4E00000
|
direct allocation
|
page read and write
|
 |
|
|
Name: |
00000006.00000003.2153204111.0000000004E00000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4E00000
|
Size: |
1224704
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected RisePro Stealer |
Stealing of Sensitive Information, Remote Access Functionality |
|
SQL strings found in memory and binary data |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
46C0000
|
direct allocation
|
page read and write
|
 |
|
|
Name: |
0000000C.00000003.2342969300.00000000046C0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
46C0000
|
Size: |
1224704
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected RisePro Stealer |
Stealing of Sensitive Information, Remote Access Functionality |
|
SQL strings found in memory and binary data |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
43E0000
|
direct allocation
|
page read and write
|
 |
|
|
Name: |
00000000.00000003.2128160270.00000000043E0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
43E0000
|
Size: |
1224704
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected RisePro Stealer |
Stealing of Sensitive Information, Remote Access Functionality |
|
SQL strings found in memory and binary data |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
461000
|
unkown
|
page execute and read and write
|
 |
|
|
Name: |
00000008.00000002.3375310931.0000000000461000.00000040.00000001.01000000.00000005.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
461000
|
Size: |
1224704
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected RisePro Stealer |
Stealing of Sensitive Information, Remote Access Functionality |
|
SQL strings found in memory and binary data |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
461000
|
unkown
|
page execute and read and write
|
 |
|
|
Name: |
0000000C.00000002.3375376710.0000000000461000.00000040.00000001.01000000.00000005.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
461000
|
Size: |
1224704
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected RisePro Stealer |
Stealing of Sensitive Information, Remote Access Functionality |
|
SQL strings found in memory and binary data |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
821000
|
unkown
|
page execute and read and write
|
 |
|
|
Name: |
00000006.00000002.3375371093.0000000000821000.00000040.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
821000
|
Size: |
1224704
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected RisePro Stealer |
Stealing of Sensitive Information, Remote Access Functionality |
|
SQL strings found in memory and binary data |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
4DC0000
|
direct allocation
|
page read and write
|
 |
|
|
Name: |
00000008.00000003.2263129853.0000000004DC0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4DC0000
|
Size: |
1224704
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected RisePro Stealer |
Stealing of Sensitive Information, Remote Access Functionality |
|
SQL strings found in memory and binary data |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
C21000
|
unkown
|
page execute and read and write
|
 |
|
|
Name: |
00000000.00000002.3375843712.0000000000C21000.00000040.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
C21000
|
Size: |
1224704
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected RisePro Stealer |
Stealing of Sensitive Information, Remote Access Functionality |
|
SQL strings found in memory and binary data |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
821000
|
unkown
|
page execute and read and write
|
 |
|
|
Name: |
00000007.00000002.3375363971.0000000000821000.00000040.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
821000
|
Size: |
1224704
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected RisePro Stealer |
Stealing of Sensitive Information, Remote Access Functionality |
|
SQL strings found in memory and binary data |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
4BF0000
|
direct allocation
|
page read and write
|
 |
|
|
Name: |
00000007.00000003.2154011051.0000000004BF0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4BF0000
|
Size: |
1224704
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected RisePro Stealer |
Stealing of Sensitive Information, Remote Access Functionality |
|
SQL strings found in memory and binary data |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
BFF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3375643938.0000000000BFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BFF000
|
Size: |
4096
|
|
46E0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000003.2343345503.00000000046E0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
46E0000
|
Size: |
4096
|
|
444E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3378908917.000000000444E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
444E000
|
Size: |
8192
|
|
821000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
00000007.00000000.2148179513.0000000000821000.00000080.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
821000
|
Size: |
577536
|
|
593000
|
unkown
|
page write copy
|
|
|
|
Name: |
0000000C.00000000.2337662415.0000000000593000.00000008.00000001.01000000.00000005.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
593000
|
Size: |
12288
|
|
378F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3377876262.000000000378F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
378F000
|
Size: |
4096
|
|
4E40000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000003.2153662576.0000000004E40000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4E40000
|
Size: |
4096
|
|
71E000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3375547902.000000000071E000.00000040.00000001.01000000.00000005.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
71E000
|
Size: |
561152
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
ADE000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.3375661862.0000000000ADE000.00000040.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
ADE000
|
Size: |
561152
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
46E0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000003.2343236718.00000000046E0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
46E0000
|
Size: |
4096
|
|
1400000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3376818625.0000000001400000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1400000
|
Size: |
4096
|
|
14FE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2281764994.00000000014FE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14FE000
|
Size: |
4096
|
|
42FE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3379254713.00000000042FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
42FE000
|
Size: |
8192
|
|
410000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3375370836.0000000000410000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
410000
|
Size: |
4096
|
|
CF8000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3376567599.0000000000CF8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CF8000
|
Size: |
159744
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
58E000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000002.3375376710.000000000058E000.00000040.00000001.01000000.00000005.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
58E000
|
Size: |
20480
|
|
4C5E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3379338171.0000000004C5E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4C5E000
|
Size: |
8192
|
|
13D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3376651060.00000000013D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13D0000
|
Size: |
4096
|
|
30CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3377131714.00000000030CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
30CE000
|
Size: |
8192
|
|
4E00000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000003.2263355848.0000000004E00000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4E00000
|
Size: |
8192
|
|
4A3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3379650105.0000000004A3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4A3E000
|
Size: |
8192
|
|
368E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3377839660.000000000368E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
368E000
|
Size: |
8192
|
|
418F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3378526772.000000000418F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
418F000
|
Size: |
4096
|
|
4C30000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000003.2154247384.0000000004C30000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4C30000
|
Size: |
4096
|
|
367E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3378026341.000000000367E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
367E000
|
Size: |
8192
|
|
7FC000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
0000000C.00000002.3376116862.00000000007FC000.00000080.00000001.01000000.00000005.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
7FC000
|
Size: |
1441792
|
|
4E00000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000003.2263400652.0000000004E00000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4E00000
|
Size: |
4096
|
|
297E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3377269203.000000000297E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
297E000
|
Size: |
8192
|
|
3F8F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3378112141.0000000003F8F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3F8F000
|
Size: |
4096
|
|
3DBF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3378651821.0000000003DBF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3DBF000
|
Size: |
4096
|
|
33FE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3377820932.00000000033FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
33FE000
|
Size: |
8192
|
|
7AE000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000002.3375602728.00000000007AE000.00000040.00000001.01000000.00000005.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
7AE000
|
Size: |
8192
|
|
4A4F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3379471708.0000000004A4F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4A4F000
|
Size: |
4096
|
|
467E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3379272345.000000000467E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
467E000
|
Size: |
8192
|
|
D53000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.2122353802.0000000000D53000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
D53000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
3A4E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3378069205.0000000003A4E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3A4E000
|
Size: |
8192
|
|
51F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2143170518.000000000051F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
51F000
|
Size: |
184320
|
|
28DE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3376869741.00000000028DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
28DE000
|
Size: |
8192
|
|
