864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2234111869.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
22A3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2579694926.00000000022A3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22A3000
|
Size: |
20480
|
|
2245E002000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2579489791.000002245E002000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2245E002000
|
Size: |
4096
|
|
5D05DFE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000004.00000002.2576345394.0000005D05DFE000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
5D05DFE000
|
Size: |
4096
|
|
2245D848000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2577671429.000002245D848000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2245D848000
|
Size: |
32768
|
|
C14067E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2575900692.000000C14067E000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
C14067E000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230843963.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231422245.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
20960800000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2577430092.0000020960800000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
20960800000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231661734.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
2245D800000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2576650433.000002245D800000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2245D800000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230393160.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230785549.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231331617.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
95000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2575596086.0000000000095000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
95000
|
Size: |
45056
|
|
5D0587E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2575771013.0000005D0587E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5D0587E000
|
Size: |
8192
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2234466802.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
28D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1310390171.00000000028D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
28D0000
|
Size: |
20480
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2232165943.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2232969030.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
2245D88F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2578538729.000002245D88F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2245D88F000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230541792.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
C140276000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2575702817.000000C140276000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C140276000
|
Size: |
40960
|
|
23B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2579869632.00000000023B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23B0000
|
Size: |
12288
|
|
5D0515B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2575525037.0000005D0515B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5D0515B000
|
Size: |
20480
|
|
2603AC31000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2576154033.000002603AC31000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2603AC31000
|
Size: |
20480
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2232472217.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
A5F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1318709584.0000000000A5F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A5F000
|
Size: |
143360
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2229503563.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
A0B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2577622121.0000000000A0B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A0B000
|
Size: |
69632
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231072400.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
4CE000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2576149350.00000000004CE000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4CE000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231547545.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
2603AC48000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2576562419.000002603AC48000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2603AC48000
|
Size: |
77824
|
|
CAC4FDC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2575293374.000000CAC4FDC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
CAC4FDC000
|
Size: |
16384
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2233443255.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
A58000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1318744728.0000000000A58000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A58000
|
Size: |
28672
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2229162404.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
55EE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2580570948.00000000055EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
55EE000
|
Size: |
8192
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231150103.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2233994422.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
2245D82B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2577335450.000002245D82B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2245D82B000
|
Size: |
32768
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2223573180.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
48CF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2580403018.00000000048CF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
48CF000
|
Size: |
4096
|
|
CAC597E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2575440653.000000CAC597E000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
CAC597E000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230523367.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231875554.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
5D061FB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2576765471.0000005D061FB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5D061FB000
|
Size: |
20480
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230466928.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2229619169.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
A5E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2577622121.0000000000A5E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A5E000
|
Size: |
262144
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230303405.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230862719.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2229553301.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231620275.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231602745.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
2245D83B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2577335450.000002245D83B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2245D83B000
|
Size: |
16384
|
|
2245D913000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2578885845.000002245D913000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2245D913000
|
Size: |
98304
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231512282.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
20960816000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1368306882.0000020960816000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
20960816000
|
Size: |
65536
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230050451.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
24D0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1312527236.00000000024D0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
24D0000
|
Size: |
12288
|
|
20960802000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2577430092.0000020960802000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
20960802000
|
Size: |
65536
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2235239813.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2245D891000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2578538729.000002245D891000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2245D891000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2234542975.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2229981870.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2235300596.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
5D05BFB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2576074967.0000005D05BFB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5D05BFB000
|
Size: |
20480
|
|
2603B402000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2578565480.000002603B402000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2603B402000
|
Size: |
4096
|
|
2603AAF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2575897266.000002603AAF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2603AAF0000
|
Size: |
8192
|
|
24CC000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1312463899.00000000024CC000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
24CC000
|
Size: |
8192
|
|
2603B502000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2578623410.000002603B502000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2603B502000
|
Size: |
143360
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2226247463.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231583678.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2234133818.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
2245D900000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2578625281.000002245D900000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2245D900000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231167251.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
163E5000000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2577727747.00000163E5000000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
163E5000000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231959996.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
CAC5C7E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2575618635.000000CAC5C7E000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
CAC5C7E000
|
Size: |
4096
|
|
2245D86F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2578192490.000002245D86F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2245D86F000
|
Size: |
69632
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
2245D902000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2578625281.000002245D902000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2245D902000
