2E80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64473122110.0000000002E80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E80000
|
Size: |
4096
|
|
262F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65014216981.000000000262F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
262F000
|
Size: |
4096
|
|
617000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000005.00000002.65684282624.0000000000617000.00000008.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
617000
|
Size: |
4096
|
|
A3E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64438004095.0000000000A3E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A3E000
|
Size: |
4096
|
|
33B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64458091743.00000000033B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33B1000
|
Size: |
176128
|
|
A3B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64437911620.0000000000A3B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A3B000
|
Size: |
16384
|
|
A50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65686449565.0000000000A50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A50000
|
Size: |
4096
|
|
9D4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64436294756.00000000009D4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D4000
|
Size: |
8192
|
|
32CF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65689927553.00000000032CF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
32CF000
|
Size: |
4096
|
|
2421000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.65685370248.0000000002421000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2421000
|
Size: |
8192
|
|
2637000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65014216981.0000000002637000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2637000
|
Size: |
4096
|
|
264B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64619880930.000000000264B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
264B000
|
Size: |
8192
|
|
3040000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65689300630.0000000003040000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3040000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
98C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64436399399.000000000098C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
98C000
|
Size: |
405504
|
|
9E8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64436031126.00000000009E8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9E8000
|
Size: |
12288
|
|
2655000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65014216981.0000000002655000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2655000
|
Size: |
4096
|
|
2961000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64439731305.0000000002961000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2961000
|
Size: |
16384
|
|
2637000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65043456638.0000000002637000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2637000
|
Size: |
4096
|
|
2645000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65062931577.0000000002645000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2645000
|
Size: |
36864
|
|
6CE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.65684197051.00000000006CE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6CE000
|
Size: |
131072
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
988000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64440163559.0000000000988000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
988000
|
Size: |
86016
|
|
2655000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64634675342.0000000002655000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2655000
|
Size: |
4096
|
|
2645000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64598543559.0000000002645000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2645000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
2648000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64598543559.0000000002648000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2648000
|
Size: |
8192
|
|
2645000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65014216981.0000000002645000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2645000
|
Size: |
32768
|
|
2400000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.65685306720.0000000002400000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2400000
|
Size: |
8192
|
|
A28000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64598209342.0000000000A28000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A28000
|
Size: |
49152
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
25A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65686650854.00000000025A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25A0000
|
Size: |
4096
|
|
2655000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64965126850.0000000002655000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2655000
|
Size: |
4096
|
|
2260000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.65684817658.0000000002260000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2260000
|
Size: |
4096
|
|
2645000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64564834260.0000000002645000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2645000
|
Size: |
4096
|
|
262F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65055546953.000000000262F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
262F000
|
Size: |
4096
|
|
2637000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64619880930.0000000002637000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2637000
|
Size: |
4096
|
|
19A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65682906357.000000000019A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
19A000
|
Size: |
24576
|
|
2645000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64650350699.0000000002645000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2645000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
2999000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65687862327.0000000002999000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2999000
|
Size: |
4096
|
|
5599000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64600745181.0000000005599000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5599000
|
Size: |
3997696
|
|
262F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64939498153.000000000262F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
262F000
|
Size: |
20480
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
A7B6779000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.65682835263.000000A7B6779000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
A7B6779000
|
Size: |
28672
|
|
9C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64435843682.00000000009C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9C1000
|
Size: |
126976
|
|
9D6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64437566745.00000000009D6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D6000
|
Size: |
40960
|
|
C47D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65711317269.000000000C47D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C47D000
|
Size: |
12288
|
|
2E80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64473222424.0000000002E80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E80000
|
Size: |
4096
|
|
401000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000009.00000002.65683227657.0000000000401000.00000020.00000001.01000000.0000000C.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
401000
|
Size: |
299008
|
|
2930000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65687685467.0000000002930000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2930000
|
Size: |
8192
|
|
29CF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65687862327.00000000029CF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29CF000
|
Size: |
12288
|
|
A28000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64439631355.0000000000A28000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A28000
|
Size: |
12288
|
|
9C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64435546405.00000000009C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9C1000
|
Size: |
188416
|
|
9D4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64473526006.00000000009D4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D4000
|
Size: |
8192
|
|
1D90AA41000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.65684197033.000001D90AA41000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1D90AA41000
|
Size: |
16384
|
|
2633000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64529135804.0000000002633000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2633000
|
Size: |
4096
|
|
290E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65687461312.000000000290E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
290E000
|
Size: |
8192
|
|
1D90A990000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.65683516268.000001D90A990000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1D90A990000
|
Size: |
4096
|
|
2645000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64619880930.0000000002645000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2645000
|
Size: |
8192
|
|
5832000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65690955337.0000000005832000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5832000
|
Size: |
36864
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
57CF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65155924750.00000000057CF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
57CF000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
A30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64438751143.0000000000A30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A30000
|
Size: |
4096
|
|
9A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64436580394.00000000009A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9A0000
|
Size: |
204800
|
|
9C3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64438688643.00000000009C3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9C3000
|
Size: |
53248
|
|
264C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64597671997.000000000264C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
264C000
|
Size: |
4096
|
|
262F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64590392463.000000000262F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
262F000
|
Size: |
4096
|
|
97E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64435721553.000000000097E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
97E000
|
Size: |
28672
|
|
5842000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65260956996.0000000005842000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5842000
|
Size: |
159744
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
AV process strings found (often used to terminate AV products) |
Lowering of HIPS / PFW / Operating System Security Settings |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
2655000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64557308414.0000000002655000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2655000
|
Size: |
12288
|
|
9E3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64436031126.00000000009E3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9E3000
|
Size: |
12288
|
|
59B000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000002.65683861864.000000000059B000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
59B000
|
Size: |
450560
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
A38000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64598136802.0000000000A38000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A38000
|
Size: |
20480
|
|
2645000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65043456638.0000000002645000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2645000
|
Size: |
32768
|
|
2655000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64598543559.0000000002655000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2655000
|
Size: |
4096
|
|
9E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64435785355.00000000009E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9E0000
|
Size: |
45056
|
|
BDD8000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65710952945.000000000BDD8000.00000004.00000001.01000000.0000000A.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
BDD8000
|
Size: |
12288
|
|
264C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64605109588.000000000264C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
264C000
|
Size: |
4096
|
|
A3B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64715095351.0000000000A3B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A3B000
|
Size: |
16384
|
|
57F3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65260956996.00000000057F3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
57F3000
|
Size: |
4096
|
|
264B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64650350699.000000000264B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
264B000
|
Size: |
8192
|
|
99D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64439097487.000000000099D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
99D000
|
Size: |
151552
|
|
9EB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64436779128.00000000009EB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9EB000
|
Size: |
16384
|
|
296A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64438568022.000000000296A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
296A000
|
Size: |
8192
|
|
2633000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64557437339.0000000002633000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2633000
