750000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1325510660.0000000000750000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
750000
|
Size: |
16384
|
|
1A658113000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3122309484.000001A658113000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658113000
|
Size: |
131072
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
BB305FE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000002.3118746098.000000BB305FE000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BB305FE000
|
Size: |
4096
|
|
24043928000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3120508374.0000024043928000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
24043928000
|
Size: |
24576
|
|
1A658176000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3122479263.000001A658176000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658176000
|
Size: |
4096
|
|
34561FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1369811874.00000034561FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
34561FE000
|
Size: |
8192
|
|
1A658159000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2659244813.000001A658159000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658159000
|
Size: |
4096
|
|
22054625000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3118642594.0000022054625000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22054625000
|
Size: |
20480
|
|
2413E602000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3120677272.000002413E602000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2413E602000
|
Size: |
65536
|
|
1A6577C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3120682629.000001A6577C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1A6577C0000
|
Size: |
4096
|
|
BB303FE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000002.3118592426.000000BB303FE000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BB303FE000
|
Size: |
4096
|
|
188FD66E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1369211649.00000188FD66E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD66E000
|
Size: |
90112
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1A6578E5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3121755751.000001A6578E5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A6578E5000
|
Size: |
12288
|
|
2413E600000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3120677272.000002413E600000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2413E600000
|
Size: |
4096
|
|
24043650000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3118594049.0000024043650000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
24043650000
|
Size: |
4096
|
|
1A658611000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3122586708.000001A658611000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658611000
|
Size: |
4096
|
|
1A658155000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2658640169.000001A658155000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658155000
|
Size: |
20480
|
|
784A37B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3119013723.000000784A37B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
784A37B000
|
Size: |
20480
|
|
1C0000
|
unclassified section
|
page readonly
|
|
|
|
Name: |
00000002.00000002.1325049132.00000000001C0000.00000002.10000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page readonly
|
Base address: |
1C0000
|
Size: |
4096
|
|
1A65815B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2658699630.000001A65815B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A65815B000
|
Size: |
4096
|
|
240437B0000
|
remote allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1276077234.00000240437B0000.00000004.00000400.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
remote allocation
|
Protect: |
page read and write
|
Base address: |
240437B0000
|
Size: |
4096
|
|
2314DC46000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1278773999.000002314DC46000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2314DC46000
|
Size: |
4096
|
|
24043813000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3119058720.0000024043813000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
24043813000
|
Size: |
90112
|
|
188FD636000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1369940841.00000188FD636000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD636000
|
Size: |
40960
|
|
188FD64C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1369306162.00000188FD64C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD64C000
|
Size: |
8192
|
|
1DCA8BA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3118516371.000001DCA8BA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DCA8BA0000
|
Size: |
4096
|
|
188FD64E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1369193547.00000188FD64E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD64E000
|
Size: |
4096
|
|
1A658000000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3122102382.000001A658000000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658000000
|
Size: |
4096
|
|
2314E402000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3121508908.000002314E402000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2314E402000
|
Size: |
4096
|
|
2E0F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1326004292.0000000002E0F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2E0F000
|
Size: |
4096
|
|
24045202000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3120603214.0000024045202000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24045202000
|
Size: |
4096
|
|
188FD661000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1369270569.00000188FD661000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD661000
|
Size: |
24576
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
188FD642000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1369956943.00000188FD642000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD642000
|
Size: |
24576
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
AEF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1325737081.0000000000AEF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
AEF000
|
Size: |
4096
|
|
7849E7E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3118259381.0000007849E7E000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7849E7E000
|
Size: |
4096
|
|
26C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1325935243.00000000026C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
26C0000
|
Size: |
8192
|
|
DC5BB9C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3118025414.000000DC5BB9C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
DC5BB9C000
|
Size: |
16384
|
|
2C10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1325990488.0000000002C10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C10000
|
Size: |
4096
|
|
1A658655000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3123030218.000001A658655000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658655000
|
Size: |
32768
|
|
2314DB20000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3120680130.000002314DB20000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2314DB20000
|
Size: |
4096
|
|
619F7FE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3118302538.000000619F7FE000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
619F7FE000
|
Size: |
4096
|
|
3455FFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1369786728.0000003455FFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3455FFE000
|
Size: |
8192
|
|
1A658174000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2667459109.000001A658174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658174000
|
Size: |
12288
|
|
61A01FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3119220467.00000061A01FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
61A01FE000
|
Size: |
8192
|
|
24043760000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3118749015.0000024043760000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24043760000
|
Size: |
4096
|
|
188FD641000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1369477861.00000188FD641000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD641000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
61A03FD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3119374247.00000061A03FD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
61A03FD000
|
Size: |
12288
|
|
188FD68E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1369120992.00000188FD68E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD68E000
|
Size: |
4096
|
|
784A97C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3119753591.000000784A97C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
784A97C000
|
Size: |
16384
