E21000
|
unkown
|
page execute and read and write
|
 |
|
|
Name: |
00000008.00000002.3319260844.0000000000E21000.00000040.00000001.01000000.00000005.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
E21000
|
Size: |
1249280
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected RisePro Stealer |
Stealing of Sensitive Information, Remote Access Functionality |
|
SQL strings found in memory and binary data |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
471000
|
unkown
|
page execute and read and write
|
 |
|
|
Name: |
00000007.00000002.3319154863.0000000000471000.00000040.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
471000
|
Size: |
1249280
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected RisePro Stealer |
Stealing of Sensitive Information, Remote Access Functionality |
|
SQL strings found in memory and binary data |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
4980000
|
direct allocation
|
page read and write
|
 |
|
|
Name: |
00000007.00000003.2082671106.0000000004980000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4980000
|
Size: |
1249280
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected RisePro Stealer |
Stealing of Sensitive Information, Remote Access Functionality |
|
SQL strings found in memory and binary data |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
471000
|
unkown
|
page execute and read and write
|
 |
|
|
Name: |
00000006.00000002.3319156368.0000000000471000.00000040.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
471000
|
Size: |
1249280
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected RisePro Stealer |
Stealing of Sensitive Information, Remote Access Functionality |
|
SQL strings found in memory and binary data |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
4A40000
|
direct allocation
|
page read and write
|
 |
|
|
Name: |
0000000A.00000003.2283677130.0000000004A40000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4A40000
|
Size: |
1249280
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected RisePro Stealer |
Stealing of Sensitive Information, Remote Access Functionality |
|
SQL strings found in memory and binary data |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
E21000
|
unkown
|
page execute and read and write
|
 |
|
|
Name: |
0000000A.00000002.3319651891.0000000000E21000.00000040.00000001.01000000.00000005.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
E21000
|
Size: |
1249280
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected RisePro Stealer |
Stealing of Sensitive Information, Remote Access Functionality |
|
SQL strings found in memory and binary data |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
4860000
|
direct allocation
|
page read and write
|
 |
|
|
Name: |
00000006.00000003.2082082490.0000000004860000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4860000
|
Size: |
1249280
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected RisePro Stealer |
Stealing of Sensitive Information, Remote Access Functionality |
|
SQL strings found in memory and binary data |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
4A60000
|
direct allocation
|
page read and write
|
 |
|
|
Name: |
00000000.00000003.2056094300.0000000004A60000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4A60000
|
Size: |
1249280
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected RisePro Stealer |
Stealing of Sensitive Information, Remote Access Functionality |
|
SQL strings found in memory and binary data |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
611000
|
unkown
|
page execute and read and write
|
 |
|
|
Name: |
00000000.00000002.3319167481.0000000000611000.00000040.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
611000
|
Size: |
1249280
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected RisePro Stealer |
Stealing of Sensitive Information, Remote Access Functionality |
|
SQL strings found in memory and binary data |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
5210000
|
direct allocation
|
page read and write
|
 |
|
|
Name: |
00000008.00000003.2202132987.0000000005210000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
5210000
|
Size: |
1249280
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected RisePro Stealer |
Stealing of Sensitive Information, Remote Access Functionality |
|
SQL strings found in memory and binary data |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
40BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3322723794.00000000040BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
40BE000
|
Size: |
8192
|
|
7C1000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3319492334.00000000007C1000.00000040.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
7C1000
|
Size: |
77824
|
|
415E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3322190204.000000000415E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
415E000
|
Size: |
8192
|
|
49B0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000003.2082881393.00000000049B0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
49B0000
|
Size: |
8192
|
|
4DAE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3323241628.0000000004DAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4DAE000
|
Size: |
8192
|
|
2BFE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3320682946.0000000002BFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2BFE000
|
Size: |
8192
|
|
11A0000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3319559246.00000000011A0000.00000040.00000001.01000000.00000005.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
11A0000
|
Size: |
24576
|
|
2D5F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3320906966.0000000002D5F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2D5F000
|
Size: |
4096
|
|
2D9E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3320949336.0000000002D9E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2D9E000
|
Size: |
8192
|
|
37AF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3321434910.00000000037AF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
37AF000
|
Size: |
4096
|
|
116D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2070064752.000000000116D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
116D000
|
Size: |
262144
|
|
37EE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3321480101.00000000037EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
37EE000
|
Size: |
8192
|
|
446E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3322326555.000000000446E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
446E000
|
Size: |
8192
|
|
4A1F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3322916212.0000000004A1F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4A1F000
|
Size: |
4096
|
|
1130000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3320586655.0000000001130000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1130000
|
Size: |
32768
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
11B6000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
00000008.00000000.2196508423.00000000011B6000.00000080.00000001.01000000.00000005.sdmp
|
TargetID: |
8
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
11B6000
|
Size: |
1429504
|
|
5250000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000003.2202597003.0000000005250000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
5250000
|
Size: |
4096
|
|
F04000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000003.2095019691.0000000000F04000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F04000
|
Size: |
4096
|
|
1070000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3320549326.0000000001070000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1070000
|
Size: |
4096
|
|
1720000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3320468771.0000000001720000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1720000
|
Size: |
32768
|
|
3420000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3321013714.0000000003420000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3420000
|
Size: |
16384
|
|
470000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3319086036.0000000000470000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
470000
|
Size: |
4096
|
|
43DF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3322467587.00000000043DF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
43DF000
|
Size: |
4096
|
|
28A7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3320643689.00000000028A7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
28A7000
|
Size: |
12288
|
|
3E3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3322547831.0000000003E3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3E3E000
|
Size: |
8192
|
|
3DEF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3321852466.0000000003DEF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3DEF000
|
Size: |
4096
|
|
4AA0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000003.2056784206.0000000004AA0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4AA0000
|
Size: |
4096
|
|
470000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3319088494.0000000000470000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
470000
|
Size: |
4096
|
|
4A80000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000003.2285049450.0000000004A80000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4A80000