467F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3379596944.000000000467F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
467F000
|
Size: |
4096
|
|
4ADF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3379144824.0000000004ADF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4ADF000
|
Size: |
4096
|
|
4DE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3375441152.00000000004DE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DE000
|
Size: |
184320
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
D34000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3376567599.0000000000D34000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D34000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
B6E000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3375585687.0000000000B6E000.00000040.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
B6E000
|
Size: |
8192
|
|
44CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3378480176.00000000044CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
44CE000
|
Size: |
8192
|
|
314F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3377363338.000000000314F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
314F000
|
Size: |
4096
|
|
7ED000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3375547902.00000000007ED000.00000040.00000001.01000000.00000005.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
7ED000
|
Size: |
32768
|
|
4F2E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3380089004.0000000004F2E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4F2E000
|
Size: |
8192
|
|
3BFF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3378951513.0000000003BFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3BFF000
|
Size: |
4096
|
|
516000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2143235948.0000000000516000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
516000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
953000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000006.00000000.2147456797.0000000000953000.00000008.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
953000
|
Size: |
12288
|
|
821000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
00000006.00000000.2147389817.0000000000821000.00000080.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
821000
|
Size: |
577536
|
|
3FFF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3378531034.0000000003FFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3FFF000
|
Size: |
4096
|
|
4F2D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000006.00000003.2153204111.0000000004F2D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4F2D000
|
Size: |
16384
|
|
48FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3379535364.00000000048FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
48FE000
|
Size: |
8192
|
|
36CF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3377554476.00000000036CF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
36CF000
|
Size: |
4096
|
|
4E00000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000003.2263566410.0000000004E00000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4E00000
|
Size: |
4096
|
|
413E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3379598867.000000000413E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
413E000
|
Size: |
8192
|
|
373F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3377917367.000000000373F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
373F000
|
Size: |
4096
|
|
4B3F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3379717414.0000000004B3F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4B3F000
|
Size: |
4096
|
|
344F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3377359255.000000000344F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
344F000
|
Size: |
4096
|
|
4DBF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3379943882.0000000004DBF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4DBF000
|
Size: |
4096
|
|
3A8F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3377802924.0000000003A8F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3A8F000
|
Size: |
4096
|
|
3BCF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3377878273.0000000003BCF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3BCF000
|
Size: |
4096
|
|
470F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3378714838.000000000470F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
470F000
|
Size: |
4096
|
|
5110000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3380025909.0000000005110000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5110000
|
Size: |
4096
|
|
9C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3375212761.000000000009C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9C000
|
Size: |
16384
|
|
36FF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3378299132.00000000036FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
36FF000
|
Size: |
4096
|
|
953000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000006.00000002.3375631164.0000000000953000.00000008.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
953000
|
Size: |
12288
|
|
BAD000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.3375661862.0000000000BAD000.00000040.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
BAD000
|
Size: |
32768
|
|
337F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3377680893.000000000337F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
337F000
|
Size: |
4096
|
|
460000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000C.00000000.2337515680.0000000000460000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
460000
|
Size: |
4096
|
|
3A0F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3378024101.0000000003A0F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3A0F000
|
Size: |
4096
|
|
4C30000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000003.2154313810.0000000004C30000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4C30000
|
Size: |
4096
|
|
51E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3375441152.000000000051E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
51E000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
4E40000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000003.2153433032.0000000004E40000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4E40000
|
Size: |
8192
|
|
46E0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000003.2343390091.00000000046E0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
46E0000
|
Size: |
12288
|
|
10FD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3376463341.00000000010FD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
10FD000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
38BF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3378192083.00000000038BF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
38BF000
|
Size: |
4096
|
|
3A3E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3378348885.0000000003A3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3A3E000
|
Size: |
8192
|
|
489E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3378956896.000000000489E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
489E000
|
Size: |
8192
|
|
3EBF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3378439468.0000000003EBF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3EBF000
|
Size: |
4096
|
|
4420000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000003.2128487075.0000000004420000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4420000
|
Size: |
4096
|
|
46C6000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3379657987.00000000046C6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
46C6000
|
Size: |
2002944
|
|
387E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3378442684.000000000387E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
387E000
|
Size: |
8192
|
|
11C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3376694949.00000000011C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11C0000
|
Size: |
4096
|
|
95C000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3376337589.000000000095C000.00000040.00000001.01000000.00000005.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
95C000
|
Size: |
4096
|
|
42BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3378905948.00000000042BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
42BE000
|
Size: |
8192
|
|
327E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3377644468.000000000327E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
327E000
|
Size: |
8192
|
|
46E0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000003.2343258014.00000000046E0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
46E0000
|
Size: |
4096
|
|
27FF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3377129638.00000000027FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
27FF000
|
Size: |
4096
|
|
4DD0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000003.2263619339.0000000004DD0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4DD0000
|
Size: |
4096
|
|
D32000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3376567599.0000000000D32000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D32000
|
Size: |
4096
|
|
14E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3377004143.00000000014E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14E0000
|
Size: |
4096
|
|
4E40000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000003.2153564054.0000000004E40000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4E40000
|
Size: |
4096
|
|
2FCE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3377375097.0000000002FCE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2FCE000
|
Size: |
8192
|
|
29FF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3377003062.00000000029FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
29FF000
|
Size: |
4096
|
|
4C30000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000003.2154358051.0000000004C30000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4C30000
|
Size: |
4096
|
|
353E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3377921961.000000000353E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
353E000
|
Size: |
8192
|
|
B6E000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.3375661862.0000000000B6E000.00000040.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
B6E000
|
Size: |
8192
|
|
4420000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000003.2128397239.0000000004420000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4420000
|
Size: |
4096
|
|
C07000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3375662263.0000000000C07000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C07000
|
Size: |
12288
|
|
3DBE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3378394437.0000000003DBE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3DBE000
|
Size: |
8192
|
|
94E000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.3375371093.000000000094E000.00000040.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
94E000
|
Size: |
20480
|
|
38CF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3377952200.00000000038CF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