|
Size: |
4096
|
|
9D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64437449236.00000000009D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D0000
|
Size: |
65536
|
|
5843000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65209331608.0000000005843000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5843000
|
Size: |
155648
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
AV process strings found (often used to terminate AV products) |
Lowering of HIPS / PFW / Operating System Security Settings |
Security Software Discovery
|
|
9C2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64440486031.00000000009C2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9C2000
|
Size: |
36864
|
|
2655000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65035894043.0000000002655000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2655000
|
Size: |
4096
|
|
2637000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64598757083.0000000002637000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2637000
|
Size: |
4096
|
|
57F3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65282683181.00000000057F3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
57F3000
|
Size: |
4096
|
|
A28000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64598884287.0000000000A28000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A28000
|
Size: |
49152
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2655000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64597671997.0000000002655000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2655000
|
Size: |
4096
|
|
2637000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64627113533.0000000002637000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2637000
|
Size: |
4096
|
|
97E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64436399399.000000000097E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
97E000
|
Size: |
4096
|
|
9E2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64437045844.00000000009E2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9E2000
|
Size: |
53248
|
|
29A2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64598679322.00000000029A2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29A2000
|
Size: |
311296
|
|
2655000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64650350699.0000000002655000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2655000
|
Size: |
4096
|
|
2648000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64669015323.0000000002648000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2648000
|
Size: |
8192
|
|
BE1A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65159076369.000000000BE1A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BE1A000
|
Size: |
233472
|
|
2648000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64572041339.0000000002648000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2648000
|
Size: |
4096
|
|
264B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64939498153.000000000264B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
264B000
|
Size: |
8192
|
|
BE00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65711025839.000000000BE00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BE00000
|
Size: |
12288
|
|
6A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.65684118942.00000000006A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6A0000
|
Size: |
4096
|
|
2A1E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64714965223.0000000002A1E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A1E000
|
Size: |
4096
|
|
296C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64437881309.000000000296C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
296C000
|
Size: |
16384
|
|
25F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65686679062.00000000025F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25F0000
|
Size: |
12288
|
|
568F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65690908732.000000000568F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
568F000
|
Size: |
4096
|
|
A37000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65685771122.0000000000A37000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A37000
|
Size: |
12288
|
|
2655000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64669400229.0000000002655000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2655000
|
Size: |
4096
|
|
5842000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65245149130.0000000005842000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5842000
|
Size: |
159744
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
AV process strings found (often used to terminate AV products) |
Lowering of HIPS / PFW / Operating System Security Settings |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
609000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65684050436.0000000000609000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
609000
|
Size: |
12288
|
|
264C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64598543559.000000000264C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
264C000
|
Size: |
4096
|
|
2645000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64605109588.0000000002645000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2645000
|
Size: |
8192
|
|
2655000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64972478692.0000000002655000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2655000
|
Size: |
4096
|
|
2637000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64612508941.0000000002637000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2637000
|
Size: |
4096
|
|
97C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64440088564.000000000097C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
97C000
|
Size: |
16384
|
|
A37000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64598496568.0000000000A37000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A37000
|
Size: |
4096
|
|
975000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64440550126.0000000000975000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
975000
|
Size: |
28672
|
|
2645000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64572041339.0000000002645000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2645000
|
Size: |
4096
|
|
9E9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64715452114.00000000009E9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9E9000
|
Size: |
131072
|
|
22C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.65685085467.00000000022C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22C0000
|
Size: |
4096
|
|
C120000
|
remote allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65230716067.000000000C120000.00000004.00000400.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
remote allocation
|
Protect: |
page read and write
|
Base address: |
C120000
|
Size: |
4096
|
|
4EDE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65690772132.0000000004EDE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4EDE000
|
Size: |
8192
|
|
296C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64440354567.000000000296C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
296C000
|
Size: |
16384
|
|
330E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65689996933.000000000330E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
330E000
|
Size: |
8192
|
|
2A1D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65687862327.0000000002A1D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A1D000
|
Size: |
57344
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
5804000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65690955337.0000000005804000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5804000
|
Size: |
4096
|
|
550000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.65683825652.0000000000550000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
550000
|
Size: |
4096
|
|
816000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65685609776.0000000000816000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
816000
|
Size: |
12288
|
|
2645000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64669400229.0000000002645000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2645000
|
Size: |
8192
|
|
262F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64557437339.000000000262F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
262F000
|
Size: |
4096
|
|
1D90A980000
|
unclassified section
|
page readonly
|
|
|
|
Name: |
00000000.00000002.65683424910.000001D90A980000.00000002.10000000.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page readonly
|
Base address: |
1D90A980000
|
Size: |
4096
|
|
29B6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65687862327.00000000029B6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29B6000
|
Size: |
40960
|
|
2655000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64939498153.0000000002655000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2655000
|
Size: |
4096
|
|
A34000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64438004095.0000000000A34000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A34000
|
Size: |
28672
|
|
57F3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65268106271.00000000057F3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
57F3000
|
Size: |
4096
|
|
9E9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64438126882.00000000009E9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9E9000
|
Size: |
24576
|
|
299C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64715285342.000000000299C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
299C000
|
Size: |
4096
|
|
45D000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.65615420846.000000000045D000.00000002.00000001.01000000.0000000C.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
45D000
|
Size: |
40960
|
|
52B1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64600226560.00000000052B1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
52B1000
|
Size: |
4096
|
|
2655000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64557437339.0000000002655000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2655000
|
Size: |
12288
|
|
9E4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64439043896.00000000009E4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9E4000
|
Size: |
8192
|
|
C5FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65711431455.000000000C5FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C5FE000
|
Size: |
8192
|
|
9C5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64436346951.00000000009C5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9C5000
|
Size: |
16384
|
|
5D70000
|
stack
|
page readonly
|
|
|
|
Name: |
00000005.00000002.65691591234.0000000005D70000.00000002.00000010.00040000.00000009.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page readonly
|
Base address: |
5D70000
|
Size: |
10485760
|
|
31CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65689855835.00000000031CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
31CE000
|
Size: |
8192
|
|
262B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64529135804.000000000262B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
262B000
|
Size: |
4096
|
|
2655000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65055546953.0000000002655000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2655000
|
Size: |
4096
|
|
A28000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64715095351.0000000000A28000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A28000
|
Size: |
49152
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
264B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64643053248.000000000264B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
264B000
|
Size: |
8192
|
|
2648000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64597671997.0000000002648000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2648000
|
Size: |
8192
|
|
A37000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64598884287.0000000000A37000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A37000
|
Size: |
4096
|
|
A31000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64438262177.0000000000A31000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A31000
|
Size: |
12288
|
|
57B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65690955337.00000000057B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
57B0000
|
Size: |
315392
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
AV process strings found (often used to terminate AV products) |
Lowering of HIPS / PFW / Operating System Security Settings |
Security Software Discovery
|
|
2A0A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64599558758.0000000002A0A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A0A000
|
Size: |
131072
|
|
BE4E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65711058890.000000000BE4E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BE4E000
|
Size: |
8192
|
|
A28000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64715452114.0000000000A28000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A28000
|
Size: |
49152
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
99D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64436692516.000000000099D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
99D000
|
Size: |
12288
|
|
329B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64455072510.000000000329B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
329B000
|
Size: |
4096
|
|
458000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000009.00000000.65615383151.0000000000458000.00000008.00000001.01000000.0000000C.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