|
|
1A658666000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2664988081.000001A658666000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658666000
|
Size: |
32768
|
|
2413E550000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3120597752.000002413E550000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2413E550000
|
Size: |
4096
|
|
1A658132000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2659554120.000001A658132000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658132000
|
Size: |
8192
|
|
34560FE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1369799539.00000034560FE000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
34560FE000
|
Size: |
4096
|
|
1A658156000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2659244813.000001A658156000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658156000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
BB304FC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3118662799.000000BB304FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BB304FC000
|
Size: |
16384
|
|
1A658167000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2659054333.000001A658167000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658167000
|
Size: |
16384
|
|
2205468D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3119688171.000002205468D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2205468D000
|
Size: |
8192
|
|
784A67E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3119314201.000000784A67E000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
784A67E000
|
Size: |
4096
|
|
1A6578C6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3121630073.000001A6578C6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A6578C6000
|
Size: |
20480
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2314DC00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3120981144.000002314DC00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2314DC00000
|
Size: |
4096
|
|
99000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1325004877.0000000000099000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
99000
|
Size: |
28672
|
|
22054E15000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3120931295.0000022054E15000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22054E15000
|
Size: |
4096
|
|
569000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
00000002.00000002.1325340738.0000000000569000.00000080.00000001.01000000.00000003.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
569000
|
Size: |
372736
|
|
1DCA8C85000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3119660448.000001DCA8C85000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DCA8C85000
|
Size: |
151552
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
220545E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3118231694.00000220545E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
220545E0000
|
Size: |
8192
|
|
1DCA9402000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3120306265.000001DCA9402000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DCA9402000
|
Size: |
4096
|
|
4B804AB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3118148876.0000004B804AB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4B804AB000
|
Size: |
20480
|
|
1A65792B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2667848832.000001A65792B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A65792B000
|
Size: |
12288
|
|
188FD631000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1369511509.00000188FD631000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD631000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2500000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1325853895.0000000002500000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2500000
|
Size: |
4096
|
|
784A57A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3119241982.000000784A57A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
784A57A000
|
Size: |
24576
|
|
1A658655000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2664945691.000001A658655000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658655000
|
Size: |
40960
|
|
22054700000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3119888572.0000022054700000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22054700000
|
Size: |
4096
|
|
24043841000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3119323544.0000024043841000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
24043841000
|
Size: |
122880
|
|
388A67B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3118028129.000000388A67B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
388A67B000
|
Size: |
20480
|
|
188FD64B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1369396215.00000188FD64B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD64B000
|
Size: |
4096
|
|
22054600000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3118331108.0000022054600000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22054600000
|
Size: |
4096
|
|
188FD660000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1369290585.00000188FD660000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD660000
|
Size: |
4096
|
|
188FD4E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1369851488.00000188FD4E0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD4E0000
|
Size: |
4096
|
|
1DCA8B90000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3118284435.000001DCA8B90000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DCA8B90000
|
Size: |
4096
|
|
2B0F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1325964956.0000000002B0F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2B0F000
|
Size: |
4096
|
|
24043860000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3119323544.0000024043860000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
24043860000
|
Size: |
65536
|
|
1DCA8C68000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3119258980.000001DCA8C68000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DCA8C68000
|
Size: |
90112
|
|
24043800000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3118899274.0000024043800000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
24043800000
|
Size: |
4096
|
|
1A6578BA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2660126615.000001A6578BA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A6578BA000
|
Size: |
36864
|
|
1DCA8BD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3118599101.000001DCA8BD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1DCA8BD0000
|
Size: |
4096
|
|
188FD68E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1370052587.00000188FD68E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD68E000
|
Size: |
4096
|
|
784A27E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3118940099.000000784A27E000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
784A27E000
|
Size: |
4096
|
|
DC5BFFF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3118256899.000000DC5BFFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
DC5BFFF000
|
Size: |
4096
|
|
400000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000000.1272733968.0000000000400000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
400000
|
Size: |
4096
|
|
61A07FE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3120000523.00000061A07FE000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
61A07FE000
|
Size: |
4096
|
|
BB308FE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000002.3119050808.000000BB308FE000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BB308FE000
|
Size: |
4096
|
|
1A6578EB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3121755751.000001A6578EB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A6578EB000
|
Size: |
24576
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
1A657880000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3121235179.000001A657880000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A657880000
|
Size: |
8192
|
|
345557B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1369654287.000000345557B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
345557B000
|
Size: |
20480
|
|
1A658152000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2659244813.000001A658152000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658152000
|
Size: |
4096
|
|
1A658127000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2659010451.000001A658127000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658127000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
BB30BFE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000002.3119522176.000000BB30BFE000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BB30BFE000
|
Size: |
4096
|
|