38CF000
|
Size: |
4096
|
|
FBC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3376642786.0000000000FBC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FBC000
|
Size: |
16384
|
|
3B4F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3378112950.0000000003B4F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3B4F000
|
Size: |
4096
|
|
AFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3375616988.0000000000AFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
AFE000
|
Size: |
8192
|
|
12FD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3376611719.00000000012FD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
12FD000
|
Size: |
12288
|
|
4E00000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000003.2263463535.0000000004E00000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4E00000
|
Size: |
4096
|
|
4420000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000003.2128470836.0000000004420000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4420000
|
Size: |
4096
|
|
4850000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3378908025.0000000004850000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4850000
|
Size: |
4096
|
|
47ED000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2342969300.00000000047ED000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
47ED000
|
Size: |
16384
|
|
BAD000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3375585687.0000000000BAD000.00000040.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
BAD000
|
Size: |
32768
|
|
13CC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3376838901.00000000013CC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13CC000
|
Size: |
77824
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
310E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3377468692.000000000310E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
310E000
|
Size: |
8192
|
|
33BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3377712519.00000000033BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
33BE000
|
Size: |
8192
|
|
4E40000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000003.2153546898.0000000004E40000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4E40000
|
Size: |
4096
|
|
49EE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3380136740.00000000049EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
49EE000
|
Size: |
8192
|
|
957000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3375585687.0000000000957000.00000040.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
957000
|
Size: |
1593344
|
|
3130000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3377516551.0000000003130000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3130000
|
Size: |
16384
|
|
2BBF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3377431584.0000000002BBF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2BBF000
|
Size: |
4096
|
|
4E40000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000003.2153644651.0000000004E40000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4E40000
|
Size: |
4096
|
|
3B7E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3378437801.0000000003B7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3B7E000
|
Size: |
8192
|
|
308F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3377084315.000000000308F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
308F000
|
Size: |
4096
|
|
597000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000002.3375602728.0000000000597000.00000040.00000001.01000000.00000005.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
597000
|
Size: |
1593344
|
|
39BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3378623539.00000000039BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
39BE000
|
Size: |
8192
|
|
7B1000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000002.3375602728.00000000007B1000.00000040.00000001.01000000.00000005.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
7B1000
|
Size: |
69632
|
|
F7C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3376418287.0000000000F7C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
F7C000
|
Size: |
16384
|
|
2B3E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3377083413.0000000002B3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2B3E000
|
Size: |
8192
|
|
398E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3377763546.000000000398E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
398E000
|
Size: |
8192
|
|
13B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3376838901.00000000013B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13B0000
|
Size: |
36864
|
|
13E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3376838901.00000000013E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13E0000
|
Size: |
32768
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
50C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2140274900.000000000050C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
50C000
|
Size: |
262144
|
|
413F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3378708497.000000000413F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
413F000
|
Size: |
4096
|
|
4E00000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000003.2263424729.0000000004E00000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4E00000
|
Size: |
4096
|
|
38BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3378042532.00000000038BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
38BE000
|
Size: |
8192
|
|
4420000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000003.2128457705.0000000004420000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4420000
|
Size: |
4096
|
|
43BF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3378959208.00000000043BF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
43BF000
|
Size: |
4096
|
|
13F3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3376838901.00000000013F3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13F3000
|
Size: |
12288
|
|
39FF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3378302739.00000000039FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
39FF000
|
Size: |
4096
|
|
3C7F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3378484084.0000000003C7F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3C7F000
|
Size: |
4096
|
|
1415000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3376890128.0000000001415000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1415000
|
Size: |
12288
|
|
494E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3379405096.000000000494E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
494E000
|
Size: |
8192
|
|
4C30000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000003.2154196434.0000000004C30000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4C30000
|
Size: |
8192
|
|
461000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
00000008.00000000.2257281057.0000000000461000.00000080.00000001.01000000.00000005.sdmp
|
TargetID: |
8
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
461000
|
Size: |
577536
|
|
C21000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
00000000.00000000.2122289537.0000000000C21000.00000080.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
C21000
|
Size: |
577536
|
|
37BE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3378139370.00000000037BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
37BE000
|
Size: |
8192
|
|
14F4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2281764994.00000000014F4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14F4000
|
Size: |
4096
|
|
4D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3375441152.00000000004D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D0000
|
Size: |
32768
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
4C30000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000003.2154229300.0000000004C30000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4C30000
|
Size: |
4096
|
|
3D7E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3379212872.0000000003D7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3D7E000
|
Size: |
8192
|
|
593000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000008.00000000.2257359177.0000000000593000.00000008.00000001.01000000.00000005.sdmp
|
TargetID: |
8
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
593000
|
Size: |
12288
|
|
373E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3378345376.000000000373E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
373E000
|
Size: |
8192
|
|
820000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.2148160627.0000000000820000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
820000
|
Size: |
4096
|
|
503D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3380291335.000000000503D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
503D000
|
Size: |
12288
|
|
13BA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3376838901.00000000013BA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13BA000
|
Size: |
69632
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
49DE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3379089685.00000000049DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
49DE000
|
Size: |
8192
|
|
363E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3377875011.000000000363E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
363E000
|
Size: |
8192
|
|
347F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3378114225.000000000347F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
347F000
|
Size: |
4096
|
|
4E40000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000003.2153599134.0000000004E40000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4E40000
|
Size: |
4096
|
|
3B3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3378225262.0000000003B3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3B3E000
|
Size: |
8192
|
|
460E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3378591031.000000000460E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
460E000
|
Size: |
8192
|
|
468F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3379091679.000000000468F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
468F000
|
Size: |
4096
|
|
4A8E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3379542123.0000000004A8E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4A8E000
|
Size: |
8192
|
|
420F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3378270079.000000000420F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
420F000
|
Size: |
4096
|
|
153F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000003.2165077681.000000000153F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
153F000
|
Size: |
8192
|
|
4E00000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000003.2263594253.0000000004E00000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4E00000
|
Size: |
12288
|
|
D1D000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
00000006.00000002.3376587417.0000000000D1D000.00000080.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
D1D000
|
Size: |
8192
|
|