|
Size: |
8192
|
|
1870000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3320686648.0000000001870000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1870000
|
Size: |
4096
|
|
366F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3321362969.000000000366F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
366F000
|
Size: |
4096
|
|
44DF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3322416496.00000000044DF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
44DF000
|
Size: |
4096
|
|
32BF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3321553713.00000000032BF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
32BF000
|
Size: |
4096
|
|
4C7D000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3323174263.0000000004C7D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4C7D000
|
Size: |
12288
|
|
2CAE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3320852981.0000000002CAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2CAE000
|
Size: |
8192
|
|
4A80000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000003.2285445483.0000000004A80000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4A80000
|
Size: |
4096
|
|
38DE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3321761527.00000000038DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
38DE000
|
Size: |
8192
|
|
4CB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3323625218.0000000004CB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CB0000
|
Size: |
4096
|
|
317F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3321443557.000000000317F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
317F000
|
Size: |
4096
|
|
2F3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3321273037.0000000002F3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2F3E000
|
Size: |
8192
|
|
3CAF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3321757040.0000000003CAF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3CAF000
|
Size: |
4096
|
|
806000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.3319492640.0000000000806000.00000040.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
806000
|
Size: |
4096
|
|
11B7000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
0000000A.00000002.3320409253.00000000011B7000.00000080.00000001.01000000.00000005.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
11B7000
|
Size: |
1417216
|
|
376F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3321259493.000000000376F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
376F000
|
Size: |
4096
|
|
1250000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3320576587.0000000001250000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1250000
|
Size: |
4096
|
|
353F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3321764196.000000000353F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
353F000
|
Size: |
4096
|
|
9A7000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
00000000.00000002.3320092164.00000000009A7000.00000080.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
9A7000
|
Size: |
1417216
|
|
1311000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.3320607317.0000000001311000.00000040.00000001.01000000.00000005.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
1311000
|
Size: |
4096
|
|
307E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3321379445.000000000307E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
307E000
|
Size: |
8192
|
|
172E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3320468771.000000000172E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
172E000
|
Size: |
225280
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
47FF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3323149223.00000000047FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
47FF000
|
Size: |
4096
|
|
4A7B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3322958490.0000000004A7B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4A7B000
|
Size: |
2002944
|
|
4AA0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000003.2056693492.0000000004AA0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4AA0000
|
Size: |
4096
|
|
D70000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3320332326.0000000000D70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D70000
|
Size: |
4096
|
|
7F0000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3319492334.00000000007F0000.00000040.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
7F0000
|
Size: |
24576
|
|
46EE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3322593963.00000000046EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
46EE000
|
Size: |
8192
|
|
806000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
00000007.00000000.2076518763.0000000000806000.00000080.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
806000
|
Size: |
1429504
|
|
39DF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3321809241.00000000039DF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
39DF000
|
Size: |
4096
|
|
479F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3322730182.000000000479F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
479F000
|
Size: |
4096
|
|
5A3000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.3319156368.00000000005A3000.00000040.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
5A3000
|
Size: |
20480
|
|
3CBF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3322436391.0000000003CBF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3CBF000
|
Size: |
4096
|
|
EFD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3320411319.0000000000EFD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
EFD000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
4A2F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3322636290.0000000004A2F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4A2F000
|
Size: |
4096
|
|
411F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3322148711.000000000411F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
411F000
|
Size: |
4096
|
|
3B5E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3321936701.0000000003B5E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3B5E000
|
Size: |
8192
|
|
366E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3321217102.000000000366E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
366E000
|
Size: |
8192
|
|
37AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3321291414.00000000037AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
37AE000
|
Size: |
8192
|
|
4981000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3323248752.0000000004981000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4981000
|
Size: |
2002944
|
|
10DF000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.3319930362.00000000010DF000.00000040.00000001.01000000.00000005.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
10DF000
|
Size: |
573440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
8CF000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3319543415.00000000008CF000.00000040.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
8CF000
|
Size: |
573440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
5250000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000003.2202402536.0000000005250000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
5250000
|
Size: |
4096
|
|
962000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
00000007.00000002.3320274736.0000000000962000.00000080.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
962000
|
Size: |
4096
|
|
F5C000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.3319930362.0000000000F5C000.00000040.00000001.01000000.00000005.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
F5C000
|
Size: |
1572864
|
|
48A0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000003.2082485088.00000000048A0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
48A0000
|
Size: |
4096
|
|
5AC000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3319492334.00000000005AC000.00000040.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
5AC000
|
Size: |
1572864
|
|
2E9F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3320988212.0000000002E9F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2E9F000
|
Size: |
4096
|
|
E20000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3319624486.0000000000E20000.00000004.00000001.01000000.00000005.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
E20000
|
Size: |
4096
|
|
470000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000000.2075741035.0000000000470000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
470000
|
Size: |
4096
|
|
4870000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000003.2082563959.0000000004870000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4870000
|
Size: |
4096
|
|
2F2E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3320988137.0000000002F2E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2F2E000
|
Size: |
8192
|
|
506F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3323194644.000000000506F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
506F000
|
Size: |
4096
|
|
1820000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3320645220.0000000001820000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1820000
|
Size: |
4096
|
|