DC5C17E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3118324703.000000DC5C17E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
DC5C17E000
|
Size: |
8192
|
|
188FD66C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1369233504.00000188FD66C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD66C000
|
Size: |
8192
|
|
C29000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1325776012.0000000000C29000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C29000
|
Size: |
16384
|
|
1A65864C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3122963831.000001A65864C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A65864C000
|
Size: |
32768
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
619F77E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3118213586.000000619F77E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
619F77E000
|
Size: |
8192
|
|
188FD6AA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1370107707.00000188FD6AA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD6AA000
|
Size: |
4096
|
|
1DCA8C13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3118806044.000001DCA8C13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DCA8C13000
|
Size: |
143360
|
|
188FD65B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1369996906.00000188FD65B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD65B000
|
Size: |
4096
|
|
1A657790000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3120602769.000001A657790000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A657790000
|
Size: |
4096
|
|
22054602000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3118331108.0000022054602000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22054602000
|
Size: |
65536
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
1A65815A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2658620382.000001A65815A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A65815A000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
345597E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1369704017.000000345597E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
345597E000
|
Size: |
8192
|
|
55F000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
00000002.00000000.1272805840.000000000055F000.00000080.00000001.01000000.00000003.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
55F000
|
Size: |
782336
|
|
1A65785F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3121235179.000001A65785F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A65785F000
|
Size: |
24576
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
24043872000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3119663647.0000024043872000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
24043872000
|
Size: |
20480
|
|
1A657873000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3121235179.000001A657873000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A657873000
|
Size: |
49152
|
|
188FD653000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1369984108.00000188FD653000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD653000
|
Size: |
12288
|
|
34562FE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1369824772.00000034562FE000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
34562FE000
|
Size: |
4096
|
|
22054702000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3119888572.0000022054702000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22054702000
|
Size: |
32768
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
7849EFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3118475264.0000007849EFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7849EFE000
|
Size: |
8192
|
|
20000
|
unclassified section
|
page readonly
|
|
|
|
Name: |
00000002.00000002.1324973627.0000000000020000.00000002.10000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page readonly
|
Base address: |
20000
|
Size: |
4096
|
|
2404382A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3119235891.000002404382A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2404382A000
|
Size: |
90112
|
|
C25000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1325776012.0000000000C25000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C25000
|
Size: |
12288
|
|
1A657800000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3120775128.000001A657800000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A657800000
|
Size: |
73728
|
|
4A9000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1325157408.00000000004A9000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4A9000
|
Size: |
57344
|
|
833000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1325675291.0000000000833000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
833000
|
Size: |
28672
|
|
BB30AFE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000002.3119295516.000000BB30AFE000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BB30AFE000
|
Size: |
4096
|
|
26B4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1325907101.00000000026B4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
26B4000
|
Size: |
8192
|
|
2314DA20000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3120499835.000002314DA20000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2314DA20000
|
Size: |
8192
|
|
1A658157000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2658894084.000001A658157000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658157000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2413EE02000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3121312577.000002413EE02000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2413EE02000
|
Size: |
4096
|
|
2510000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1325867163.0000000002510000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2510000
|
Size: |
4096
|
|
756000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1325510660.0000000000756000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
756000
|
Size: |
8192
|
|
2314DC28000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3121124446.000002314DC28000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2314DC28000
|
Size: |
8192
|
|
22054664000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3119332584.0000022054664000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22054664000
|
Size: |
98304
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
188FD613000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1369909274.00000188FD613000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD613000
|
Size: |
94208
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1DCA8C7F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3119258980.000001DCA8C7F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DCA8C7F000
|
Size: |
4096
|
|
188FD697000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1370093075.00000188FD697000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD697000
|
Size: |
12288
|
|
188FD65C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1369357523.00000188FD65C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD65C000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
24043878000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3119663647.0000024043878000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
24043878000
|
Size: |
16384
|
|
1A658156000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2659492927.000001A658156000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658156000
|
Size: |
4096
|
|
24043902000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3120020703.0000024043902000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
24043902000
|
Size: |
45056
|
|
10000
|
unclassified section
|
page readonly
|
|
|
|
Name: |
00000002.00000002.1324940786.0000000000010000.00000002.10000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page readonly
|
Base address: |
10000
|
Size: |
4096
|
|
7E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1325570880.00000000007E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E0000
|
Size: |
4096
|
|
24043630000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3118497756.0000024043630000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
24043630000
|
Size: |
8192
|
|
1A657898000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2659415556.000001A657898000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A657898000
|
Size: |
12288
|
|
2413E702000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3121254644.000002413E702000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2413E702000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
AV process strings found (often used to terminate AV products) |
Lowering of HIPS / PFW / Operating System Security Settings |
Security Software Discovery
|
|