3EFF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3378781673.0000000003EFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3EFF000
|
Size: |
4096
|
|
4C1F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3379276929.0000000004C1F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4C1F000
|
Size: |
4096
|
|
434F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3378373486.000000000434F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
434F000
|
Size: |
4096
|
|
597000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3375547902.0000000000597000.00000040.00000001.01000000.00000005.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
597000
|
Size: |
1593344
|
|
4E00000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000003.2263379567.0000000004E00000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4E00000
|
Size: |
4096
|
|
377F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3378094154.000000000377F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
377F000
|
Size: |
4096
|
|
404F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3378435499.000000000404F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
404F000
|
Size: |
4096
|
|
283E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3377177060.000000000283E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
283E000
|
Size: |
8192
|
|
4C30000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000003.2154297288.0000000004C30000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4C30000
|
Size: |
4096
|
|
4420000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000003.2128353344.0000000004420000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4420000
|
Size: |
4096
|
|
390E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3377986873.000000000390E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
390E000
|
Size: |
8192
|
|
CC5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3376479051.0000000000CC5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CC5000
|
Size: |
12288
|
|
323F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3377600085.000000000323F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
323F000
|
Size: |
4096
|
|
4CBE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3379892064.0000000004CBE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4CBE000
|
Size: |
8192
|
|
4C30000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000003.2154264828.0000000004C30000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4C30000
|
Size: |
4096
|
|
953000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000007.00000000.2148243689.0000000000953000.00000008.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
953000
|
Size: |
12288
|
|
4E00000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000003.2263537934.0000000004E00000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4E00000
|
Size: |
4096
|
|
3C8F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3378185035.0000000003C8F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3C8F000
|
Size: |
4096
|
|
44FF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3379094688.00000000044FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
44FF000
|
Size: |
4096
|
|
34BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3378153025.00000000034BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
34BE000
|
Size: |
8192
|
|
FBC000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
00000000.00000002.3376742562.0000000000FBC000.00000080.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
FBC000
|
Size: |
1441792
|
|
387F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3377999769.000000000387F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
387F000
|
Size: |
4096
|
|
B71000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3375585687.0000000000B71000.00000040.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
B71000
|
Size: |
69632
|
|
4420000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000003.2128380961.0000000004420000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4420000
|
Size: |
4096
|
|
4420000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000003.2128366607.0000000004420000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4420000
|
Size: |
4096
|
|
460000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3375202386.0000000000460000.00000004.00000001.01000000.00000005.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
460000
|
Size: |
4096
|
|
437F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3379786669.000000000437F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
437F000
|
Size: |
4096
|
|
4C30000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000003.2154214943.0000000004C30000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4C30000
|
Size: |
4096
|
|
303E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3377487997.000000000303E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
303E000
|
Size: |
8192
|
|
33CF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3377614085.00000000033CF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
33CF000
|
Size: |
4096
|
|
1460000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3376696200.0000000001460000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1460000
|
Size: |
16384
|
|
394F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3377715533.000000000394F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
394F000
|
Size: |
4096
|
|
FB5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3376456841.0000000000FB5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FB5000
|
Size: |
12288
|
|
C20000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.2122272082.0000000000C20000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
C20000
|
Size: |
4096
|
|
4E13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3380000731.0000000004E13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4E13000
|
Size: |
2002944
|
|
370E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3377596362.000000000370E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
370E000
|
Size: |
8192
|
|
C10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3375744136.0000000000C10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C10000
|
Size: |
4096
|
|
26FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3377081982.00000000026FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
26FE000
|
Size: |
8192
|
|
2ABE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3377370710.0000000002ABE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2ABE000
|
Size: |
8192
|
|
49F0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3380178749.00000000049F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
49F0000
|
Size: |
4096
|
|
D57000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3376159397.0000000000D57000.00000040.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
D57000
|
Size: |
1593344
|
|
4420000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000003.2128335364.0000000004420000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4420000
|
Size: |
8192
|
|
7FB000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3375547902.00000000007FB000.00000040.00000001.01000000.00000005.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
7FB000
|
Size: |
4096
|
|
41CD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3378585448.00000000041CD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
41CD000
|
Size: |
12288
|
|
3DFE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3378713474.0000000003DFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3DFE000
|
Size: |
8192
|
|
354E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3377753871.000000000354E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
354E000
|
Size: |
8192
|
|
71E000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000002.3375602728.000000000071E000.00000040.00000001.01000000.00000005.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
71E000
|
Size: |
561152
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
D1C000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.3376516857.0000000000D1C000.00000040.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
D1C000
|
Size: |
4096
|
|
28F7000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3376924016.00000000028F7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
28F7000
|
Size: |
12288
|
|
9F0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3376405014.00000000009F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9F0000
|
Size: |
4096
|
|
F6E000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3376159397.0000000000F6E000.00000040.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
F6E000
|
Size: |
8192
|
|
19C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3375300179.000000000019C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
19C000
|
Size: |
16384
|
|
BBB000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
00000007.00000000.2148261335.0000000000BBB000.00000080.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
BBB000
|
Size: |
1458176
|
|
3137000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3377516551.0000000003137000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3137000
|
Size: |
12288
|
|
3E8E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3378069850.0000000003E8E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3E8E000
|
Size: |
8192
|
|
30FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3377879471.00000000030FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
30FE000
|
Size: |
8192
|
|
363F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3377981270.000000000363F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
363F000
|
Size: |
4096
|
|
454F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3378971337.000000000454F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
454F000
|
Size: |
4096
|
|
7ED000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000002.3375602728.00000000007ED000.00000040.00000001.01000000.00000005.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
7ED000
|
Size: |
32768
|
|
C00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3375662263.0000000000C00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C00000
|
Size: |
16384
|
|
BBC000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
00000007.00000002.3376129085.0000000000BBC000.00000080.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
BBC000
|
Size: |
1441792
|
|
340E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3377662155.000000000340E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
340E000
|
Size: |
8192
|
|
513E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3380314901.000000000513E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
513E000
|
Size: |
8192
|
|
FB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3376456841.0000000000FB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FB0000
|
Size: |
16384
|
|
490F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3379338579.000000000490F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
490F000
|
Size: |
4096
|
|
474E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3378770926.000000000474E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