306E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3321052020.000000000306E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
306E000
|
Size: |
8192
|
|
51AF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3323353903.00000000051AF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
51AF000
|
Size: |
4096
|
|
3DAF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3321678319.0000000003DAF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3DAF000
|
Size: |
4096
|
|
E21000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
00000008.00000000.2196404582.0000000000E21000.00000080.00000001.01000000.00000005.sdmp
|
TargetID: |
8
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
E21000
|
Size: |
593920
|
|
3ADF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3321630492.0000000003ADF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3ADF000
|
Size: |
4096
|
|
961000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3320247369.0000000000961000.00000040.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
961000
|
Size: |
4096
|
|
4B92000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2056094300.0000000004B92000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4B92000
|
Size: |
16384
|
|
45AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3322434628.00000000045AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
45AE000
|
Size: |
8192
|
|
F58000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000008.00000000.2196494657.0000000000F58000.00000008.00000001.01000000.00000005.sdmp
|
TargetID: |
8
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
F58000
|
Size: |
12288
|
|
483E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3323178027.000000000483E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
483E000
|
Size: |
8192
|
|
3A7E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3322307656.0000000003A7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3A7E000
|
Size: |
8192
|
|
5250000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000003.2202569242.0000000005250000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
5250000
|
Size: |
4096
|
|
41FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3322819210.00000000041FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
41FE000
|
Size: |
8192
|
|
F58000
|
unkown
|
page write copy
|
|
|
|
Name: |
0000000A.00000000.2277152120.0000000000F58000.00000008.00000001.01000000.00000005.sdmp
|
TargetID: |
10
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
F58000
|
Size: |
12288
|
|
392E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3321555614.000000000392E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
392E000
|
Size: |
8192
|
|
3F3F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3322596969.0000000003F3F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3F3F000
|
Size: |
4096
|
|
33FF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3321679536.00000000033FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
33FF000
|
Size: |
4096
|
|
1177000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2072867835.0000000001177000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1177000
|
Size: |
36864
|
|
2DEE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3320918200.0000000002DEE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2DEE000
|
Size: |
8192
|
|
F5C000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3319559246.0000000000F5C000.00000040.00000001.01000000.00000005.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
F5C000
|
Size: |
1572864
|
|
2A2E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3320727039.0000000002A2E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2A2E000
|
Size: |
8192
|
|
1880000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3320726342.0000000001880000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1880000
|
Size: |
16384
|
|
4AA0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000003.2056823614.0000000004AA0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4AA0000
|
Size: |
4096
|
|
F3C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3320434890.0000000000F3C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
F3C000
|
Size: |
16384
|
|
402F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3321847887.000000000402F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
402F000
|
Size: |
4096
|
|
470000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.2076415278.0000000000470000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
470000
|
Size: |
4096
|
|
491E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3322863577.000000000491E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
491E000
|
Size: |
8192
|
|
38EF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3321518626.00000000038EF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
38EF000
|
Size: |
4096
|
|
5250000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000003.2202476605.0000000005250000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
5250000
|
Size: |
4096
|
|
38EE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3321364067.00000000038EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
38EE000
|
Size: |
8192
|
|
49B0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000003.2083200292.00000000049B0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
49B0000
|
Size: |
4096
|
|
748000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.2049821270.0000000000748000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
748000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
997000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3319543415.0000000000997000.00000040.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
997000
|
Size: |
40960
|
|
7F7000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3319492334.00000000007F7000.00000040.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
7F7000
|
Size: |
40960
|
|
465F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3322638189.000000000465F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
465F000
|
Size: |
4096
|
|
3A6E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3321632162.0000000003A6E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3A6E000
|
Size: |
8192
|
|
172A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3320468771.000000000172A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
172A000
|
Size: |
8192
|
|
3DEE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3321717969.0000000003DEE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3DEE000
|
Size: |
8192
|
|
407F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3322676531.000000000407F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
407F000
|
Size: |
4096
|
|
4AA0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000003.2056739974.0000000004AA0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4AA0000
|
Size: |
4096
|
|
335F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3321175492.000000000335F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
335F000
|
Size: |
4096
|
|
113A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3320586655.000000000113A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
113A000
|
Size: |
8192
|
|
48DF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3322825259.00000000048DF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
48DF000
|
Size: |
4096
|
|
117F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2072822878.000000000117F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
117F000
|
Size: |
188416
|
|
42FF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3322862150.00000000042FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
42FF000
|
Size: |
4096
|
|
3F2F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3321938462.0000000003F2F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3F2F000
|
Size: |
4096
|
|
4D7E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3323211366.0000000004D7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4D7E000
|
Size: |
8192
|
|
356E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3321327868.000000000356E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
356E000
|
Size: |
8192
|
|
3EDE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3322004322.0000000003EDE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3EDE000
|
Size: |
8192
|
|
47DE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3322775920.00000000047DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
47DE000
|
Size: |
8192
|
|
2880000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3320607406.0000000002880000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2880000
|
Size: |
4096
|
|
303F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3321326407.000000000303F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
303F000
|
Size: |
4096
|
|
2B3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3320874774.0000000002B3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2B3E000
|
Size: |
8192
|
|
D60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3320301775.0000000000D60000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D60000
|
Size: |
4096
|
|
469E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3322688670.000000000469E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
469E000
|
Size: |
8192
|
|
325F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3321234884.000000000325F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