DC5BEFF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3118188257.000000DC5BEFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
DC5BEFF000
|
Size: |
4096
|
|
619FBFD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3118756118.000000619FBFD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
619FBFD000
|
Size: |
12288
|
|
26C4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1325935243.00000000026C4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
26C4000
|
Size: |
16384
|
|
345587E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1369672507.000000345587E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
345587E000
|
Size: |
8192
|
|
BB307FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3118975461.000000BB307FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BB307FE000
|
Size: |
8192
|
|
4DB000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1325157408.00000000004DB000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4DB000
|
Size: |
4096
|
|
1A65863F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3122825463.000001A65863F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A65863F000
|
Size: |
40960
|
|
1A657872000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2659168403.000001A657872000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A657872000
|
Size: |
4096
|
|
2413E657000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3121077327.000002413E657000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2413E657000
|
Size: |
36864
|
|
24043730000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3118667629.0000024043730000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
24043730000
|
Size: |
4096
|
|
2314DA40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3120599307.000002314DA40000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2314DA40000
|
Size: |
4096
|
|
2413E520000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3120505385.000002413E520000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2413E520000
|
Size: |
4096
|
|
3455CFE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1369747417.0000003455CFE000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
3455CFE000
|
Size: |
4096
|
|
2413E666000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3121197229.000002413E666000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2413E666000
|
Size: |
49152
|
|
824000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1319504429.0000000000824000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
824000
|
Size: |
45056
|
|
4DF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000000.1272772945.00000000004DF000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
4DF000
|
Size: |
106496
|
|
1A65815D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3122382521.000001A65815D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A65815D000
|
Size: |
4096
|
|
188FD64A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1369409709.00000188FD64A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD64A000
|
Size: |
4096
|
|
1A65789B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3121565438.000001A65789B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A65789B000
|
Size: |
114688
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2314DC2B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3121252173.000002314DC2B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2314DC2B000
|
Size: |
81920
|
|
1A658100000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3122259003.000001A658100000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658100000
|
Size: |
73728
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1A6576B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3120506877.000001A6576B0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A6576B0000
|
Size: |
4096
|
|
490000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000002.1325137952.0000000000490000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
490000
|
Size: |
102400
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
URLs found in memory or binary data |
Networking |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
73E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1325490943.000000000073E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
73E000
|
Size: |
8192
|
|
1A6578D5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3121630073.000001A6578D5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A6578D5000
|
Size: |
24576
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1A6578F2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3121847330.000001A6578F2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A6578F2000
|
Size: |
61440
|
|
61D000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
00000002.00000002.1325461621.000000000061D000.00000080.00000001.01000000.00000003.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
61D000
|
Size: |
4096
|
|
188FD62B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1369926442.00000188FD62B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD62B000
|
Size: |
24576
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
55F000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
00000002.00000002.1325299877.000000000055F000.00000080.00000001.01000000.00000003.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
55F000
|
Size: |
36864
|
|
1A658178000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3122514622.000001A658178000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658178000
|
Size: |
32768
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1A658172000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2658951756.000001A658172000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658172000
|
Size: |
8192
|
|
619F67B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3118114628.000000619F67B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
619F67B000
|
Size: |
20480
|
|
1DCA8C00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3118688442.000001DCA8C00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DCA8C00000
|
Size: |
73728
|
|
81F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1319487266.000000000081F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
81F000
|
Size: |
65536
|
|
188FD668000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1370021331.00000188FD668000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD668000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2413E420000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3120169167.000002413E420000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2413E420000
|
Size: |
8192
|
|
188FD684000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1369120992.00000188FD684000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD684000
|
Size: |
36864
|
|
61A06FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3119850369.00000061A06FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
61A06FE000
|
Size: |
8192
|
|
1DCA9500000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3120465384.000001DCA9500000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DCA9500000
|
Size: |
4096
|
|
24043913000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3120334100.0000024043913000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
24043913000
|
Size: |
8192
|
|
7849AEB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3118025141.0000007849AEB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7849AEB000
|
Size: |
20480
|
|
188FD649000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1369453159.00000188FD649000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD649000
|
Size: |
4096
|
|
22054E02000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3120729140.0000022054E02000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22054E02000
|
Size: |
4096
|
|
1A658154000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2659879145.000001A658154000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658154000
|
Size: |
12288
|
|
784AB7E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3120014774.000000784AB7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
784AB7E000
|
Size: |
8192
|
|
1A657847000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3121173245.000001A657847000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A657847000
|
Size: |
94208
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
188FD692000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1370079895.00000188FD692000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD692000
|
Size: |
12288
|
|
784A87E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3119677826.000000784A87E000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
784A87E000
|
Size: |
4096
|
|