458000
|
Size: |
8192
|
|
2655000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64619880930.0000000002655000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2655000
|
Size: |
4096
|
|
982000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64435843682.0000000000982000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
982000
|
Size: |
12288
|
|
3050000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64529290301.0000000003050000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3050000
|
Size: |
4096
|
|
5842000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65268106271.0000000005842000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5842000
|
Size: |
159744
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
AV process strings found (often used to terminate AV products) |
Lowering of HIPS / PFW / Operating System Security Settings |
Security Software Discovery
|
|
9C5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64437109893.00000000009C5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9C5000
|
Size: |
118784
|
|
985000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64435546405.0000000000985000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
985000
|
Size: |
167936
|
|
98B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64598884287.000000000098B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
98B000
|
Size: |
266240
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
A37000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64598209342.0000000000A37000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A37000
|
Size: |
4096
|
|
2637000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64643053248.0000000002637000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2637000
|
Size: |
4096
|
|
5842000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65615684858.0000000005842000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5842000
|
Size: |
159744
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
AV process strings found (often used to terminate AV products) |
Lowering of HIPS / PFW / Operating System Security Settings |
Security Software Discovery
|
|
3050000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64529338206.0000000003050000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3050000
|
Size: |
4096
|
|
44A000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.65683400124.000000000044A000.00000002.00000001.01000000.0000000C.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
44A000
|
Size: |
57344
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
975000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64598209342.0000000000975000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
975000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
57C8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65156023010.00000000057C8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
57C8000
|
Size: |
16384
|
|
C4BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65711353577.000000000C4BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C4BE000
|
Size: |
8192
|
|
9E5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64440203260.00000000009E5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9E5000
|
Size: |
188416
|
|
2645000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65028745124.0000000002645000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2645000
|
Size: |
32768
|
|
9D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64436090060.00000000009D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D0000
|
Size: |
65536
|
|
4EA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65690772132.0000000004EA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4EA0000
|
Size: |
131072
|
|
2655000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64597468566.0000000002655000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2655000
|
Size: |
4096
|
|
29A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65687862327.00000000029A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29A0000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
99000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65682822612.0000000000099000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
99000
|
Size: |
28672
|
|
264B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64612508941.000000000264B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
264B000
|
Size: |
8192
|
|
9CE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65685771122.00000000009CE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9CE000
|
Size: |
32768
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
9C6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64437155860.00000000009C6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9C6000
|
Size: |
114688
|
|
5C6E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65691512841.0000000005C6E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5C6E000
|
Size: |
8192
|
|
8570000
|
stack
|
page readonly
|
|
|
|
Name: |
00000005.00000002.65691591234.0000000008570000.00000002.00000010.00040000.00000009.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page readonly
|
Base address: |
8570000
|
Size: |
10485760
|
|
10000000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000002.65711508673.0000000010000000.00000002.00000001.01000000.00000009.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
10000000
|
Size: |
4096
|
|
262F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64979948530.000000000262F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
262F000
|
Size: |
4096
|
|
5832000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65309908503.0000000005832000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5832000
|
Size: |
36864
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
5842000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65690955337.0000000005842000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5842000
|
Size: |
159744
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
AV process strings found (often used to terminate AV products) |
Lowering of HIPS / PFW / Operating System Security Settings |
Security Software Discovery
|
|
22B5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.65684913442.00000000022B5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22B5000
|
Size: |
16384
|
|
2645000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64979948530.0000000002645000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2645000
|
Size: |
8192
|
|
9D6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64438221894.00000000009D6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D6000
|
Size: |
77824
|
|
2637000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64972478692.0000000002637000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2637000
|
Size: |
4096
|
|
2648000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64597468566.0000000002648000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2648000
|
Size: |
8192
|
|
C25A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65711235113.000000000C25A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C25A000
|
Size: |
24576
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
264B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64669015323.000000000264B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
264B000
|
Size: |
8192
|
|
29A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64715285342.00000000029A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29A0000
|
Size: |
8192
|
|
262F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65062931577.000000000262F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
262F000
|
Size: |
4096
|
|
2648000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64939498153.0000000002648000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2648000
|
Size: |
8192
|
|
60E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.65683967677.000000000060E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
60E000
|
Size: |
8192
|
|
30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65682737520.0000000000030000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30000
|
Size: |
4096
|
|
8F70000
|
stack
|
page readonly
|
|
|
|
Name: |
00000005.00000002.65691591234.0000000008F70000.00000002.00000010.00040000.00000009.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page readonly
|
Base address: |
8F70000
|
Size: |
10485760
|
|
810000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65685609776.0000000000810000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
810000
|
Size: |
16384
|
|
262F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64965126850.000000000262F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
262F000
|
Size: |
4096
|
|
28CF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65687402041.00000000028CF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
28CF000
|
Size: |
4096
|
|
304A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65689300630.000000000304A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
304A000
|
Size: |
12288
|
|
9E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64436514379.00000000009E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9E0000
|
Size: |
61440
|
|
651000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000000.64405417696.0000000000651000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
651000
|
Size: |
888832
|
|
2637000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64572041339.0000000002637000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2637000
|
Size: |
4096
|
|
262F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64643053248.000000000262F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
262F000
|
Size: |
4096
|
|
358D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65690345046.000000000358D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
358D000
|
Size: |
12288
|
|
A3B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64715452114.0000000000A3B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A3B000
|
Size: |
16384
|
|
400000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000000.64404763813.0000000000400000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
400000
|
Size: |
4096
|
|
9E4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64440002154.00000000009E4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9E4000
|
Size: |
192512
|
|
2920000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.65687524224.0000000002920000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
2920000
|
Size: |
4096
|
|
99D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64437486959.000000000099D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
99D000
|
Size: |
159744
|
|
2648000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64634675342.0000000002648000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2648000
|
Size: |
8192
|
|
5842000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65282683181.0000000005842000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5842000
|
Size: |
159744
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
AV process strings found (often used to terminate AV products) |
Lowering of HIPS / PFW / Operating System Security Settings |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.65682730266.0000000000030000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30000
|
Size: |
4096
|
|
A3E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64599613064.0000000000A3E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A3E000
|
Size: |
4096
|
|
5C2F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65691482105.0000000005C2F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5C2F000
|
Size: |
4096
|
|
5832000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65260956996.0000000005832000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5832000
|
Size: |
36864
|
|
5A1F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65691371331.0000000005A1F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5A1F000
|
Size: |
4096
|
|
2648000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64958008286.0000000002648000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2648000
|
Size: |
8192
|
|
400000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.65615137767.0000000000400000.00000002.00000001.01000000.0000000C.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
400000
|
Size: |
4096
|
|
8BF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.65684611215.00000000008BF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8BF000
|
Size: |
4096
|
|
296C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64598084439.000000000296C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
296C000
|
Size: |
139264
|
|
57CF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65156023010.00000000057CF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
57CF000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
989000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64438154747.0000000000989000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
989000
|
Size: |
233472
|
|
9D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64440580495.00000000009D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D0000
|
Size: |
24576
|
|
264B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64958008286.000000000264B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
264B000
|
Size: |
8192
|
|
1D90AA3D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.65683966202.000001D90AA3D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1D90AA3D000
|
Size: |
12288
|
|
4DA1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64598579181.0000000004DA1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DA1000