325F000
|
Size: |
4096
|
|
3B1E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3321674914.0000000003B1E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3B1E000
|
Size: |
8192
|
|
1171000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3319559246.0000000001171000.00000040.00000001.01000000.00000005.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
1171000
|
Size: |
77824
|
|
46AF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3322517108.00000000046AF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
46AF000
|
Size: |
4096
|
|
34DF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3321483230.00000000034DF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
34DF000
|
Size: |
4096
|
|
47AF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3322396975.00000000047AF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
47AF000
|
Size: |
4096
|
|
36BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3321914368.00000000036BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
36BE000
|
Size: |
8192
|
|
74C000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3319543415.000000000074C000.00000040.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
74C000
|
Size: |
1572864
|
|
4A70000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000003.2056894173.0000000004A70000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4A70000
|
Size: |
4096
|
|
456F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3322376296.000000000456F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
456F000
|
Size: |
4096
|
|
461F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3322544534.000000000461F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
461F000
|
Size: |
4096
|
|
47ED000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3322471749.00000000047ED000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
47ED000
|
Size: |
12288
|
|
1766000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2213925700.0000000001766000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1766000
|
Size: |
4096
|
|
32EE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3321180610.00000000032EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
32EE000
|
Size: |
8192
|
|
315E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3321183695.000000000315E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
315E000
|
Size: |
8192
|
|
47EF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3322681847.00000000047EF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
47EF000
|
Size: |
4096
|
|
32AF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3321152737.00000000032AF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
32AF000
|
Size: |
4096
|
|
49B0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000003.2083246012.00000000049B0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
49B0000
|
Size: |
4096
|
|
5220000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000003.2202645200.0000000005220000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
5220000
|
Size: |
4096
|
|
5A8000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000006.00000002.3319459077.00000000005A8000.00000008.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
5A8000
|
Size: |
12288
|
|
475F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3322681266.000000000475F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
475F000
|
Size: |
4096
|
|
16FD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3320408065.00000000016FD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
16FD000
|
Size: |
12288
|
|
7FD000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3319259869.00000000007FD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7FD000
|
Size: |
12288
|
|
48A0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000003.2082463026.00000000048A0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
48A0000
|
Size: |
4096
|
|
37FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3322046908.00000000037FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
37FE000
|
Size: |
8192
|
|
455E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3322598847.000000000455E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
455E000
|
Size: |
8192
|
|
419E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3322354841.000000000419E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
419E000
|
Size: |
8192
|
|
3CFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3322467735.0000000003CFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3CFE000
|
Size: |
8192
|
|
3F7E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3322634756.0000000003F7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3F7E000
|
Size: |
8192
|
|
961000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.3320175939.0000000000961000.00000040.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
961000
|
Size: |
4096
|
|
2B6E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3320789014.0000000002B6E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2B6E000
|
Size: |
8192
|
|
4992000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000006.00000003.2082082490.0000000004992000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4992000
|
Size: |
16384
|
|
367F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3321865476.000000000367F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
367F000
|
Size: |
4096
|
|
43EF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3322106762.00000000043EF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
43EF000
|
Size: |
4096
|
|
5250000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000003.2202611442.0000000005250000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
5250000
|
Size: |
4096
|
|
46FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3323114066.00000000046FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
46FE000
|
Size: |
8192
|
|
48A0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000003.2082329144.00000000048A0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
48A0000
|
Size: |
4096
|
|
49B0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000003.2083261549.00000000049B0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
49B0000
|
Size: |
4096
|
|
9A6000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
00000000.00000000.2049887429.00000000009A6000.00000080.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
9A6000
|
Size: |
1429504
|
|
E20000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000008.00000000.2195894369.0000000000E20000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
8
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E20000
|
Size: |
4096
|
|
351E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3321521858.000000000351E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
351E000
|
Size: |
8192
|
|
479E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3322724634.000000000479E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
479E000
|
Size: |
8192
|
|
443F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3322957455.000000000443F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
443F000
|
Size: |
4096
|
|
743000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3319167481.0000000000743000.00000040.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
743000
|
Size: |
20480
|
|
3F6E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3321972618.0000000003F6E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3F6E000
|
Size: |
8192
|
|
33EF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3321217150.00000000033EF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
33EF000
|
Size: |
4096
|
|
127A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3320619593.000000000127A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
127A000
|
Size: |
114688
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
31AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3321120787.00000000031AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
31AE000
|
Size: |
8192
|
|
B02000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
00000000.00000002.3320330323.0000000000B02000.00000080.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
B02000
|
Size: |
4096
|
|
3A2E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3321432907.0000000003A2E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3A2E000
|
Size: |
8192
|
|
362F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3321178798.000000000362F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
362F000
|
Size: |
4096
|
|
4A55000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3322924026.0000000004A55000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4A55000
|
Size: |
2002944
|
|
7C1000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.3319492640.00000000007C1000.00000040.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
7C1000
|
Size: |
77824
|
|
49B0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000003.2083281562.00000000049B0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
49B0000
|
Size: |
4096
|
|
9A6000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3319543415.00000000009A6000.00000040.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
9A6000
|
Size: |
4096
|
|
4A80000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000003.2285427954.0000000004A80000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4A80000