|
Size: |
32768
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2223400106.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230689673.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2229536880.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231796218.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231033282.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230634319.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
4D0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2576196219.00000000004D0000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4D0000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2232945522.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
CAC637D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2576416214.000000CAC637D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
CAC637D000
|
Size: |
12288
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2232430146.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2233157501.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2232127516.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
7F5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2576718270.00000000007F5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7F5000
|
Size: |
16384
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231112536.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
20960870000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2578646511.0000020960870000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
20960870000
|
Size: |
8192
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230228290.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230000773.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2229140105.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230766300.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2229697431.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
2603ACB1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2577477643.000002603ACB1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2603ACB1000
|
Size: |
323584
|
|
5D05FFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2576528609.0000005D05FFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5D05FFE000
|
Size: |
8192
|
|
20961002000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2578909323.0000020961002000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
20961002000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2234286077.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230430461.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2234151868.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
8192
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230652245.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
22A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2579694926.00000000022A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22A0000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1415827663.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
8192
|
|
AC4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2577622121.0000000000AC4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AC4000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230356855.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2234037104.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
3120000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2580252727.0000000003120000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3120000
|
Size: |
4096
|
|
4691000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1415798545.0000000004691000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4691000
|
Size: |
65536
|
|
5D057FE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000004.00000002.2575722571.0000005D057FE000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
5D057FE000
|
Size: |
4096
|
|
163E5046000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1366789820.00000163E5046000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
163E5046000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231738504.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2223509660.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
217E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2221364857.000000000217E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
217E000
|
Size: |
106496
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
5D056FD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2575606223.0000005D056FD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5D056FD000
|
Size: |
12288
|
|
A00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2577622121.0000000000A00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A00000
|
Size: |
36864
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2233967213.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2229289802.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
163E4FE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2577668729.00000163E4FE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
163E4FE0000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2229259320.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231856242.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231222629.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
209607E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2577316524.00000209607E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
209607E0000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231186345.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2234870877.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
5D063FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2577117573.0000005D063FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5D063FE000
|
Size: |
8192
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2220485527.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2233372614.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
2F3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2580184651.0000000002F3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2F3E000
|
Size: |
8192
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230670467.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
49B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2580505155.00000000049B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
49B0000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2234092095.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
2603B526000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2578623410.000002603B526000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2603B526000
|
Size: |
8192
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2228977128.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
163E4EA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2577276024.00000163E4EA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
163E4EA0000
|
Size: |
8192
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231013928.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
5D059FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2575928208.0000005D059FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5D059FE000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231368798.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230411933.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2232089299.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2234204388.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
20960837000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2577989974.0000020960837000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
20960837000
|
Size: |
65536
|
|
220F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2579603651.000000000220F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
220F000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230708396.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
EAA0EFE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000002.2575757516.000000EAA0EFE000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
EAA0EFE000
|
Size: |
4096
|
|
2245DAE0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2579327439.000002245DAE0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2245DAE0000
|
Size: |
4096
|
|
EAA0DFC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2575694534.000000EAA0DFC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
EAA0DFC000
|
Size: |
16384
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231052732.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2232300074.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2233354343.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
860000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2577485746.0000000000860000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
860000
|
Size: |
16384
|
|
2245D851000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2577763622.000002245D851000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2245D851000
|
Size: |
118784
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230578021.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
C13FCAB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2575580303.000000C13FCAB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C13FCAB000
|
Size: |
20480
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2229123083.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
47CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2580307077.00000000047CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
47CE000
|
Size: |
8192
|
|
AA5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2577622121.0000000000AA5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AA5000
|
Size: |
114688
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
163E5802000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2579012658.00000163E5802000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
163E5802000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230338738.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
5D058FE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000004.00000002.2575864906.0000005D058FE000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
5D058FE000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230133826.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
2603AC68000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2576723422.000002603AC68000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2603AC68000
|
Size: |
106496
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2229774722.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2229395413.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
C14037E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2575758921.000000C14037E000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