474E000
|
Size: |
8192
|
|
D2A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3376567599.0000000000D2A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D2A000
|
Size: |
4096
|
|
34FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3377793252.00000000034FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
34FE000
|
Size: |
8192
|
|
31FF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3377947152.00000000031FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
31FF000
|
Size: |
4096
|
|
7FC000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
00000008.00000002.3376119794.00000000007FC000.00000080.00000001.01000000.00000005.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
7FC000
|
Size: |
1441792
|
|
2F7F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3377751381.0000000002F7F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2F7F000
|
Size: |
4096
|
|
47CF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3379211016.00000000047CF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
47CF000
|
Size: |
4096
|
|
380F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3377645557.000000000380F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
380F000
|
Size: |
4096
|
|
7FB000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000002.3375602728.00000000007FB000.00000040.00000001.01000000.00000005.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
7FB000
|
Size: |
4096
|
|
3AFF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3378180288.0000000003AFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3AFF000
|
Size: |
4096
|
|
300F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3377268150.000000000300F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
300F000
|
Size: |
4096
|
|
14BA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3376796312.00000000014BA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14BA000
|
Size: |
8192
|
|
458E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3379039438.000000000458E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
458E000
|
Size: |
8192
|
|
4E10000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000003.2153695625.0000000004E10000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4E10000
|
Size: |
4096
|
|
3CCE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3378226024.0000000003CCE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3CCE000
|
Size: |
8192
|
|
2F8E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3377049439.0000000002F8E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2F8E000
|
Size: |
8192
|
|
3CBE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3378529804.0000000003CBE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3CBE000
|
Size: |
8192
|
|
2D7F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3377224418.0000000002D7F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2D7F000
|
Size: |
4096
|
|
4E40000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000003.2153493547.0000000004E40000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4E40000
|
Size: |
4096
|
|
FBB000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
00000000.00000000.2122370046.0000000000FBB000.00000080.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
FBB000
|
Size: |
1458176
|
|
3ABE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3378780986.0000000003ABE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3ABE000
|
Size: |
8192
|
|
35FF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3377840966.00000000035FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
35FF000
|
Size: |
4096
|
|
337E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3378072273.000000000337E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
337E000
|
Size: |
8192
|
|
47BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3379401533.00000000047BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
47BE000
|
Size: |
8192
|
|
28E0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000003.2343413260.00000000028E0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
28E0000
|
Size: |
4096
|
|
FBB000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3376159397.0000000000FBB000.00000040.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
FBB000
|
Size: |
4096
|
|
3FCE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3378142046.0000000003FCE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3FCE000
|
Size: |
8192
|
|
403E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3378592748.000000000403E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
403E000
|
Size: |
8192
|
|
397F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3378522253.000000000397F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
397F000
|
Size: |
4096
|
|
3C7E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3378300996.0000000003C7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3C7E000
|
Size: |
8192
|
|
820000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3375329300.0000000000820000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
820000
|
Size: |
4096
|
|
30BF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3377838542.00000000030BF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
30BF000
|
Size: |
4096
|
|
35CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3377515283.00000000035CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
35CE000
|
Size: |
8192
|
|
35FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3378252705.00000000035FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
35FE000
|
Size: |
8192
|
|
2CFF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3377547037.0000000002CFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2CFF000
|
Size: |
4096
|
|
37CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3377915752.00000000037CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
37CE000
|
Size: |
8192
|
|
F71000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3376159397.0000000000F71000.00000040.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
F71000
|
Size: |
69632
|
|
377E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3377954729.000000000377E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
377E000
|
Size: |
8192
|
|
41BE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3379117958.00000000041BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
41BE000
|
Size: |
8192
|
|
14FC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2281764994.00000000014FC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14FC000
|
Size: |
4096
|
|
2EBF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3377325837.0000000002EBF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2EBF000
|
Size: |
4096
|
|
14BE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3376796312.00000000014BE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14BE000
|
Size: |
208896
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
11D5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3376743466.00000000011D5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11D5000
|
Size: |
12288
|
|
43FD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3379852535.00000000043FD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
43FD000
|
Size: |
2002944
|
|
427F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3378840540.000000000427F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
427F000
|
Size: |
4096
|
|
94E000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3375363971.000000000094E000.00000040.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
94E000
|
Size: |
20480
|
|
34BF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3377751470.00000000034BF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
34BF000
|
Size: |
4096
|
|
3B3F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3378412326.0000000003B3F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3B3F000
|
Size: |
4096
|
|
400000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3375344257.0000000000400000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
400000
|
Size: |
4096
|
|
1467000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3376696200.0000000001467000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1467000
|
Size: |
12288
|
|
1110000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3376494486.0000000001110000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1110000
|
Size: |
4096
|
|
4420000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000003.2128502402.0000000004420000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4420000
|
Size: |
12288
|
|
450D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2128160270.000000000450D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
450D000
|
Size: |
16384
|
|
957000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.3375661862.0000000000957000.00000040.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
957000
|
Size: |
1593344
|
|
408E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3378479789.000000000408E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
408E000
|
Size: |
8192
|
|
11D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3376743466.00000000011D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11D0000
|
Size: |
16384
|
|
11B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3376611806.00000000011B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11B0000
|
Size: |
16384
|
|
4E00000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000003.2263518059.0000000004E00000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4E00000
|
Size: |
4096
|
|
457E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3379538536.000000000457E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
457E000
|
Size: |
8192
|
|
46E0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000003.2343215713.00000000046E0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
46E0000
|
Size: |
4096
|
|
D1D000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
00000007.00000002.3376372410.0000000000D1D000.00000080.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
D1D000
|
Size: |
8192
|
|
4E40000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000003.2153454306.0000000004E40000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4E40000
|
Size: |
4096
|
|
4C01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3379652791.0000000004C01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4C01000
|
Size: |
2002944
|
|
3ACE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3377843056.0000000003ACE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3ACE000
|
Size: |
8192
|
|
11B7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3376611806.00000000011B7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11B7000
|
Size: |
12288
|
|
45D000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3375321803.000000000045D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
45D000
|
Size: |
12288
|
|
427E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3379730707.000000000427E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
427E000
|
Size: |
8192
|
|