|
Size: |
102400
|
|
A7B657E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.65682757984.000000A7B657E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
A7B657E000
|
Size: |
8192
|
|
9D7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64439150174.00000000009D7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D7000
|
Size: |
53248
|
|
22B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.65684913442.00000000022B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22B0000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
3050000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64529383940.0000000003050000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3050000
|
Size: |
4096
|
|
1D90AA6C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.65684586403.000001D90AA6C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1D90AA6C000
|
Size: |
86016
|
|
629000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000002.65684583359.0000000000629000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
629000
|
Size: |
155648
|
|
584A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65223536479.000000000584A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
584A000
|
Size: |
126976
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2655000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64979948530.0000000002655000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2655000
|
Size: |
4096
|
|
57CF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65096028104.00000000057CF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
57CF000
|
Size: |
4096
|
|
2648000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64979948530.0000000002648000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2648000
|
Size: |
20480
|
|
1D90AB02000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.65684675884.000001D90AB02000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1D90AB02000
|
Size: |
16384
|
|
9D3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64438814064.00000000009D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D3000
|
Size: |
12288
|
|
2637000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64605109588.0000000002637000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2637000
|
Size: |
4096
|
|
B770000
|
stack
|
page readonly
|
|
|
|
Name: |
00000005.00000002.65691591234.000000000B770000.00000002.00000010.00040000.00000009.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page readonly
|
Base address: |
B770000
|
Size: |
6508544
|
|
2655000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64564834260.0000000002655000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2655000
|
Size: |
12288
|
|
25FE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65686679062.00000000025FE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25FE000
|
Size: |
4096
|
|
2418000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.65685370248.0000000002418000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2418000
|
Size: |
4096
|
|
1D90AA00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.65683619037.000001D90AA00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1D90AA00000
|
Size: |
4096
|
|
5910000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65691269538.0000000005910000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5910000
|
Size: |
16384
|
|
2648000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64965126850.0000000002648000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2648000
|
Size: |
20480
|
|
333C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64457777903.000000000333C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
333C000
|
Size: |
241664
|
|
5D6F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65691559762.0000000005D6F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5D6F000
|
Size: |
4096
|
|
262F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64564834260.000000000262F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
262F000
|
Size: |
4096
|
|
57CF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65117253083.00000000057CF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
57CF000
|
Size: |
8192
|
|
616000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65684206838.0000000000616000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
616000
|
Size: |
4096
|
|
57F3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65253430677.00000000057F3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
57F3000
|
Size: |
4096
|
|
6C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.65684197051.00000000006C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6C0000
|
Size: |
36864
|
|
9E7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64438814064.00000000009E7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9E7000
|
Size: |
8192
|
|
9D7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64438959909.00000000009D7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D7000
|
Size: |
61440
|
|
5842000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65309908503.0000000005842000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5842000
|
Size: |
159744
|
|
2645000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65687085487.0000000002645000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2645000
|
Size: |
36864
|
|
9EB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64435752287.00000000009EB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9EB000
|
Size: |
16384
|
|
19D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.65682902183.000000000019D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
19D000
|
Size: |
12288
|
|
2716000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65687214037.0000000002716000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2716000
|
Size: |
36864
|
|
A2E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64438292535.0000000000A2E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A2E000
|
Size: |
12288
|
|
2645000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64669015323.0000000002645000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2645000
|
Size: |
8192
|
|
9D9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64437618610.00000000009D9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D9000
|
Size: |
28672
|
|
584A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65230568707.000000000584A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
584A000
|
Size: |
126976
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
458000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000002.65683489847.0000000000458000.00000004.00000001.01000000.0000000C.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
458000
|
Size: |
12288
|
|
2A0A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64714965223.0000000002A0A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A0A000
|
Size: |
4096
|
|
9D6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64439631355.00000000009D6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D6000
|
Size: |
249856
|
|
9E3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64435843682.00000000009E3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9E3000
|
Size: |
12288
|
|
308C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65689588275.000000000308C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
308C000
|
Size: |
16384
|
|
9DE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64440642225.00000000009DE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9DE000
|
Size: |
24576
|
|
9D4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64436185670.00000000009D4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D4000
|
Size: |
8192
|
|
5916000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65691269538.0000000005916000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5916000
|
Size: |
36864
|
|
9D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64436637125.00000000009D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D0000
|
Size: |
8192
|
|
5832000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65282683181.0000000005832000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5832000
|
Size: |
36864
|
|
32E2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64457777903.00000000032E2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32E2000
|
Size: |
241664
|
|
7C7000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000000.64405417696.00000000007C7000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7C7000
|
Size: |
102400
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
2614000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64597797930.0000000002614000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2614000
|
Size: |
110592
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
A51000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65615571903.0000000000A51000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A51000
|
Size: |
417792
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
236E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.65685146187.000000000236E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
236E000
|
Size: |
8192
|
|
A09000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64715095351.0000000000A09000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A09000
|
Size: |
40960
|
|
1D90AA13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.65683794349.000001D90AA13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1D90AA13000
|
Size: |
77824
|
|
2648000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64627113533.0000000002648000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2648000
|
Size: |
8192
|
|
262F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64627113533.000000000262F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
262F000
|
Size: |
4096
|
|
2934000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65687685467.0000000002934000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2934000
|
Size: |
8192
|
|
1D90A8D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.65682908446.000001D90A8D0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1D90A8D0000
|
Size: |
4096
|
|
2648000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64987526393.0000000002648000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2648000
|
Size: |
20480
|
|
8F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65685743109.00000000008F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F0000
|
Size: |
8192
|
|
2645000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64590392463.0000000002645000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2645000
|
Size: |
4096
|
|
2EBC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65689151187.0000000002EBC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2EBC000
|
Size: |
16384
|
|
2645000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64612508941.0000000002645000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2645000
|
Size: |
8192
|
|
980000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64439821345.0000000000980000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
980000
|
Size: |
352256
|
|
296C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64473400241.000000000296C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
296C000
|
Size: |
90112
|
|
2613000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64557569594.0000000002613000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2613000
|
Size: |
98304
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
9C2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64436809791.00000000009C2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9C2000
|
Size: |
57344
|
|
45D000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.65683573068.000000000045D000.00000002.00000001.01000000.0000000C.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
45D000
|
Size: |
40960
|
|
5842000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65216304057.0000000005842000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5842000
|
Size: |
4096
|
|
57CA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65178139763.00000000057CA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
57CA000
|
Size: |
36864
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
A28000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65685771122.0000000000A28000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A28000
|
Size: |
49152
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
9C2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64437944901.00000000009C2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9C2000
|
Size: |
184320
|
|
262F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64612508941.000000000262F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
262F000
|
Size: |
4096
|
|
7B70000
|
stack
|
page readonly
|
|
|
|
Name: |
00000005.00000002.65691591234.0000000007B70000.00000002.00000010.00040000.00000009.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page readonly
|
Base address: |
7B70000
|
Size: |
10485760
|
|
5832000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65216304057.0000000005832000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5832000
|
Size: |
36864
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1D90B402000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.65684816504.000001D90B402000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1D90B402000
|
Size: |
4096
|
|
5B2E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65691424164.0000000005B2E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5B2E000
|
Size: |
8192
|
|