|
Size: |
4096
|
|
2E9E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3320929579.0000000002E9E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2E9E000
|
Size: |
8192
|
|
4AA0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000003.2056769226.0000000004AA0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4AA0000
|
Size: |
4096
|
|
4AA0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000003.2056723918.0000000004AA0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4AA0000
|
Size: |
4096
|
|
5250000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000003.2202532533.0000000005250000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
5250000
|
Size: |
4096
|
|
11A0000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.3319930362.00000000011A0000.00000040.00000001.01000000.00000005.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
11A0000
|
Size: |
24576
|
|
49B0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000003.2083316006.00000000049B0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
49B0000
|
Size: |
4096
|
|
50AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3323246874.00000000050AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
50AE000
|
Size: |
8192
|
|
42EE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3322069291.00000000042EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
42EE000
|
Size: |
8192
|
|
4A80000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000003.2285127671.0000000004A80000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4A80000
|
Size: |
4096
|
|
442E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3322159989.000000000442E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
442E000
|
Size: |
8192
|
|
990000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3319543415.0000000000990000.00000040.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
990000
|
Size: |
24576
|
|
33FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3320911280.00000000033FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
33FE000
|
Size: |
8192
|
|
B2C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3320315039.0000000000B2C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B2C000
|
Size: |
16384
|
|
72F000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3319492334.000000000072F000.00000040.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
72F000
|
Size: |
573440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
2C50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3320819652.0000000002C50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C50000
|
Size: |
16384
|
|
4CAF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3322978927.0000000004CAF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4CAF000
|
Size: |
4096
|
|
2DFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3321183147.0000000002DFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2DFE000
|
Size: |
8192
|
|
34DE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3321304959.00000000034DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
34DE000
|
Size: |
8192
|
|
429E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3322273722.000000000429E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
429E000
|
Size: |
8192
|
|
379E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3321678276.000000000379E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
379E000
|
Size: |
8192
|
|
4CAE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3323598414.0000000004CAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4CAE000
|
Size: |
8192
|
|
3C9E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3322017184.0000000003C9E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3C9E000
|
Size: |
8192
|
|
441E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3322510491.000000000441E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
441E000
|
Size: |
8192
|
|
429F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3322399308.000000000429F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
429F000
|
Size: |
4096
|
|
3D9E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3321853176.0000000003D9E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3D9E000
|
Size: |
8192
|
|
4AA0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000003.2056856649.0000000004AA0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4AA0000
|
Size: |
4096
|
|
961000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3319543415.0000000000961000.00000040.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
961000
|
Size: |
77824
|
|
1260000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3320619593.0000000001260000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1260000
|
Size: |
36864
|
|
4AB2000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2082671106.0000000004AB2000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4AB2000
|
Size: |
16384
|
|
4A80000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000003.2285238271.0000000004A80000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4A80000
|
Size: |
4096
|
|
6FC000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3319117006.00000000006FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6FC000
|
Size: |
16384
|
|
4A80000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000003.2285465982.0000000004A80000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4A80000
|
Size: |
4096
|
|
361E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3321365581.000000000361E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
361E000
|
Size: |
8192
|
|
489F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3322780166.000000000489F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
489F000
|
Size: |
4096
|
|
2B2F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3320758995.0000000002B2F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2B2F000
|
Size: |
4096
|
|
2D5E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3320856361.0000000002D5E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2D5E000
|
Size: |
8192
|
|
2FDE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3320990909.0000000002FDE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2FDE000
|
Size: |
8192
|
|
3400000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3320959616.0000000003400000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3400000
|
Size: |
4096
|
|
1297000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3320619593.0000000001297000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1297000
|
Size: |
4096
|
|
43DE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3322346824.00000000043DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
43DE000
|
Size: |
8192
|
|
1312000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
00000008.00000002.3320334801.0000000001312000.00000080.00000001.01000000.00000005.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
1312000
|
Size: |
4096
|
|
375E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3321435972.000000000375E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
375E000
|
Size: |
8192
|
|
2FDF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3321050551.0000000002FDF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2FDF000
|
Size: |
4096
|
|
748000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000002.3319487653.0000000000748000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
748000
|
Size: |
12288
|
|
5250000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000003.2202628183.0000000005250000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
5250000
|
Size: |
12288
|
|
3B2F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3321480478.0000000003B2F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3B2F000
|
Size: |
4096
|
|
4872000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3322833403.0000000004872000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4872000
|
Size: |
2002944
|
|
46BF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3323079723.00000000046BF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
46BF000
|
Size: |
4096
|
|
451F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3322551849.000000000451F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
451F000
|
Size: |
4096
|
|
962000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
00000006.00000002.3320203537.0000000000962000.00000080.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
962000
|
Size: |
4096
|
|
415E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3322311618.000000000415E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
415E000
|
Size: |
8192
|
|
2C1E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3320757765.0000000002C1E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2C1E000
|
Size: |
8192
|
|
48A0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000003.2082501743.00000000048A0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
48A0000
|
Size: |
4096
|
|
4F6E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3323150488.0000000004F6E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4F6E000
|
Size: |
8192
|
|
3C5F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3321971914.0000000003C5F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3C5F000
|
Size: |
4096
|
|