61A02FE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3119303449.00000061A02FE000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
61A02FE000
|
Size: |
4096
|
|
188FD657000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1369494933.00000188FD657000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD657000
|
Size: |
4096
|
|
5C4000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1325386389.00000000005C4000.00000040.00000001.01000000.00000003.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
5C4000
|
Size: |
4096
|
|
22054640000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3118943214.0000022054640000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22054640000
|
Size: |
12288
|
|
2314DB50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3120752260.000002314DB50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2314DB50000
|
Size: |
4096
|
|
1A6578B3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2660126615.000001A6578B3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A6578B3000
|
Size: |
4096
|
|
188FD64D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1369971456.00000188FD64D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD64D000
|
Size: |
4096
|
|
1A65816E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3122442376.000001A65816E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A65816E000
|
Size: |
24576
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
24DE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1325838606.00000000024DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
24DE000
|
Size: |
8192
|
|
3455C7E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1369732633.0000003455C7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3455C7E000
|
Size: |
8192
|
|
22054E00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3120729140.0000022054E00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22054E00000
|
Size: |
4096
|
|
1A657882000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2659168403.000001A657882000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A657882000
|
Size: |
12288
|
|
1A65867A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3123154610.000001A65867A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A65867A000
|
Size: |
4096
|
|
188FD65E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1369321458.00000188FD65E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD65E000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
61A05FE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3119751483.00000061A05FE000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
61A05FE000
|
Size: |
4096
|
|
BEF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1325749979.0000000000BEF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BEF000
|
Size: |
4096
|
|
83B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1275323372.000000000083B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
83B000
|
Size: |
4096
|
|
619F9FE000
|
stack
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3118662956.000000619F9FE000.00000002.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page readonly
|
Base address: |
619F9FE000
|
Size: |
4096
|
|
22054800000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3120459322.0000022054800000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22054800000
|
Size: |
4096
|
|
1A658159000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2659492927.000001A658159000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658159000
|
Size: |
4096
|
|
1A657888000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2659415556.000001A657888000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A657888000
|
Size: |
4096
|
|
83B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1319436204.000000000083B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
83B000
|
Size: |
69632
|
|
1A6578CF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3121630073.000001A6578CF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A6578CF000
|
Size: |
12288
|
|
1A658668000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2668818664.000001A658668000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658668000
|
Size: |
32768
|
|
1A65815B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2667810220.000001A65815B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A65815B000
|
Size: |
12288
|
|
1A65812C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2659010451.000001A65812C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A65812C000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
188FD702000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1370120596.00000188FD702000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD702000
|
Size: |
16384
|
|
1DCA9502000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3120465384.000001DCA9502000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DCA9502000
|
Size: |
102400
|
|
2314DC61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3121424512.000002314DC61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2314DC61000
|
Size: |
28672
|
|
1A658015000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3122234287.000001A658015000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658015000
|
Size: |
8192
|
|
BB302FA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3118465642.000000BB302FA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BB302FA000
|
Size: |
24576
|
|
1A658153000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2667780413.000001A658153000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658153000
|
Size: |
4096
|
|
1A657825000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3121075964.000001A657825000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A657825000
|
Size: |
135168
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
188FD662000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1370009125.00000188FD662000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD662000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1A657FE0000
|
remote allocation
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2660077145.000001A657FE0000.00000004.00000400.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
remote allocation
|
Protect: |
page read and write
|
Base address: |
1A657FE0000
|
Size: |
4096
|
|
3455DFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1369760684.0000003455DFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3455DFE000
|
Size: |
8192
|
|
22054638000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3118801053.0000022054638000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22054638000
|
Size: |
28672
|
|
784A079000
|
stack
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3118686297.000000784A079000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
784A079000
|
Size: |
28672
|
|
1DCA8C16000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1277297368.000001DCA8C16000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DCA8C16000
|
Size: |
65536
|
|
188FD64F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1369176496.00000188FD64F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD64F000
|
Size: |
8192
|
|
2413E440000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3120322321.000002413E440000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2413E440000
|
Size: |
4096
|
|
24043780000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3118835059.0000024043780000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24043780000
|
Size: |
4096
|
|
22054613000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3118642594.0000022054613000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22054613000
|
Size: |
69632
|
|
2530000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1325879867.0000000002530000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2530000
|
Size: |
8192
|
|
188FD5F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1369878847.00000188FD5F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
188FD5F0000
|
Size: |
4096
|
|
2314DC02000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3120981144.000002314DC02000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2314DC02000
|
Size: |
65536
|
|
BB309FB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3119213295.000000BB309FB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BB309FB000
|
Size: |
20480
|
|
2205462B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3118801053.000002205462B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2205462B000
|
Size: |
24576
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
1A658540000
|
remote allocation
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2660341030.000001A658540000.00000004.00000400.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