2637000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64564834260.0000000002637000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2637000
|
Size: |
4096
|
|
263F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64669015323.000000000263F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
263F000
|
Size: |
4096
|
|
9C9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64436320913.00000000009C9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9C9000
|
Size: |
28672
|
|
BDB0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000002.65710833823.000000000BDB0000.00000002.00000001.01000000.0000000A.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BDB0000
|
Size: |
4096
|
|
2655000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65002412186.0000000002655000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2655000
|
Size: |
4096
|
|
9D2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64436548440.00000000009D2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D2000
|
Size: |
57344
|
|
1D90AA2A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.65683966202.000001D90AA2A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1D90AA2A000
|
Size: |
61440
|
|
A28000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64440002154.0000000000A28000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A28000
|
Size: |
4096
|
|
401000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000005.00000002.65683234028.0000000000401000.00000020.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
401000
|
Size: |
1679360
|
|
296D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64440517967.000000000296D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
296D000
|
Size: |
12288
|
|
6CA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.65684197051.00000000006CA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6CA000
|
Size: |
12288
|
|
9D3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64438959909.00000000009D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D3000
|
Size: |
12288
|
|
817000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64537867952.0000000000817000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
817000
|
Size: |
8192
|
|
329F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64457777903.000000000329F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
329F000
|
Size: |
262144
|
|
788000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000002.65684583359.0000000000788000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
788000
|
Size: |
241664
|
|
264B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64634675342.000000000264B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
264B000
|
Size: |
8192
|
|
9D9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64439205756.00000000009D9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D9000
|
Size: |
45056
|
|
2633000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64498879415.0000000002633000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2633000
|
Size: |
4096
|
|
2648000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64619880930.0000000002648000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2648000
|
Size: |
8192
|
|
2655000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65028745124.0000000002655000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2655000
|
Size: |
4096
|
|
9D7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65685771122.00000000009D7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D7000
|
Size: |
253952
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
C120000
|
remote allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65230866456.000000000C120000.00000004.00000400.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
remote allocation
|
Protect: |
page read and write
|
Base address: |
C120000
|
Size: |
4096
|
|
262F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65021729204.000000000262F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
262F000
|
Size: |
4096
|
|
2655000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65043456638.0000000002655000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2655000
|
Size: |
4096
|
|
2637000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65062931577.0000000002637000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2637000
|
Size: |
4096
|
|
2655000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64643053248.0000000002655000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2655000
|
Size: |
4096
|
|
97C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64438619990.000000000097C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
97C000
|
Size: |
12288
|
|
2655000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64987526393.0000000002655000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2655000
|
Size: |
4096
|
|
2645000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64627113533.0000000002645000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2645000
|
Size: |
8192
|
|
262F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64619880930.000000000262F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
262F000
|
Size: |
4096
|
|
57D1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65118579432.00000000057D1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
57D1000
|
Size: |
36864
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
A37000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64715452114.0000000000A37000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A37000
|
Size: |
12288
|
|
2637000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64590392463.0000000002637000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2637000
|
Size: |
4096
|
|
BF9E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65711123452.000000000BF9E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BF9E000
|
Size: |
8192
|
|
9D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64438493984.00000000009D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D0000
|
Size: |
24576
|
|
35A1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64537803294.00000000035A1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35A1000
|
Size: |
65536
|
|
3185000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65689740870.0000000003185000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3185000
|
Size: |
45056
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4C10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65690505501.0000000004C10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4C10000
|
Size: |
4096
|
|
9BF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.65684679315.00000000009BF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9BF000
|
Size: |
4096
|
|
AD70000
|
stack
|
page readonly
|
|
|
|
Name: |
00000005.00000002.65691591234.000000000AD70000.00000002.00000010.00040000.00000009.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page readonly
|
Base address: |
AD70000
|
Size: |
10485760
|
|
2656000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64564995524.0000000002656000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2656000
|
Size: |
8192
|
|
5832000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65177623859.0000000005832000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5832000
|
Size: |
36864
|
|
72D000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000000.64405417696.000000000072D000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
72D000
|
Size: |
241664
|
|
57DA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65118473742.00000000057DA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
57DA000
|
Size: |
159744
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
9CD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64439178452.00000000009CD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9CD000
|
Size: |
12288
|
|
5832000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65268106271.0000000005832000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5832000
|
Size: |
36864
|
|
57F3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65309908503.00000000057F3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
57F3000
|
Size: |
4096
|
|
2983000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64473400241.0000000002983000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2983000
|
Size: |
77824
|
|
51B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64600226560.00000000051B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
51B0000
|
Size: |
1024000
|
|
609000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000005.00000000.64405381588.0000000000609000.00000008.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
609000
|
Size: |
69632
|
|
262F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65002412186.000000000262F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
262F000
|
Size: |
4096
|
|
4CA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65690663435.0000000004CA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CA0000
|
Size: |
69632
|
|
2645000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64965126850.0000000002645000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2645000
|
Size: |
8192
|
|
2637000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64939498153.0000000002637000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2637000
|
Size: |
4096
|
|
9CB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64440296466.00000000009CB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9CB000
|
Size: |
8192
|
|
263B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64498879415.000000000263B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
263B000
|
Size: |
4096
|
|
29AE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65687862327.00000000029AE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29AE000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
9C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64436185670.00000000009C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9C1000
|
Size: |
61440
|
|
29A2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64599377198.00000000029A2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29A2000
|
Size: |
131072
|
|
2A25000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64714965223.0000000002A25000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A25000
|
Size: |
4096
|
|
262F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64634675342.000000000262F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
262F000
|
Size: |
4096
|
|
A2D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64598496568.0000000000A2D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A2D000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
A28000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64440203260.0000000000A28000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A28000
|
Size: |
4096
|
|
2FBE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65689209220.0000000002FBE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2FBE000
|
Size: |
8192
|
|
9C5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64438814064.00000000009C5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9C5000
|
Size: |
45056
|
|
540000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.65683656536.0000000000540000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
540000
|
Size: |
16384
|
|
2637000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65055546953.0000000002637000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2637000
|
Size: |
4096
|
|
9E7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64437315611.00000000009E7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9E7000
|
Size: |
32768
|
|
2410000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.65685370248.0000000002410000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2410000
|
Size: |
4096
|
|
4DA1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64600149819.0000000004DA1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DA1000
|
Size: |
126976
|
|
584A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65178099565.000000000584A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
584A000
|
Size: |
4096
|
|
A2E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64438530328.0000000000A2E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A2E000
|
Size: |
12288
|
|
9E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64437315611.00000000009E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9E0000
|
Size: |
8192
|
|
9E6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64438722277.00000000009E6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9E6000
|
Size: |
12288
|
|
262F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64650350699.000000000262F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
262F000
|
Size: |
4096
|
|
A32000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64438751143.0000000000A32000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A32000
|
Size: |
8192
|
|
264B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64669400229.000000000264B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
264B000
|
Size: |
8192
|
|
9D7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64473526006.00000000009D7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D7000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
9CD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64437593676.00000000009CD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9CD000
|
Size: |
12288
|
|
978000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64598884287.0000000000978000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