339E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3321227704.000000000339E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
339E000
|
Size: |
8192
|
|
471000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
00000007.00000000.2076437209.0000000000471000.00000080.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
471000
|
Size: |
593920
|
|
176E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3320468771.000000000176E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
176E000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
385F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3321482556.000000000385F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
385F000
|
Size: |
4096
|
|
38FF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3322108146.00000000038FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
38FF000
|
Size: |
4096
|
|
28A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3320643689.00000000028A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
28A0000
|
Size: |
16384
|
|
F90000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3320512379.0000000000F90000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F90000
|
Size: |
4096
|
|
F53000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.3319651891.0000000000F53000.00000040.00000001.01000000.00000005.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
F53000
|
Size: |
20480
|
|
ECD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3320441207.0000000000ECD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
ECD000
|
Size: |
212992
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
493F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3323213386.000000000493F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
493F000
|
Size: |
4096
|
|
72F000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.3319492640.000000000072F000.00000040.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
72F000
|
Size: |
573440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
33BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3320860461.00000000033BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
33BE000
|
Size: |
8192
|
|
11A7000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.3319930362.00000000011A7000.00000040.00000001.01000000.00000005.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
11A7000
|
Size: |
40960
|
|
33DE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3321429382.00000000033DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
33DE000
|
Size: |
8192
|
|
49B0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000003.2083106342.00000000049B0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
49B0000
|
Size: |
4096
|
|
352F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3321152257.000000000352F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
352F000
|
Size: |
4096
|
|
F0C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000003.2095019691.0000000000F0C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F0C000
|
Size: |
8192
|
|
2C10000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3320753700.0000000002C10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C10000
|
Size: |
16384
|
|
451E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3322475313.000000000451E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
451E000
|
Size: |
8192
|
|
3BAE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3321715954.0000000003BAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3BAE000
|
Size: |
8192
|
|
5AC000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.3319492640.00000000005AC000.00000040.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
5AC000
|
Size: |
1572864
|
|
11B6000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
0000000A.00000000.2277172885.00000000011B6000.00000080.00000001.01000000.00000005.sdmp
|
TargetID: |
10
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
11B6000
|
Size: |
1429504
|
|
3FDF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3322043616.0000000003FDF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3FDF000
|
Size: |
4096
|
|
113E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3320586655.000000000113E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
113E000
|
Size: |
233472
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
405E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3322276302.000000000405E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
405E000
|
Size: |
8192
|
|
3F2E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3321802374.0000000003F2E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3F2E000
|
Size: |
8192
|
|
342E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3321255792.000000000342E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
342E000
|
Size: |
8192
|
|
DA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3320364058.0000000000DA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DA0000
|
Size: |
16384
|
|
3E9F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3321939813.0000000003E9F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3E9F000
|
Size: |
4096
|
|
3A2F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3321592633.0000000003A2F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3A2F000
|
Size: |
4096
|
|
416F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3321935544.000000000416F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
416F000
|
Size: |
4096
|
|
48DE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3322821538.00000000048DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
48DE000
|
Size: |
8192
|
|
10D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3320461780.00000000010D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10D0000
|
Size: |
4096
|
|
E20000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3319083155.0000000000E20000.00000004.00000001.01000000.00000005.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
E20000
|
Size: |
4096
|
|
4BAD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3323521335.0000000004BAD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4BAD000
|
Size: |
12288
|
|
389E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3321519032.000000000389E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
389E000
|
Size: |
8192
|
|
126A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3320619593.000000000126A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
126A000
|
Size: |
61440
|
|
545E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3323827982.000000000545E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
545E000
|
Size: |
8192
|
|
47F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3322728008.00000000047F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
47F0000
|
Size: |
4096
|
|
B01000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3320291056.0000000000B01000.00000040.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
B01000
|
Size: |
4096
|
|
10F5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3320500879.00000000010F5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10F5000
|
Size: |
12288
|
|
48A0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000003.2082290902.00000000048A0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
48A0000
|
Size: |
8192
|
|
3CEE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3321803342.0000000003CEE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3CEE000
|
Size: |
8192
|
|
4A80000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000003.2285533057.0000000004A80000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4A80000
|
Size: |
12288
|
|
BD5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3319495443.0000000000BD5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BD5000
|
Size: |
12288
|
|
35DF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3321333224.00000000035DF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
35DF000
|
Size: |
4096
|
|
433E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3322922860.000000000433E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
433E000
|
Size: |
8192
|
|
48A0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000003.2082447979.00000000048A0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
48A0000
|
Size: |
4096
|
|
11A7000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3319559246.00000000011A7000.00000040.00000001.01000000.00000005.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
11A7000
|
Size: |
40960
|
|
302F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3321016870.000000000302F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
302F000
|
Size: |
4096
|
|
2C3F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3320908334.0000000002C3F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2C3F000
|
Size: |
4096
|
|
4AA0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000003.2056872445.0000000004AA0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4AA0000
|
Size: |
12288
|
|
4A50000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000003.2285554715.0000000004A50000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4A50000
|
Size: |
4096
|
|
2C6F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3320821980.0000000002C6F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2C6F000
|
Size: |
4096
|
|
13AC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3320366420.00000000013AC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