C14037E000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2229178146.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2232200280.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
8192
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231719573.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230995122.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2222402116.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
1F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2575998006.00000000001F0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F0000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2229214129.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
2EFF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2580156688.0000000002EFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2EFF000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2229193237.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
8192
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2234358540.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
2245D802000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2576650433.000002245D802000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2245D802000
|
Size: |
32768
|
|
4D2000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2576196219.00000000004D2000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4D2000
|
Size: |
4096
|
|
2118000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2221364857.0000000002118000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2118000
|
Size: |
413696
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
209607B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2577160351.00000209607B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
209607B0000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230559628.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2225436714.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2229375730.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
A41000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2577622121.0000000000A41000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A41000
|
Size: |
12288
|
|
494E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2580473602.000000000494E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
494E000
|
Size: |
8192
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2232107218.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
7FA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2576718270.00000000007FA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7FA000
|
Size: |
20480
|
|
5D060FE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000004.00000002.2576679111.0000005D060FE000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
5D060FE000
|
Size: |
4096
|
|
46A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1422161500.00000000046A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
46A0000
|
Size: |
102400
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230190927.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
4C9000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.1296213236.00000000004C9000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
4C9000
|
Size: |
28672
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230900146.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231825147.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2234916849.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2233922857.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2229243244.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
CAC5D7E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2575801887.000000CAC5D7E000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
CAC5D7E000
|
Size: |
4096
|
|
850000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2577415869.0000000000850000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
850000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2232264025.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231777600.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2228941391.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2232910600.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
2603B52B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2579247542.000002603B52B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2603B52B000
|
Size: |
12288
|
|
CAC5E7E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2575861654.000000CAC5E7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
CAC5E7E000
|
Size: |
8192
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2229634671.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2234406020.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2234818541.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
CAC5A7E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2575466751.000000CAC5A7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
CAC5A7E000
|
Size: |
8192
|
|
20960902000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2578727875.0000020960902000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
20960902000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
AV process strings found (often used to terminate AV products) |
Lowering of HIPS / PFW / Operating System Security Settings |
Security Software Discovery
|
|
5D064FE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000004.00000002.2577160081.0000005D064FE000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
5D064FE000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2229228800.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231757264.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
EAA0FFE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000002.2575814983.000000EAA0FFE000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
EAA0FFE000
|
Size: |
4096
|
|
7A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2576503551.00000000007A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A0000
|
Size: |
8192
|
|
54AF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2580551245.00000000054AF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
54AF000
|
Size: |
4096
|
|
24B0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2579915195.00000000024B0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
24B0000
|
Size: |
131072
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
CAC5CFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2575723648.000000CAC5CFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
CAC5CFE000
|
Size: |
8192
|
|
4692000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1422161500.0000000004692000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4692000
|
Size: |
24576
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2234763216.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230374909.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231439634.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231258182.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
400000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1296117843.0000000000400000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
400000
|
Size: |
4096
|
|
CAC627E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2576234225.000000CAC627E000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
CAC627E000
|
Size: |
4096
|
|
163E5002000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2577727747.00000163E5002000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
163E5002000
|
Size: |
65536
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2232891135.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
2603AC16000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1365445327.000002603AC16000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2603AC16000
|
Size: |
65536
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2232017714.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
4690000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2580280363.0000000004690000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4690000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2233948977.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
2603AD02000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2577477643.000002603AD02000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2603AD02000
|
Size: |
12288
|
|
CAC617E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2576078669.000000CAC617E000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
CAC617E000
|
Size: |
4096
|
|
CAC677E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2576719057.000000CAC677E000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
CAC677E000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230448483.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2233266524.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
209606D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2577102086.00000209606D0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
209606D0000
|
Size: |
4096
|
|
23AF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2579839740.00000000023AF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
23AF000
|
Size: |
4096
|
|
5D05D7E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2576242839.0000005D05D7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5D05D7E000
|
Size: |
8192
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2223493469.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1422224257.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
8192
|
|
163E4FA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2577388734.00000163E4FA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
163E4FA0000
|
Size: |
4096
|
|
4C9000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2576089385.00000000004C9000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4C9000
|
Size: |
12288
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2223383363.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2229275443.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231092091.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2229435822.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231476340.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
18C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2575758142.000000000018C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
18C000
|
Size: |
12288
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2234503637.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230319614.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2229470909.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
163E502B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2578350647.00000163E502B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
163E502B000
|
Size: |
106496
|
|
EAA0A7B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2575503147.000000EAA0A7B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