318E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3377426072.000000000318E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
318E000
|
Size: |
8192
|
|
384E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3377683527.000000000384E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
384E000
|
Size: |
8192
|
|
2D3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3377599682.0000000002D3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2D3E000
|
Size: |
8192
|
|
4C30000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000003.2154343272.0000000004C30000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4C30000
|
Size: |
4096
|
|
DAC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3376421591.0000000000DAC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
DAC000
|
Size: |
16384
|
|
14B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3376796312.00000000014B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14B0000
|
Size: |
32768
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
43FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3379021538.00000000043FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
43FE000
|
Size: |
8192
|
|
424E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3378305373.000000000424E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
424E000
|
Size: |
8192
|
|
153F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3377080253.000000000153F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
153F000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
2C3F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3377131723.0000000002C3F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2C3F000
|
Size: |
4096
|
|
13EB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2165831999.00000000013EB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13EB000
|
Size: |
4096
|
|
1410000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3376890128.0000000001410000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1410000
|
Size: |
16384
|
|
480E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3379272976.000000000480E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
480E000
|
Size: |
8192
|
|
463F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3379208765.000000000463F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
463F000
|
Size: |
4096
|
|
4C30000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000003.2154280387.0000000004C30000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4C30000
|
Size: |
4096
|
|
7FB000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
00000008.00000000.2257395219.00000000007FB000.00000080.00000001.01000000.00000005.sdmp
|
TargetID: |
8
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
7FB000
|
Size: |
1458176
|
|
440F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3378847434.000000000440F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
440F000
|
Size: |
4096
|
|
58E000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3375310931.000000000058E000.00000040.00000001.01000000.00000005.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
58E000
|
Size: |
20480
|
|
4C00000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000003.2154392991.0000000004C00000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4C00000
|
Size: |
4096
|
|
320E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3377228921.000000000320E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
320E000
|
Size: |
8192
|
|
CA0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3376445248.0000000000CA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CA0000
|
Size: |
4096
|
|
2FFF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3377437163.0000000002FFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2FFF000
|
Size: |
4096
|
|
2DBE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3377280955.0000000002DBE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2DBE000
|
Size: |
8192
|
|
40FF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3379561751.00000000040FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
40FF000
|
Size: |
4096
|
|
2C7E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3377178256.0000000002C7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2C7E000
|
Size: |
8192
|
|
CF0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3376567599.0000000000CF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CF0000
|
Size: |
24576
|
|
438D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3378411886.000000000438D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
438D000
|
Size: |
12288
|
|
510E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3379975263.000000000510E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
510E000
|
Size: |
8192
|
|
407E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3378991410.000000000407E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
407E000
|
Size: |
8192
|
|
111C000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3377002468.000000000111C000.00000040.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
111C000
|
Size: |
4096
|
|
4E00000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000003.2263443071.0000000004E00000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4E00000
|
Size: |
4096
|
|
499F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3379020280.000000000499F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
499F000
|
Size: |
4096
|
|
1180000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3376551892.0000000001180000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1180000
|
Size: |
4096
|
|
460000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3375348356.0000000000460000.00000004.00000001.01000000.00000005.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
460000
|
Size: |
4096
|
|
4C30000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000003.2154375012.0000000004C30000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4C30000
|
Size: |
12288
|
|
2EFE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3377373963.0000000002EFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2EFE000
|
Size: |
8192
|
|
820000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000000.2147373147.0000000000820000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
820000
|
Size: |
4096
|
|
289E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3376836241.000000000289E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
289E000
|
Size: |
8192
|
|
2E3F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3377665074.0000000002E3F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2E3F000
|
Size: |
4096
|
|
31CF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3377181544.00000000031CF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
31CF000
|
Size: |
4096
|
|
593000
|
unkown
|
page write copy
|
|
|
|
Name: |
0000000C.00000002.3375571059.0000000000593000.00000008.00000001.01000000.00000005.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
593000
|
Size: |
12288
|
|
3EBE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3379341132.0000000003EBE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3EBE000
|
Size: |
8192
|
|
820000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3375327883.0000000000820000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
820000
|
Size: |
4096
|
|
42CF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3378706590.00000000042CF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
42CF000
|
Size: |
4096
|
|
14FC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3376796312.00000000014FC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14FC000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
423F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3379654369.000000000423F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
423F000
|
Size: |
4096
|
|
43F0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000003.2128518182.00000000043F0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
43F0000
|
Size: |
4096
|
|
111D000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
00000000.00000002.3377050312.000000000111D000.00000080.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
111D000
|
Size: |
8192
|
|
461000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
0000000C.00000000.2337583682.0000000000461000.00000080.00000001.01000000.00000005.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
461000
|
Size: |
577536
|
|
3DCF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3378259604.0000000003DCF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3DCF000
|
Size: |
4096
|
|
12FD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3376693028.00000000012FD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
12FD000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
13F3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2165831999.00000000013F3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13F3000
|
Size: |
8192
|
|
2BFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3377485604.0000000002BFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2BFE000
|
Size: |
8192
|
|
3FFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3379476834.0000000003FFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3FFE000
|
Size: |
8192
|
|
3AFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3378890390.0000000003AFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3AFE000
|
Size: |
8192
|
|
95D000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
0000000C.00000002.3376338358.000000000095D000.00000080.00000001.01000000.00000005.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
95D000
|
Size: |
8192
|
|
4B7E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3379782954.0000000004B7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4B7E000
|
Size: |
8192
|
|
2E7E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3377712924.0000000002E7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2E7E000
|
Size: |
8192
|
|
32BE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3377727843.00000000032BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
32BE000
|
Size: |
8192
|
|
4E40000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000003.2153615935.0000000004E40000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4E40000
|
Size: |
4096
|
|
4F30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3380130945.0000000004F30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4F30000
|
Size: |
4096
|
|
7FB000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
0000000C.00000000.2337685684.00000000007FB000.00000080.00000001.01000000.00000005.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
7FB000
|
Size: |
1458176
|
|
48ED000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3380086640.00000000048ED000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
48ED000
|
Size: |
12288
|
|
313F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3377561840.000000000313F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
313F000
|
Size: |
4096
|
|
4B1E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3379212924.0000000004B1E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4B1E000