13AC000
|
Size: |
16384
|
|
49DF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3322866714.00000000049DF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
49DF000
|
Size: |
4096
|
|
2CB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3321019954.0000000002CB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2CB0000
|
Size: |
16384
|
|
343E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3321720550.000000000343E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
343E000
|
Size: |
8192
|
|
3D5F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3321807780.0000000003D5F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3D5F000
|
Size: |
4096
|
|
3B7F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3322346009.0000000003B7F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3B7F000
|
Size: |
4096
|
|
2C00000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3320716921.0000000002C00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C00000
|
Size: |
4096
|
|
452F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3322206762.000000000452F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
452F000
|
Size: |
4096
|
|
EC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3320441207.0000000000EC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EC0000
|
Size: |
32768
|
|
357E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3321820588.000000000357E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
357E000
|
Size: |
8192
|
|
4AA0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000003.2056679003.0000000004AA0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4AA0000
|
Size: |
4096
|
|
611000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
00000000.00000000.2049663877.0000000000611000.00000080.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
611000
|
Size: |
593920
|
|
3EDF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3322151344.0000000003EDF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3EDF000
|
Size: |
4096
|
|
555E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3324068041.000000000555E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
555E000
|
Size: |
8192
|
|
5A8000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000007.00000002.3319454932.00000000005A8000.00000008.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
5A8000
|
Size: |
12288
|
|
3DFF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3322513056.0000000003DFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3DFF000
|
Size: |
4096
|
|
2C7E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3320962241.0000000002C7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2C7E000
|
Size: |
8192
|
|
2E5F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3320891942.0000000002E5F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2E5F000
|
Size: |
4096
|
|
2F9F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3320959625.0000000002F9F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2F9F000
|
Size: |
4096
|
|
389F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3321719150.000000000389F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
389F000
|
Size: |
4096
|
|
3BBE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3322398210.0000000003BBE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3BBE000
|
Size: |
8192
|
|
3C6F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3321597729.0000000003C6F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3C6F000
|
Size: |
4096
|
|
3A3F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3322252921.0000000003A3F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3A3F000
|
Size: |
4096
|
|
349F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3321265942.000000000349F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
349F000
|
Size: |
4096
|
|
4F2F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3323115050.0000000004F2F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4F2F000
|
Size: |
4096
|
|
48A0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000003.2082521953.00000000048A0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
48A0000
|
Size: |
12288
|
|
B00000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3319335738.0000000000B00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B00000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
457F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3323019068.000000000457F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
457F000
|
Size: |
4096
|
|
AD0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3319335738.0000000000AD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AD0000
|
Size: |
24576
|
|
5250000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000003.2202554986.0000000005250000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
5250000
|
Size: |
4096
|
|
401F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3322234899.000000000401F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
401F000
|
Size: |
4096
|
|
7F0000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.3319492640.00000000007F0000.00000040.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
7F0000
|
Size: |
24576
|
|
4D80000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3323243430.0000000004D80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D80000
|
Size: |
4096
|
|
2DBF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3321150394.0000000002DBF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2DBF000
|
Size: |
4096
|
|
5A3000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3319154863.00000000005A3000.00000040.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
5A3000
|
Size: |
20480
|
|
466F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3322285292.000000000466F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
466F000
|
Size: |
4096
|
|
12A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2095211059.00000000012A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12A0000
|
Size: |
8192
|
|
339F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3321360066.000000000339F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
339F000
|
Size: |
4096
|
|
3EEF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3321759794.0000000003EEF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3EEF000
|
Size: |
4096
|
|
45BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3323049561.00000000045BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
45BE000
|
Size: |
8192
|
|
4A9E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3323332325.0000000004A9E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4A9E000
|
Size: |
8192
|
|
5250000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000003.2202444214.0000000005250000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
5250000
|
Size: |
4096
|
|
3C5E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3321756504.0000000003C5E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3C5E000
|
Size: |
8192
|
|
48A0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000003.2082399813.00000000048A0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
48A0000
|
Size: |
4096
|
|
4A6E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3322676835.0000000004A6E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4A6E000
|
Size: |
8192
|
|
3B1F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3321892136.0000000003B1F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3B1F000
|
Size: |
4096
|
|
49B0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000003.2083299080.00000000049B0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
49B0000
|
Size: |
4096
|
|
E21000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
0000000A.00000000.2276925315.0000000000E21000.00000080.00000001.01000000.00000005.sdmp
|
TargetID: |
10
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
E21000
|
Size: |
593920
|
|
1885000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3320726342.0000000001885000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1885000
|
Size: |
12288
|
|
4BAE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3322872605.0000000004BAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4BAE000
|
Size: |
8192
|
|
49B0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000003.2083347771.00000000049B0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
49B0000
|
Size: |
4096
|
|
3B6F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3321676175.0000000003B6F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3B6F000
|
Size: |
4096
|
|
49B0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000003.2083331297.00000000049B0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
49B0000
|
Size: |
4096
|
|
4B72000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.2283677130.0000000004B72000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4B72000
|
Size: |
16384
|
|
2C57000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3320819652.0000000002C57000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C57000
|
Size: |
12288
|
|
3F1E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3322188823.0000000003F1E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3F1E000
|
Size: |
8192
|
|
48A0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000003.2082373251.00000000048A0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