remote allocation
|
Protect: |
page read and write
|
Base address: |
1A658540000
|
Size: |
4096
|
|
249E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1325820639.000000000249E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
249E000
|
Size: |
8192
|
|
7F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1325583110.00000000007F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7F0000
|
Size: |
32768
|
|
4FD000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000002.00000002.1325255658.00000000004FD000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
4FD000
|
Size: |
401408
|
|
BB3067E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3118823211.000000BB3067E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BB3067E000
|
Size: |
8192
|
|
1A658163000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2658951756.000001A658163000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658163000
|
Size: |
57344
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
400000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000002.1325078705.0000000000400000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
400000
|
Size: |
4096
|
|
1A658152000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2659492927.000001A658152000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658152000
|
Size: |
4096
|
|
1A658662000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2668736426.000001A658662000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658662000
|
Size: |
20480
|
|
1A657813000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3120855069.000001A657813000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A657813000
|
Size: |
32768
|
|
4DF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000002.1325227286.00000000004DF000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
4DF000
|
Size: |
122880
|
|
1A657902000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3121847330.000001A657902000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A657902000
|
Size: |
65536
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2205464D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3118943214.000002205464D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2205464D000
|
Size: |
69632
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
BB30CFE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000002.3119755110.000000BB30CFE000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BB30CFE000
|
Size: |
4096
|
|
22054660000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3118943214.0000022054660000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22054660000
|
Size: |
12288
|
|
6F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1325475807.00000000006F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6F0000
|
Size: |
4096
|
|
1A658655000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2668736426.000001A658655000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658655000
|
Size: |
32768
|
|
784A17E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3118780232.000000784A17E000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
784A17E000
|
Size: |
4096
|
|
BB2FF4B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3118298430.000000BB2FF4B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BB2FF4B000
|
Size: |
20480
|
|
1A658613000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3122717277.000001A658613000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658613000
|
Size: |
110592
|
|
BB30FFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3120165765.000000BB30FFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BB30FFE000
|
Size: |
8192
|
|
401000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000002.00000002.1325091348.0000000000401000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
401000
|
Size: |
585728
|
|
1A658540000
|
remote allocation
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2660323385.000001A658540000.00000004.00000400.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
remote allocation
|
Protect: |
page read and write
|
Base address: |
1A658540000
|
Size: |
4096
|
|
1A657883000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3121453172.000001A657883000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A657883000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1A65813B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2658837770.000001A65813B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A65813B000
|
Size: |
94208
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
BB306FE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000002.3118894992.000000BB306FE000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BB306FE000
|
Size: |
4096
|
|
1A65794C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2667848832.000001A65794C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A65794C000
|
Size: |
4096
|
|
784AC7E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3120170967.000000784AC7E000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
784AC7E000
|
Size: |
4096
|
|
7849F7E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3118597591.0000007849F7E000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7849F7E000
|
Size: |
4096
|
|
1A658672000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2668818664.000001A658672000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658672000
|
Size: |
24576
|
|
188FD670000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1370034868.00000188FD670000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD670000
|
Size: |
81920
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
26B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1325907101.00000000026B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
26B0000
|
Size: |
8192
|
|
22054713000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3120176820.0000022054713000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22054713000
|
Size: |
98304
|
|
7DE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1325557603.00000000007DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7DE000
|
Size: |
8192
|
|
826000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1325675291.0000000000826000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
826000
|
Size: |
36864
|
|
BB30C7E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3119682940.000000BB30C7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BB30C7E000
|
Size: |
8192
|
|
1A658602000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3122586708.000001A658602000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658602000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1DCA8D02000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3119806278.000001DCA8D02000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DCA8D02000
|
Size: |
12288
|
|
1A657690000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3120329697.000001A657690000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A657690000
|
Size: |
12288
|
|
7849BEE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3118194874.0000007849BEE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7849BEE000
|
Size: |
8192
|
|
1DCA8CB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3119806278.000001DCA8CB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DCA8CB0000
|
Size: |
327680
|
|
1A657866000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3121235179.000001A657866000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A657866000
|
Size: |
49152
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1DCA8C48000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1277951605.000001DCA8C48000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DCA8C48000
|
Size: |
262144
|
|
240437B0000
|
remote allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1276055484.00000240437B0000.00000004.00000400.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
remote allocation
|
Protect: |
page read and write
|
Base address: |
240437B0000
|
Size: |
4096
|
|
2C0F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1325978167.0000000002C0F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2C0F000
|
Size: |
4096
|
|
1A65794C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3122040027.000001A65794C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A65794C000
|
Size: |
4096
|
|
188FD68B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1370052587.00000188FD68B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD68B000
|
Size: |
8192
|
|
188FD648000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1369465578.00000188FD648000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD648000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1325062437.00000000001F0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F0000