978000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
584A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65216525788.000000000584A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
584A000
|
Size: |
126976
|
|
2637000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65035894043.0000000002637000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2637000
|
Size: |
4096
|
|
2999000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64715285342.0000000002999000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2999000
|
Size: |
4096
|
|
9CE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64598209342.00000000009CE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9CE000
|
Size: |
32768
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2A07000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65687862327.0000000002A07000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A07000
|
Size: |
8192
|
|
2720000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65687314052.0000000002720000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2720000
|
Size: |
4096
|
|
1D90A970000
|
unclassified section
|
page readonly
|
|
|
|
Name: |
00000000.00000002.65683332115.000001D90A970000.00000002.10000000.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page readonly
|
Base address: |
1D90A970000
|
Size: |
4096
|
|
99D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64439940450.000000000099D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
99D000
|
Size: |
196608
|
|
2648000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64669400229.0000000002648000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2648000
|
Size: |
8192
|
|
94A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65685771122.000000000094A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
94A000
|
Size: |
12288
|
|
9CE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64598884287.00000000009CE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9CE000
|
Size: |
32768
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
618000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65684425147.0000000000618000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
618000
|
Size: |
36864
|
|
2655000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64669015323.0000000002655000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2655000
|
Size: |
4096
|
|
1D90B270000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.65684744833.000001D90B270000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1D90B270000
|
Size: |
4096
|
|
1D90AA02000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.65683619037.000001D90AA02000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1D90AA02000
|
Size: |
65536
|
|
9A1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64436692516.00000000009A1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9A1000
|
Size: |
192512
|
|
940000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65685771122.0000000000940000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
940000
|
Size: |
32768
|
|
400000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000002.65682973492.0000000000400000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
400000
|
Size: |
4096
|
|
2645000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64972478692.0000000002645000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2645000
|
Size: |
8192
|
|
BE15000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65156126290.000000000BE15000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BE15000
|
Size: |
4096
|
|
584A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65216304057.000000000584A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
584A000
|
Size: |
126976
|
|
98C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64435843682.000000000098C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
98C000
|
Size: |
139264
|
|
2E80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64473175979.0000000002E80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E80000
|
Size: |
4096
|
|
262F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64958008286.000000000262F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
262F000
|
Size: |
4096
|
|
2648000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64650350699.0000000002648000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2648000
|
Size: |
8192
|
|
59B000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000000.64405269010.000000000059B000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
59B000
|
Size: |
450560
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
264C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64590392463.000000000264C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
264C000
|
Size: |
4096
|
|
27CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65687368211.00000000027CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
27CE000
|
Size: |
8192
|
|
400000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.65682968831.0000000000400000.00000002.00000001.01000000.0000000C.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
400000
|
Size: |
4096
|
|
5832000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65245149130.0000000005832000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5832000
|
Size: |
36864
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
94E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65685771122.000000000094E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
94E000
|
Size: |
229376
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
97F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64438469537.000000000097F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
97F000
|
Size: |
28672
|
|
2A0A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65687862327.0000000002A0A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A0A000
|
Size: |
24576
|
|
36A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64537937834.00000000036A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
36A0000
|
Size: |
188416
|
|
299C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65687862327.000000000299C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
299C000
|
Size: |
4096
|
|
2648000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64605109588.0000000002648000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2648000
|
Size: |
8192
|
|
9D7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64598209342.00000000009D7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D7000
|
Size: |
245760
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
A3B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65685771122.0000000000A3B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A3B000
|
Size: |
16384
|
|
BDDC000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000002.65710986211.000000000BDDC000.00000002.00000001.01000000.0000000A.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BDDC000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
97C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64437079731.000000000097C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
97C000
|
Size: |
16384
|
|
9D6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64436124664.00000000009D6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D6000
|
Size: |
40960
|
|
9E8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64435843682.00000000009E8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9E8000
|
Size: |
12288
|
|
C5BF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65711392227.000000000C5BF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C5BF000
|
Size: |
4096
|
|
D8E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65686598143.0000000000D8E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
D8E000
|
Size: |
8192
|
|
788000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000000.64405417696.0000000000788000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
788000
|
Size: |
241664
|
|
2645000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65021729204.0000000002645000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2645000
|
Size: |
32768
|
|
629000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000000.64405417696.0000000000629000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
629000
|
Size: |
155648
|
|
2710000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65687214037.0000000002710000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2710000
|
Size: |
16384
|
|
3047000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64601528828.0000000003047000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3047000
|
Size: |
24576
|
|
9EC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64438292535.00000000009EC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9EC000
|
Size: |
12288
|
|
9D7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64598884287.00000000009D7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D7000
|
Size: |
245760
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2940000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65687862327.0000000002940000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2940000
|
Size: |
200704
|
|
401000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000005.00000000.64404855705.0000000000401000.00000020.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
401000
|
Size: |
1679360
|
|
2645000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64557308414.0000000002645000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2645000
|
Size: |
4096
|
|
262B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64557437339.000000000262B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
262B000
|
Size: |
4096
|
|
9D9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64440610264.00000000009D9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D9000
|
Size: |
45056
|
|
621000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000000.64405417696.0000000000621000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
621000
|
Size: |
24576
|
|
2655000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64590392463.0000000002655000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2655000
|
Size: |
4096
|
|
2637000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65021729204.0000000002637000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2637000
|
Size: |
4096
|
|
2655000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65687085487.0000000002655000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2655000
|
Size: |
4096
|
|
9E7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64439043896.00000000009E7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9E7000
|
Size: |
8192
|
|
C15C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65711198292.000000000C15C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C15C000
|
Size: |
16384
|
|
1D90AA3A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.65683966202.000001D90AA3A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1D90AA3A000
|
Size: |
8192
|
|
98C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64437155860.000000000098C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
98C000
|
Size: |
233472
|
|
2637000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65002412186.0000000002637000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2637000
|
Size: |
4096
|
|
29D4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64599377198.00000000029D4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29D4000
|
Size: |
106496
|
|
260F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.65685590634.000000000260F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
260F000
|
Size: |
4096
|
|
A37000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64715095351.0000000000A37000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A37000
|
Size: |
12288
|
|
2962000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64438064340.0000000002962000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2962000
|
Size: |
8192
|
|
2614000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64598757083.0000000002614000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2614000
|
Size: |
110592
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
9E7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64437155860.00000000009E7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9E7000
|
Size: |
32768
|
|
C8E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65686494871.0000000000C8E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C8E000
|
Size: |
8192
|
|
57CF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65118532734.00000000057CF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
57CF000
|
Size: |
45056
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3321000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64457777903.0000000003321000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3321000
|
Size: |
98304
|
|
25F6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65686679062.00000000025F6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25F6000
|
Size: |
24576
|
|
2655000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65021729204.0000000002655000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2655000
|
Size: |
4096
|
|
98B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64598209342.000000000098B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
98B000
|
Size: |
266240
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2A0C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64714965223.0000000002A0C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A0C000
|
Size: |
69632
|
|
