
23FDF800000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3860090942.0000023FDF800000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23FDF800000
|
Size: |
8192
|
|
37F0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2979434887.00000000037F0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
37F0000
|
Size: |
40960
|
|
14AF4640000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3850235690.0000014AF4640000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF4640000
|
Size: |
32768
|
|
14AF6D42000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.3769746035.0000014AF6D42000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AF6D42000
|
Size: |
114688
|
|
18D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2990593891.000000000018D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
18D000
|
Size: |
77824
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|