|
Size: |
4096
|
|
19C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1325033172.000000000019C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
19C000
|
Size: |
16384
|
|
4C5000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1325157408.00000000004C5000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4C5000
|
Size: |
4096
|
|
1A658110000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2658592641.000001A658110000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658110000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1A658662000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3123030218.000001A658662000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658662000
|
Size: |
20480
|
|
1A6578DC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3121755751.000001A6578DC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A6578DC000
|
Size: |
20480
|
|
1A65812A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2659554120.000001A65812A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A65812A000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
5C5000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
00000002.00000002.1325402922.00000000005C5000.00000080.00000001.01000000.00000003.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
5C5000
|
Size: |
356352
|
|
1DCA8B70000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3118197037.000001DCA8B70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DCA8B70000
|
Size: |
8192
|
|
784A77E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3119411371.000000784A77E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
784A77E000
|
Size: |
8192
|
|
188FD667000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1369250033.00000188FD667000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD667000
|
Size: |
20480
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
188FD4C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1369838786.00000188FD4C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD4C0000
|
Size: |
8192
|
|
1DCA8C37000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3118939042.000001DCA8C37000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DCA8C37000
|
Size: |
65536
|
|
2314DC40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3121313535.000002314DC40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2314DC40000
|
Size: |
131072
|
|
240437B0000
|
remote allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1276034692.00000240437B0000.00000004.00000400.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
remote allocation
|
Protect: |
page read and write
|
Base address: |
240437B0000
|
Size: |
4096
|
|
4470000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1326016725.0000000004470000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4470000
|
Size: |
4096
|
|
1A6578BA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3121565438.000001A6578BA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A6578BA000
|
Size: |
45056
|
|
188FD5C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1369865949.00000188FD5C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD5C0000
|
Size: |
4096
|
|
220548E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3120560303.00000220548E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
220548E0000
|
Size: |
4096
|
|
619FCFE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3118862038.000000619FCFE000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
619FCFE000
|
Size: |
4096
|
|
619F97C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3118554485.000000619F97C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
619F97C000
|
Size: |
16384
|
|
BF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1325762332.0000000000BF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BF0000
|
Size: |
4096
|
|
784AA7E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3119868875.000000784AA7E000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
784AA7E000
|
Size: |
4096
|
|
188FD658000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1369376503.00000188FD658000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD658000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
188FD68F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1369095911.00000188FD68F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD68F000
|
Size: |
24576
|
|
784A1FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3118863457.000000784A1FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
784A1FE000
|
Size: |
8192
|
|
188FD665000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1369545641.00000188FD665000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD665000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
C20000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1325776012.0000000000C20000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C20000
|
Size: |
12288
|
|
1A657913000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3121910361.000001A657913000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A657913000
|
Size: |
49152
|
|
188FD65D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1369340511.00000188FD65D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD65D000
|
Size: |
4096
|
|
82F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1319436204.000000000082F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
82F000
|
Size: |
4096
|
|
1A657893000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3121453172.000001A657893000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A657893000
|
Size: |
28672
|
|
1A658600000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3122586708.000001A658600000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658600000
|
Size: |
4096
|
|
1A658140000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2658932794.000001A658140000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658140000
|
Size: |
73728
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
61A057E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3119671568.00000061A057E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
61A057E000
|
Size: |
8192
|
|
568000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1325321475.0000000000568000.00000040.00000001.01000000.00000003.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
568000
|
Size: |
4096
|
|
BB30DFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3119862627.000000BB30DFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BB30DFE000
|
Size: |
8192
|
|
1A658157000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2667749309.000001A658157000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658157000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1A658192000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2667338082.000001A658192000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658192000
|
Size: |
4096
|
|
1DCA8C48000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3119050094.000001DCA8C48000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DCA8C48000
|
Size: |
77824
|
|
1A65781C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3120855069.000001A65781C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A65781C000
|
Size: |
32768
|
|
1A658154000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2667656725.000001A658154000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658154000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
188FD600000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1369891479.00000188FD600000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD600000
|
Size: |
73728
|
|
1A65816B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2658981647.000001A65816B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A65816B000
|
Size: |
24576
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
619FDFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3118975974.000000619FDFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
619FDFE000
|
Size: |
8192
|
|
784A47E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3119095758.000000784A47E000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
784A47E000
|
Size: |
4096
|
|
61C000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1325443883.000000000061C000.00000040.00000001.01000000.00000003.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
61C000
|
Size: |
4096
|
|
266F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1325893769.000000000266F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
266F000
|
Size: |
4096
|
|
7FE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1325583110.00000000007FE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7FE000