|
Size: |
8192
|
|
3C3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3379027191.0000000003C3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3C3E000
|
Size: |
8192
|
|
403F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3378930252.000000000403F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
403F000
|
Size: |
4096
|
|
EDE000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3376159397.0000000000EDE000.00000040.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
EDE000
|
Size: |
561152
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
443E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3379400373.000000000443E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
443E000
|
Size: |
8192
|
|
4D1D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2154011051.0000000004D1D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4D1D000
|
Size: |
16384
|
|
3E7F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3379279183.0000000003E7F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3E7F000
|
Size: |
4096
|
|
358F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3377465029.000000000358F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
358F000
|
Size: |
4096
|
|
4E00000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000003.2263500751.0000000004E00000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4E00000
|
Size: |
4096
|
|
7B1000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3375547902.00000000007B1000.00000040.00000001.01000000.00000005.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
7B1000
|
Size: |
69632
|
|
B71000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.3375661862.0000000000B71000.00000040.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
B71000
|
Size: |
69632
|
|
293F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3377226504.000000000293F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
293F000
|
Size: |
4096
|
|
4EED000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2263129853.0000000004EED000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4EED000
|
Size: |
16384
|
|
3FBF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3379416594.0000000003FBF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3FBF000
|
Size: |
4096
|
|
D53000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000002.3376118583.0000000000D53000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
D53000
|
Size: |
12288
|
|
3D0F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3377961388.0000000003D0F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3D0F000
|
Size: |
4096
|
|
1537000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000003.2165077681.0000000001537000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1537000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
4420000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000003.2128410989.0000000004420000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4420000
|
Size: |
4096
|
|
7DE000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3375547902.00000000007DE000.00000040.00000001.01000000.00000005.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
7DE000
|
Size: |
57344
|
|
D20000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3376567599.0000000000D20000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D20000
|
Size: |
32768
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
40CF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3378183480.00000000040CF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
40CF000
|
Size: |
4096
|
|
14FA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3377080253.00000000014FA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14FA000
|
Size: |
8192
|
|
49FF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3379594086.00000000049FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
49FF000
|
Size: |
4096
|
|
334E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3377311450.000000000334E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
334E000
|
Size: |
8192
|
|
CC0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3376479051.0000000000CC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CC0000
|
Size: |
16384
|
|
383F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3378396780.000000000383F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
383F000
|
Size: |
4096
|
|
453E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3379153008.000000000453E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
453E000
|
Size: |
8192
|
|
462D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3380193423.000000000462D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
462D000
|
Size: |
12288
|
|
4B8F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3379596969.0000000004B8F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4B8F000
|
Size: |
4096
|
|
35BF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3378206248.00000000035BF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
35BF000
|
Size: |
4096
|
|
328F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3377486625.000000000328F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
328F000
|
Size: |
4096
|
|
FF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3376535178.0000000000FF0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FF0000
|
Size: |
4096
|
|
5140000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3380338007.0000000005140000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5140000
|
Size: |
4096
|
|
330F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3377264437.000000000330F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
330F000
|
Size: |
4096
|
|
3C3F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3378256628.0000000003C3F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3C3F000
|
Size: |
4096
|
|
323E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3377988973.000000000323E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
323E000
|
Size: |
8192
|
|
34FF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3377873612.00000000034FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
34FF000
|
Size: |
4096
|
|
43FF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3379331593.00000000043FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
43FF000
|
Size: |
4096
|
|
3E0E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3378302112.0000000003E0E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3E0E000
|
Size: |
8192
|
|
3B8E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3378150370.0000000003B8E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3B8E000
|
Size: |
8192
|
|
7AE000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3375547902.00000000007AE000.00000040.00000001.01000000.00000005.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
7AE000
|
Size: |
8192
|
|
4E40000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000003.2153679346.0000000004E40000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4E40000
|
Size: |
12288
|
|
2AFF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3377053068.0000000002AFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2AFF000
|
Size: |
4096
|
|
BBB000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3375585687.0000000000BBB000.00000040.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
BBB000
|
Size: |
4096
|
|
350F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3377715165.000000000350F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
350F000
|
Size: |
4096
|
|
D32000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2362394351.0000000000D32000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D32000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
4E40000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000003.2153475251.0000000004E40000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4E40000
|
Size: |
4096
|
|
46E0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000003.2343175612.00000000046E0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
46E0000
|
Size: |
4096
|
|
410E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3378228245.000000000410E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
410E000
|
Size: |
8192
|
|
953000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000007.00000002.3375549813.0000000000953000.00000008.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
953000
|
Size: |
12288
|
|
46E0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000003.2343300330.00000000046E0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
46E0000
|
Size: |
4096
|
|
417F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3379049179.000000000417F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
417F000
|
Size: |
4096
|
|
D34000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2362394351.0000000000D34000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D34000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
50C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3375441152.000000000050C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
50C000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
9C0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3376370134.00000000009C0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9C0000
|
Size: |
4096
|
|
46E0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000003.2343195151.00000000046E0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
46E0000
|
Size: |
4096
|
|
3D7F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3378343779.0000000003D7F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3D7F000
|
Size: |
4096
|
|
3D4E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3377987584.0000000003D4E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3D4E000
|
Size: |
8192
|
|
D1C000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3376340860.0000000000D1C000.00000040.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
D1C000
|
Size: |
4096
|
|
3EFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3378493375.0000000003EFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3EFE000
|
Size: |
8192
|
|
95D000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
00000008.00000002.3376371523.000000000095D000.00000080.00000001.01000000.00000005.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
95D000
|
Size: |
8192
|
|
4E00000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000003.2263482243.0000000004E00000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4E00000
|
Size: |
4096
|
|
48BF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3379469099.00000000048BF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
48BF000
|
Size: |
4096
|
|
14FD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3377080253.00000000014FD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14FD000
|
Size: |
225280
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
448F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3378438135.000000000448F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
448F000
|
Size: |
4096
|
|
4C7F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3379844809.0000000004C7F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4C7F000