2645000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64634675342.0000000002645000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2645000
|
Size: |
8192
|
|
2971000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64715285342.0000000002971000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2971000
|
Size: |
118784
|
|
A3A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64598782503.0000000000A3A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A3A000
|
Size: |
8192
|
|
2637000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65028745124.0000000002637000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2637000
|
Size: |
4096
|
|
9C4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64437377034.00000000009C4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9C4000
|
Size: |
4096
|
|
262F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65043456638.000000000262F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
262F000
|
Size: |
4096
|
|
98C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64440416109.000000000098C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
98C000
|
Size: |
69632
|
|
9D9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64436154373.00000000009D9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D9000
|
Size: |
28672
|
|
9D7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64438814064.00000000009D7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D7000
|
Size: |
61440
|
|
C37C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65711277312.000000000C37C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C37C000
|
Size: |
16384
|
|
5803000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65615684858.0000000005803000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5803000
|
Size: |
8192
|
|
5CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.65683892949.00000000005CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5CE000
|
Size: |
8192
|
|
2655000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65062931577.0000000002655000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2655000
|
Size: |
4096
|
|
2637000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64965126850.0000000002637000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2637000
|
Size: |
4096
|
|
984000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64438619990.0000000000984000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
984000
|
Size: |
8192
|
|
331E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64457777903.000000000331E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
331E000
|
Size: |
8192
|
|
264C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64597468566.000000000264C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
264C000
|
Size: |
4096
|
|
D10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65686570446.0000000000D10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D10000
|
Size: |
4096
|
|
7C4000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000002.65684583359.00000000007C4000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7C4000
|
Size: |
8192
|
|
264B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64627113533.000000000264B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
264B000
|
Size: |
8192
|
|
262F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64987526393.000000000262F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
262F000
|
Size: |
4096
|
|
6770000
|
stack
|
page readonly
|
|
|
|
Name: |
00000005.00000002.65691591234.0000000006770000.00000002.00000010.00040000.00000009.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page readonly
|
Base address: |
6770000
|
Size: |
10485760
|
|
2645000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64597468566.0000000002645000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2645000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
57D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65216613806.00000000057D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
57D0000
|
Size: |
110592
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2638000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64557308414.0000000002638000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2638000
|
Size: |
8192
|
|
270F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.65685655988.000000000270F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
270F000
|
Size: |
4096
|
|
2645000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64557437339.0000000002645000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2645000
|
Size: |
4096
|
|
2648000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64590392463.0000000002648000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2648000
|
Size: |
4096
|
|
44A000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.65615335906.000000000044A000.00000002.00000001.01000000.0000000C.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
44A000
|
Size: |
57344
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
A7B5FAB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.65682702825.000000A7B5FAB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
A7B5FAB000
|
Size: |
20480
|
|
4DBC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65690731794.0000000004DBC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DBC000
|
Size: |
20480
|
|
262F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65028745124.000000000262F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
262F000
|
Size: |
4096
|
|
2645000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64643053248.0000000002645000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2645000
|
Size: |
8192
|
|
2655000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64958008286.0000000002655000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2655000
|
Size: |
4096
|
|
60C000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000005.00000002.65684123087.000000000060C000.00000008.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
60C000
|
Size: |
40960
|
|
651000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000002.65684583359.0000000000651000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
651000
|
Size: |
888832
|
|
2E7F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65689115360.0000000002E7F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2E7F000
|
Size: |
4096
|
|
1D90AA46000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.65684197033.000001D90AA46000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1D90AA46000
|
Size: |
53248
|
|
2FD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65689261449.0000000002FD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FD0000
|
Size: |
4096
|
|
621000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000002.65684583359.0000000000621000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
621000
|
Size: |
24576
|
|
BDD2000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000002.65710916505.000000000BDD2000.00000002.00000001.01000000.0000000A.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BDD2000
|
Size: |
24576
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2E80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64458234761.0000000002E80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E80000
|
Size: |
4096
|
|
64E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.65684044322.000000000064E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
64E000
|
Size: |
8192
|
|
985000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64440416109.0000000000985000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
985000
|
Size: |
12288
|
|
A2B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64439600265.0000000000A2B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A2B000
|
Size: |
36864
|
|
296A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64438351076.000000000296A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
296A000
|
Size: |
8192
|
|
A0E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64437784792.0000000000A0E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A0E000
|
Size: |
200704
|
|
2648000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64972478692.0000000002648000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2648000
|
Size: |
20480
|
|
5832000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65615684858.0000000005832000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5832000
|
Size: |
36864
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
262F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64597468566.000000000262F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
262F000
|
Size: |
4096
|
|
57F2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65245149130.00000000057F2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
57F2000
|
Size: |
167936
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
9E7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64438959909.00000000009E7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9E7000
|
Size: |
8192
|
|
ABF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.65684744112.0000000000ABF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
ABF000
|
Size: |
4096
|
|
979000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64473494033.0000000000979000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
979000
|
Size: |
12288
|
|
2637000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64987526393.0000000002637000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2637000
|
Size: |
4096
|
|
35A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65690381153.00000000035A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35A0000
|
Size: |
258048
|
|
2637000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64669400229.0000000002637000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2637000
|
Size: |
4096
|
|
2614000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64590552705.0000000002614000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2614000
|
Size: |
110592
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2600000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65686988752.0000000002600000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2600000
|
Size: |
192512
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4DA1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64600526539.0000000004DA1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DA1000
|
Size: |
12288
|
|
C6FF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65711470379.000000000C6FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C6FF000
|
Size: |
4096
|
|
9CE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64440296466.00000000009CE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9CE000
|
Size: |
32768
|
|
584A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65177623859.000000000584A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
584A000
|
Size: |
4096
|
|
2972000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65687862327.0000000002972000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2972000
|
Size: |
114688
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2645000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64939498153.0000000002645000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2645000
|
Size: |
8192
|
|
98B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65685771122.000000000098B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
98B000
|
Size: |
266240
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1D90A8E0000
|
unclassified section
|
page readonly
|
|
|
|
Name: |
00000000.00000002.65682988163.000001D90A8E0000.00000002.10000000.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page readonly
|
Base address: |
1D90A8E0000
|
Size: |
4096
|
|
98C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64436185670.000000000098C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
98C000
|
Size: |
139264
|
|
7170000
|
stack
|
page readonly
|
|
|
|
Name: |
00000005.00000002.65691591234.0000000007170000.00000002.00000010.00040000.00000009.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page readonly
|
Base address: |
7170000
|
Size: |
10485760
|
|
262F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65035894043.000000000262F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
262F000
|
Size: |
4096
|
|
29D3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65687862327.00000000029D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29D3000
|
Size: |
110592
|
|
2637000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64597468566.0000000002637000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2637000
|
Size: |
4096
|
|
BF4F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65711092336.000000000BF4F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BF4F000
|
Size: |
4096
|
|
2645000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65055546953.0000000002645000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2645000
|
Size: |
36864
|
|
9EB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64437537327.00000000009EB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9EB000
|
Size: |
16384
|
|
262F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64605109588.000000000262F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
262F000
|
Size: |
4096
|
|
2613000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64498945759.0000000002613000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2613000
|
Size: |
98304
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
985000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64440088564.0000000000985000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
985000
|
Size: |
98304
|
|