|
Size: |
135168
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
22054D70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3120647010.0000022054D70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
22054D70000
|
Size: |
4096
|
|
188FD65A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1369424407.00000188FD65A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD65A000
|
Size: |
8192
|
|
BB30EFE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000002.3120010741.000000BB30EFE000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BB30EFE000
|
Size: |
4096
|
|
34558FE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1369689161.00000034558FE000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
34558FE000
|
Size: |
4096
|
|
833000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1319436204.0000000000833000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
833000
|
Size: |
28672
|
|
188FD651000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1369156538.00000188FD651000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD651000
|
Size: |
20480
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1A65862F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3122717277.000001A65862F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A65862F000
|
Size: |
61440
|
|
821000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1325653141.0000000000821000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
821000
|
Size: |
12288
|
|
2413E637000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3121018546.000002413E637000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2413E637000
|
Size: |
65536
|
|
619FEFE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3119057410.000000619FEFE000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
619FEFE000
|
Size: |
4096
|
|
4DD000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1325157408.00000000004DD000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4DD000
|
Size: |
4096
|
|
1A658172000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2658981647.000001A658172000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658172000
|
Size: |
8192
|
|
1A65815B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2658640169.000001A65815B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A65815B000
|
Size: |
4096
|
|
1DCA9526000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3120748448.000001DCA9526000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DCA9526000
|
Size: |
4096
|
|
79E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1325540771.000000000079E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
79E000
|
Size: |
8192
|
|
24043900000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3120020703.0000024043900000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
24043900000
|
Size: |
4096
|
|
1A65812D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2667428048.000001A65812D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A65812D000
|
Size: |
32768
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
61A04FE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3119522279.00000061A04FE000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
61A04FE000
|
Size: |
4096
|
|
2413E613000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3120832071.000002413E613000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2413E613000
|
Size: |
143360
|
|
1A658540000
|
remote allocation
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2660283418.000001A658540000.00000004.00000400.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
remote allocation
|
Protect: |
page read and write
|
Base address: |
1A658540000
|
Size: |
4096
|
|
1A658137000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3122350191.000001A658137000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658137000
|
Size: |
114688
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
22054690000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3119688171.0000022054690000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22054690000
|
Size: |
4096
|
|
9EF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1325723851.00000000009EF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9EF000
|
Size: |
4096
|
|
BB30B7E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3119366095.000000BB30B7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BB30B7E000
|
Size: |
8192
|
|
34559FE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1369718722.00000034559FE000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
34559FE000
|
Size: |
4096
|
|
7FA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1325583110.00000000007FA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7FA000
|
Size: |
8192
|
|
2314DC13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3121124446.000002314DC13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2314DC13000
|
Size: |
81920
|
|
3455EFE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1369774022.0000003455EFE000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
3455EFE000
|
Size: |
4096
|
|
83B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1325675291.000000000083B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
83B000
|
Size: |
69632
|
|
22054681000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3119332584.0000022054681000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22054681000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
BB310FE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000002.3120325212.000000BB310FE000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BB310FE000
|
Size: |
4096
|
|
1A65815F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3122412084.000001A65815F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A65815F000
|
Size: |
57344
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
188FD659000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1369439312.00000188FD659000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
188FD659000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
24043802000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3118899274.0000024043802000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
24043802000
|
Size: |
65536
|
|
2314DB60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3120829860.000002314DB60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2314DB60000
|
Size: |
4096
|
|
2314DD02000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3121465075.000002314DD02000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2314DD02000
|
Size: |
20480
|
|
1DCA951C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3120675120.000001DCA951C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DCA951C000
|
Size: |
36864
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2413E616000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1280814165.000002413E616000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2413E616000
|
Size: |
65536
|
|
188FDE02000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1370135575.00000188FDE02000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
188FDE02000
|
Size: |
4096
|
|
1A658002000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3122102382.000001A658002000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658002000
|
Size: |
4096
|
|
2205464B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3118943214.000002205464B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2205464B000
|
Size: |
4096
|
|
838000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1275323372.0000000000838000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
838000
|
Size: |
8192
|
|
1A65818E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3122548720.000001A65818E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A65818E000
|
Size: |
4096
|
|
83C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1275289478.000000000083C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
83C000
|
Size: |
118784
|
|
4B8000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1325157408.00000000004B8000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4B8000
|
Size: |
12288
|
|
2404387D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3119871616.000002404387D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2404387D000
|
Size: |
12288
|
|
1A658152000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2658640169.000001A658152000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A658152000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2413E648000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3121077327.000002413E648000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2413E648000
|
Size: |
57344
|
|