EAA0A7B000
|
Size: |
20480
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2229103881.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2229588318.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2234852953.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
24C8000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1312400154.00000000024C8000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
24C8000
|
Size: |
4096
|
|
163E5102000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2578894451.00000163E5102000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
163E5102000
|
Size: |
20480
|
|
2245D7E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2576530703.000002245D7E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2245D7E0000
|
Size: |
8192
|
|
24C8000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1312444745.00000000024C8000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
24C8000
|
Size: |
24576
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2228022744.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
490E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2580436733.000000000490E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
490E000
|
Size: |
8192
|
|
2245DF70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2579364536.000002245DF70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2245DF70000
|
Size: |
4096
|
|
2245D883000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2578192490.000002245D883000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2245D883000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2232371963.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
401000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000000.1296131840.0000000000401000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
401000
|
Size: |
819200
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Detected Delphi use of System.ParamCount |
System Summary |
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2232183556.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
83E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2577318317.000000000083E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
83E000
|
Size: |
8192
|
|
A45000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2577622121.0000000000A45000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A45000
|
Size: |
94208
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2221286245.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2232410415.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2233244939.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2229913133.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230485844.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231996512.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
C14087E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2576126206.000000C14087E000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
C14087E000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230284596.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
163E5074000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2578864042.00000163E5074000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
163E5074000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230209481.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
2290000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.2579674583.0000000002290000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
2290000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2229859686.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
2245E015000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2579614954.000002245E015000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2245E015000
|
Size: |
4096
|
|
2603ABF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2576046542.000002603ABF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2603ABF0000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2232041912.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
2096086B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2578224980.000002096086B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2096086B000
|
Size: |
12288
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2229029935.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2227998601.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2229487621.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
163E5013000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2578026505.00000163E5013000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
163E5013000
|
Size: |
57344
|
|
163E5046000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2578572981.00000163E5046000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
163E5046000
|
Size: |
61440
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2234074246.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231294824.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
2603AC13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2576154033.000002603AC13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2603AC13000
|
Size: |
118784
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230247443.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
2245DA00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2579014755.000002245DA00000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2245DA00000
|
Size: |
4096
|
|
CAC5F7E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2575925281.000000CAC5F7E000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
CAC5F7E000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2233210266.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
2245E000000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2579489791.000002245E000000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2245E000000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2232859103.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
5D062FE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000004.00000002.2576961449.0000005D062FE000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
5D062FE000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230106915.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230747425.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2234336969.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
5D05AFE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000004.00000002.2576027613.0000005D05AFE000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
5D05AFE000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2229677276.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230615940.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
C140B7E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2576412178.000000C140B7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C140B7E000
|
Size: |
8192
|
|
7C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2576560688.00000000007C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7C0000
|
Size: |
8192
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2233139445.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
2603AC00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2576075895.000002603AC00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2603AC00000
|
Size: |
73728
|
|
4D2000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.1296213236.00000000004D2000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
4D2000
|
Size: |
12288
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231565930.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231494298.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2229521771.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2223270455.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2229878188.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
5D05CFE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000004.00000002.2576190469.0000005D05CFE000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
5D05CFE000
|
Size: |
4096
|
|
20960857000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2578224980.0000020960857000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
20960857000
|
Size: |
40960
|
|
C14097E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2576223871.000000C14097E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C14097E000
|
Size: |
8192
|
|
4790000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1415862489.0000000004790000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4790000
|
Size: |
122880
|
|
5D05E7E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2576407024.0000005D05E7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5D05E7E000
|
Size: |
8192
|
|
163E4EC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2577321680.00000163E4EC0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
163E4EC0000
|
Size: |
4096
|
|
163E505A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2578694150.00000163E505A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
163E505A000
|
Size: |
36864
|
|
5D05EFE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000004.00000002.2576463247.0000005D05EFE000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
5D05EFE000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231699776.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230596723.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2229747805.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2223426929.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
A6E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1348185966.0000000000A6E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A6E000
|
Size: |
36864
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2234254806.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231385705.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
20960862000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2578224980.0000020960862000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
20960862000
|
Size: |
32768
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2229569340.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231978345.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
10000
|
unclassified section
|
page readonly
|
|
|
|
Name: |
00000000.00000002.2575536626.0000000000010000.00000002.10000000.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page readonly
|
Base address: |
10000
|
Size: |
4096
|
|
224E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2579638645.000000000224E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
224E000
|
Size: |
8192
|
|
CAC66FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2576564725.000000CAC66FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
CAC66FE000
|
Size: |
8192
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2223202753.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