2655000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64605109588.0000000002655000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2655000
|
Size: |
4096
|
|
5832000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65209176579.0000000005832000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5832000
|
Size: |
36864
|
|
57CF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65110295633.00000000057CF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
57CF000
|
Size: |
8192
|
|
262F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64972478692.000000000262F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
262F000
|
Size: |
4096
|
|
263F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64597468566.000000000263F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
263F000
|
Size: |
4096
|
|
2645000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64597671997.0000000002645000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2645000
|
Size: |
8192
|
|
2645000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64958008286.0000000002645000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2645000
|
Size: |
8192
|
|
A3E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64598782503.0000000000A3E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A3E000
|
Size: |
4096
|
|
2961000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64438568022.0000000002961000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2961000
|
Size: |
4096
|
|
98C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64438379521.000000000098C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
98C000
|
Size: |
221184
|
|
76A000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000000.64405417696.000000000076A000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
76A000
|
Size: |
110592
|
|
A370000
|
stack
|
page readonly
|
|
|
|
Name: |
00000005.00000002.65691591234.000000000A370000.00000002.00000010.00040000.00000009.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page readonly
|
Base address: |
A370000
|
Size: |
10485760
|
|
9C6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64437377034.00000000009C6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9C6000
|
Size: |
106496
|
|
2645000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64987526393.0000000002645000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2645000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
2655000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64572041339.0000000002655000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2655000
|
Size: |
4096
|
|
98C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64436949863.000000000098C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
98C000
|
Size: |
405504
|
|
9D9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64436897269.00000000009D9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D9000
|
Size: |
28672
|
|
263F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64598543559.000000000263F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
263F000
|
Size: |
4096
|
|
9EF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64437701749.00000000009EF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9EF000
|
Size: |
327680
|
|
2637000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64958008286.0000000002637000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2637000
|
Size: |
4096
|
|
296A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64438064340.000000000296A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
296A000
|
Size: |
8192
|
|
3044000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64598644289.0000000003044000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3044000
|
Size: |
40960
|
|
2A07000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64599377198.0000000002A07000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A07000
|
Size: |
143360
|
|
BDB1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000005.00000002.65710862091.000000000BDB1000.00000020.00000001.01000000.0000000A.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
BDB1000
|
Size: |
135168
|
|
1D90AA27000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.65683794349.000001D90AA27000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1D90AA27000
|
Size: |
8192
|
|
2A11000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65687862327.0000000002A11000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A11000
|
Size: |
40960
|
|
2655000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64627113533.0000000002655000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2655000
|
Size: |
4096
|
|
2648000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65002412186.0000000002648000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2648000
|
Size: |
20480
|
|
C120000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65326416486.000000000C120000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
C120000
|
Size: |
4096
|
|
2645000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65035894043.0000000002645000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2645000
|
Size: |
32768
|
|
2965000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64439535550.0000000002965000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2965000
|
Size: |
45056
|
|
3378000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64457777903.0000000003378000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3378000
|
Size: |
151552
|
|
401000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000009.00000000.65615221282.0000000000401000.00000020.00000001.01000000.0000000C.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
401000
|
Size: |
299008
|
|
5842000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65253430677.0000000005842000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5842000
|
Size: |
159744
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
5832000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65253430677.0000000005832000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5832000
|
Size: |
36864
|
|
1D90AA56000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.65684427699.000001D90AA56000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1D90AA56000
|
Size: |
45056
|
|
A34000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64439569555.0000000000A34000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A34000
|
Size: |
20480
|
|
986000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64438379521.0000000000986000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
986000
|
Size: |
12288
|
|
2964000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64437849369.0000000002964000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2964000
|
Size: |
49152
|
|
57CF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65103008057.00000000057CF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
57CF000
|
Size: |
4096
|
|
9E6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64435813284.00000000009E6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9E6000
|
Size: |
20480
|
|
2637000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64979948530.0000000002637000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2637000
|
Size: |
4096
|
|
5842000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65209176579.0000000005842000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5842000
|
Size: |
159744
|
|
A29000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64439762432.0000000000A29000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A29000
|
Size: |
8192
|
|
9970000
|
stack
|
page readonly
|
|
|
|
Name: |
00000005.00000002.65691591234.0000000009970000.00000002.00000010.00040000.00000009.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page readonly
|
Base address: |
9970000
|
Size: |
10485760
|
|
76A000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000002.65684583359.000000000076A000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
76A000
|
Size: |
110592
|
|
7C4000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000000.64405417696.00000000007C4000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7C4000
|
Size: |
8192
|
|
9D4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64436637125.00000000009D4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D4000
|
Size: |
49152
|
|
2648000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64612508941.0000000002648000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2648000
|
Size: |
8192
|
|
C09F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65711160555.000000000C09F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C09F000
|
Size: |
4096
|
|
9CB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64436837590.00000000009CB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9CB000
|
Size: |
20480
|
|
57D3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65177623859.00000000057D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
57D3000
|
Size: |
53248
|
|
9D6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64436866747.00000000009D6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D6000
|
Size: |
40960
|
|
9B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.65682820310.000000000009B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9B000
|
Size: |
20480
|
|
2637000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64634675342.0000000002637000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2637000
|
Size: |
4096
|
|
546000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.65683656536.0000000000546000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
546000
|
Size: |
8192
|
|
2645000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65002412186.0000000002645000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2645000
|
Size: |
8192
|
|
2640000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64557308414.0000000002640000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2640000
|
Size: |
4096
|
|
29C2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65687862327.00000000029C2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29C2000
|
Size: |
16384
|
|
A39000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64439477168.0000000000A39000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A39000
|
Size: |
4096
|
|
3410000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65690223710.0000000003410000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3410000
|
Size: |
4096
|
|
340E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65690183090.000000000340E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
340E000
|
Size: |
8192
|
|
A3E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64598136802.0000000000A3E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A3E000
|
Size: |
4096
|
|
2637000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64650350699.0000000002637000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2637000
|
Size: |
4096
|
|
5842000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65177623859.0000000005842000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5842000
|
Size: |
4096
|
|
2648000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64643053248.0000000002648000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2648000
|
Size: |
8192
|
|
A3E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64439477168.0000000000A3E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A3E000
|
Size: |
4096
|
|
C120000
|
remote allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65230771762.000000000C120000.00000004.00000400.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
remote allocation
|
Protect: |
page read and write
|
Base address: |
C120000
|
Size: |
4096
|
|
262F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64572041339.000000000262F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
262F000
|
Size: |
4096
|
|
23AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.65685208176.00000000023AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
23AE000
|
Size: |
8192
|
|
29C7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65687862327.00000000029C7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29C7000
|
Size: |
28672
|
|
97F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64437155860.000000000097F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
97F000
|
Size: |
4096
|
|
57E2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.65177623859.00000000057E2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
57E2000
|
Size: |
241664
|
|
A2C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64439762432.0000000000A2C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A2C000
|
Size: |
32768
|
|
1D90A940000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.65683233203.000001D90A940000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1D90A940000
|
Size: |
12288
|
|
2655000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64612508941.0000000002655000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2655000
|
Size: |
4096
|
|
7C7000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000002.65684583359.00000000007C7000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7C7000
|
Size: |
102400
|
|
348C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.65690279701.000000000348C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
348C000
|
Size: |
16384
|
|
9CD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.64439909820.00000000009CD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9CD000
|
Size: |
36864
|
|
72D000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000002.65684583359.000000000072D000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
72D000
|
Size: |
241664
|
|