|
Size: |
4096
|
|
4E40000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000003.2153578581.0000000004E40000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4E40000
|
Size: |
4096
|
|
3F4E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3378392559.0000000003F4E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3F4E000
|
Size: |
8192
|
|
BBC000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
00000006.00000002.3376276910.0000000000BBC000.00000080.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
BBC000
|
Size: |
1441792
|
|
477F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3379334296.000000000477F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
477F000
|
Size: |
4096
|
|
317E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3377621069.000000000317E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
317E000
|
Size: |
8192
|
|
46E0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000003.2343280109.00000000046E0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
46E0000
|
Size: |
4096
|
|
348E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3377412700.000000000348E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
348E000
|
Size: |
8192
|
|
32CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3377556219.00000000032CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
32CE000
|
Size: |
8192
|
|
453F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3379476257.000000000453F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
453F000
|
Size: |
4096
|
|
2ECF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3377121602.0000000002ECF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2ECF000
|
Size: |
4096
|
|
3F0F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3378345026.0000000003F0F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3F0F000
|
Size: |
4096
|
|
460000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000008.00000000.2256806379.0000000000460000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
8
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
460000
|
Size: |
4096
|
|
500E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3379924112.000000000500E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
500E000
|
Size: |
8192
|
|
4C30000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000003.2154328496.0000000004C30000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4C30000
|
Size: |
4096
|
|
BBB000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.3375661862.0000000000BBB000.00000040.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
BBB000
|
Size: |
4096
|
|
417E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3378766400.000000000417E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
417E000
|
Size: |
8192
|
|
42BF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3379193005.00000000042BF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
42BF000
|
Size: |
4096
|
|
D4E000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3375843712.0000000000D4E000.00000040.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
D4E000
|
Size: |
20480
|
|
593000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000008.00000002.3375514063.0000000000593000.00000008.00000001.01000000.00000005.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
593000
|
Size: |
12288
|
|
46E0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000003.2343151899.00000000046E0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
46E0000
|
Size: |
8192
|
|
28F0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3376924016.00000000028F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
28F0000
|
Size: |
16384
|
|
3E4F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3378027040.0000000003E4F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3E4F000
|
Size: |
4096
|
|
327F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3377674153.000000000327F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
327F000
|
Size: |
4096
|
|
4D5F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3379403559.0000000004D5F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4D5F000
|
Size: |
4096
|
|
1320000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3376746629.0000000001320000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1320000
|
Size: |
4096
|
|
95C000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000002.3376304167.000000000095C000.00000040.00000001.01000000.00000005.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
95C000
|
Size: |
4096
|
|
4C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3375404655.00000000004C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4C0000
|
Size: |
20480
|
|
4DD8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3379470528.0000000004DD8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DD8000
|
Size: |
2002944
|
|
3F3E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3378845877.0000000003F3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3F3E000
|
Size: |
8192
|
|
3D3F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3379142312.0000000003D3F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3D3F000
|
Size: |
4096
|
|
4DA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3375441152.00000000004DA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DA000
|
Size: |
8192
|
|
4E2E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3380056609.0000000004E2E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4E2E000
|
Size: |
8192
|
|
333F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3378025919.000000000333F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
333F000
|
Size: |
4096
|
|
2DCE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3377077852.0000000002DCE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2DCE000
|
Size: |
8192
|
|
4420000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000003.2128444485.0000000004420000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4420000
|
Size: |
4096
|
|
B9E000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.3375661862.0000000000B9E000.00000040.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
B9E000
|
Size: |
57344
|
|
46E0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000003.2343366762.00000000046E0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
46E0000
|
Size: |
4096
|
|
304E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3377322169.000000000304E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
304E000
|
Size: |
8192
|
|
39BF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3378093696.00000000039BF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
39BF000
|
Size: |
4096
|
|
2FBE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3377792550.0000000002FBE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2FBE000
|
Size: |
8192
|
|
7DE000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000002.3375602728.00000000007DE000.00000040.00000001.01000000.00000005.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
7DE000
|
Size: |
57344
|
|
FAD000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3376159397.0000000000FAD000.00000040.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
FAD000
|
Size: |
32768
|
|
3C0E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3377920200.0000000003C0E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3C0E000
|
Size: |
8192
|
|
364F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3377795890.000000000364F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
364F000
|
Size: |
4096
|
|
2F0E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3377182945.0000000002F0E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2F0E000
|
Size: |
8192
|
|
484F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3378841284.000000000484F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
484F000
|
Size: |
4096
|
|
4420000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000003.2128430172.0000000004420000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4420000
|
Size: |
4096
|
|
2A7F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3377324623.0000000002A7F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2A7F000
|
Size: |
4096
|
|
ADE000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3375585687.0000000000ADE000.00000040.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
ADE000
|
Size: |
561152
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
30CF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3377425028.00000000030CF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
30CF000
|
Size: |
4096
|
|
14F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3377080253.00000000014F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14F0000
|
Size: |
32768
|
|
46E0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000003.2343322977.00000000046E0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
46E0000
|
Size: |
4096
|
|
F9E000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3376159397.0000000000F9E000.00000040.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
F9E000
|
Size: |
57344
|
|
33BF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3377774035.00000000033BF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
33BF000
|
Size: |
4096
|
|
14FE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3376796312.00000000014FE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14FE000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
38FE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3378250183.00000000038FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
38FE000
|
Size: |
8192
|
|
430E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3378765549.000000000430E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
430E000
|
Size: |
8192
|
|
35C000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3375217915.000000000035C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
35C000
|
Size: |
16384
|
|
46CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3379144742.00000000046CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
46CE000
|
Size: |
8192
|
|
39FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3378138306.00000000039FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
39FE000
|
Size: |
8192
|
|
B9E000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3375585687.0000000000B9E000.00000040.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
B9E000
|
Size: |
57344
|
|
C20000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3375807351.0000000000C20000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
C20000
|
Size: |
4096
|
|
472E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3380227052.000000000472E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
472E000
|
Size: |
8192
|
|
BBB000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
00000006.00000000.2147473463.0000000000BBB000.00000080.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
BBB000
|
Size: |
1458176
|
|
45CF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3378526717.00000000045CF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
45CF000
|
Size: |
4096
|
|