20960813000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2577618645.0000020960813000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
20960813000
|
Size: |
102400
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231204492.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
AD4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2577622121.0000000000AD4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AD4000
|
Size: |
32768
|
|
4D7000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1296241447.00000000004D7000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
4D7000
|
Size: |
1654784
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
Detected Delphi use of System.ParamCount |
System Summary |
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2232451141.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2229837675.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2234017454.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2235259814.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
66D000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1296241447.000000000066D000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
66D000
|
Size: |
405504
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2223362572.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231896545.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
A78000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1348185966.0000000000A78000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A78000
|
Size: |
122880
|
|
52AF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2580530544.00000000052AF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
52AF000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2229454878.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
C14077E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2576017927.000000C14077E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C14077E000
|
Size: |
8192
|
|
2096082D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2577618645.000002096082D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2096082D000
|
Size: |
36864
|
|
2603B500000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2578623410.000002603B500000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2603B500000
|
Size: |
4096
|
|
2245D813000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2577020072.000002245D813000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2245D813000
|
Size: |
94208
|
|
24D0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1312507182.00000000024D0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
24D0000
|
Size: |
8192
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231313303.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230880805.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230976222.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
20960848000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2578224980.0000020960848000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
20960848000
|
Size: |
57344
|
|
CAC61FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2576129605.000000CAC61FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
CAC61FE000
|
Size: |
8192
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231349680.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
C140A7E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2576350437.000000C140A7E000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
C140A7E000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231240134.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2229656004.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2228960498.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2229603827.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
CAC607D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2576021240.000000CAC607D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
CAC607D000
|
Size: |
12288
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230804536.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230171684.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
163E5022000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2578026505.00000163E5022000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
163E5022000
|
Size: |
32768
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2235353624.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
209606B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2577059577.00000209606B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
209606B0000
|
Size: |
8192
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2229727114.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231132195.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230936928.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
56EF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2580616833.00000000056EF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
56EF000
|
Size: |
4096
|
|
2603B53A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2579490466.000002603B53A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2603B53A000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230265328.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
2603B532000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2579369336.000002603B532000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2603B532000
|
Size: |
4096
|
|
C14057B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2575817857.000000C14057B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C14057B000
|
Size: |
20480
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2229419175.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
2603AB10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2575994789.000002603AB10000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2603AB10000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231680206.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231458365.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
2245D80B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2576650433.000002245D80B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2245D80B000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231277095.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
EAA0BFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2575572305.000000EAA0BFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
EAA0BFE000
|
Size: |
8192
|
|
163E4FD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2577417434.00000163E4FD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
163E4FD0000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231530292.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2233390671.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2223659828.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
2603AC37000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2576460883.000002603AC37000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2603AC37000
|
Size: |
65536
|
|
19D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2575758142.000000000019D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
19D000
|
Size: |
12288
|
|
A1E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2577622121.0000000000A1E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A1E000
|
Size: |
131072
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
C140C7E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2576467144.000000C140C7E000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
C140C7E000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230955645.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230824413.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
2603AC87000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2577101177.000002603AC87000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2603AC87000
|
Size: |
147456
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
CAC5BFC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2575524726.000000CAC5BFC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
CAC5BFC000
|
Size: |
16384
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2231404804.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
303D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2580216994.000000000303D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
303D000
|
Size: |
12288
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230918814.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
CAC5B7E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2575489601.000000CAC5B7E000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
CAC5B7E000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2235279732.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
CAC647E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2576509016.000000CAC647E000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
CAC647E000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2229895465.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
1C0000
|
unclassified section
|
page readonly
|
|
|
|
Name: |
00000000.00000002.2575900870.00000000001C0000.00000002.10000000.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page readonly
|
Base address: |
1C0000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230503919.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2223340738.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2229351961.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
8192
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2233284643.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
CAC587D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2575401979.000000CAC587D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
CAC587D000
|
Size: |
12288
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230152250.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2230728575.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2233119018.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2232319111.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|
2603B280000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2578527242.000002603B280000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2603B280000
|
Size: |
4096
|
|
2603AC48000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1365938153.000002603AC48000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2603AC48000
|
Size: |
262144
|
|
2DFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2580118673.0000000002DFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2DFE000
|
Size: |
8192
|
|
7F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2576718270.00000000007F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7F0000
|
Size: |
12288
|
|
864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2234731827.0000000000864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
864000
|
Size: |
4096
|
|