48A0000
|
Size: |
4096
|
|
F50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3320481346.0000000000F50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F50000
|
Size: |
20480
|
|
9FC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3320234756.00000000009FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9FC000
|
Size: |
16384
|
|
456E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3322250416.000000000456E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
456E000
|
Size: |
8192
|
|
1171000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.3319930362.0000000001171000.00000040.00000001.01000000.00000005.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
1171000
|
Size: |
77824
|
|
48EF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3322547982.00000000048EF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
48EF000
|
Size: |
4096
|
|
49B0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000003.2082971911.00000000049B0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
49B0000
|
Size: |
4096
|
|
11B6000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3319559246.00000000011B6000.00000040.00000001.01000000.00000005.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
11B6000
|
Size: |
4096
|
|
176E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2213925700.000000000176E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
176E000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
CFD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3320273707.0000000000CFD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
CFD000
|
Size: |
12288
|
|
316F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3321082044.000000000316F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
316F000
|
Size: |
4096
|
|
2DAF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3320891074.0000000002DAF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2DAF000
|
Size: |
4096
|
|
1311000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3320293029.0000000001311000.00000040.00000001.01000000.00000005.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
1311000
|
Size: |
4096
|
|
4A80000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000003.2285083757.0000000004A80000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4A80000
|
Size: |
4096
|
|
399F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3321554543.000000000399F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
399F000
|
Size: |
4096
|
|
610000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.2049615216.0000000000610000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
610000
|
Size: |
4096
|
|
5250000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000003.2202505375.0000000005250000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
5250000
|
Size: |
4096
|
|
4A80000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000003.2285507898.0000000004A80000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4A80000
|
Size: |
4096
|
|
41BF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3322776514.00000000041BF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
41BF000
|
Size: |
4096
|
|
E3C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3320382920.0000000000E3C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
E3C000
|
Size: |
16384
|
|
4CEE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3323017386.0000000004CEE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4CEE000
|
Size: |
8192
|
|
10DF000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3319559246.00000000010DF000.00000040.00000001.01000000.00000005.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
10DF000
|
Size: |
573440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
48A0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000003.2082309898.00000000048A0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
48A0000
|
Size: |
4096
|
|
36AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3321401928.00000000036AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
36AE000
|
Size: |
8192
|
|
807000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
00000007.00000002.3320050095.0000000000807000.00000080.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
807000
|
Size: |
1417216
|
|
2D1F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3320823525.0000000002D1F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2D1F000
|
Size: |
4096
|
|
4B6F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3322781504.0000000004B6F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4B6F000
|
Size: |
4096
|
|
3A1E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3321848200.0000000003A1E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3A1E000
|
Size: |
8192
|
|
BD0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3319495443.0000000000BD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BD0000
|
Size: |
16384
|
|
40AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3322065427.00000000040AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
40AE000
|
Size: |
8192
|
|
1710000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3320440259.0000000001710000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1710000
|
Size: |
4096
|
|
401E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3322090030.000000000401E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
401E000
|
Size: |
8192
|
|
46AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3322343049.00000000046AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
46AE000
|
Size: |
8192
|
|
2CB7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3321019954.0000000002CB7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2CB7000
|
Size: |
12288
|
|
E20000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000A.00000000.2276811420.0000000000E20000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
10
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E20000
|
Size: |
4096
|
|
AD8000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3319335738.0000000000AD8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AD8000
|
Size: |
159744
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
432E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3322237089.000000000432E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
432E000
|
Size: |
8192
|
|
117E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3320586655.000000000117E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
117E000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
42EF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3322199906.00000000042EF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
42EF000
|
Size: |
4096
|
|
3B6E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3321534421.0000000003B6E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3B6E000
|
Size: |
8192
|
|
365E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3321595344.000000000365E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
365E000
|
Size: |
8192
|
|
4E2E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3323083662.0000000004E2E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4E2E000
|
Size: |
8192
|
|
4AA0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000003.2056650257.0000000004AA0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4AA0000
|
Size: |
8192
|
|
2EEF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3320953171.0000000002EEF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2EEF000
|
Size: |
4096
|
|
39DE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3321591472.00000000039DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
39DE000
|
Size: |
8192
|
|
42DE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3322436001.00000000042DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
42DE000
|
Size: |
8192
|
|
4980000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000003.2083403313.0000000004980000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4980000
|
Size: |
4096
|
|
38AF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3321331217.00000000038AF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
38AF000
|
Size: |
4096
|
|
375F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3321633856.000000000375F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
375F000
|
Size: |
4096
|
|
39EF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3321404933.00000000039EF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
39EF000
|
Size: |
4096
|
|
F53000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3319260844.0000000000F53000.00000040.00000001.01000000.00000005.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
F53000
|
Size: |
20480
|
|
48A0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000003.2082350437.00000000048A0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
48A0000
|
Size: |
4096
|
|
4DEF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3323047750.0000000004DEF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4DEF000
|
Size: |
4096
|
|
406E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3321891276.000000000406E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
406E000
|
Size: |
8192
|
|
465E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3322632983.000000000465E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
465E000
|
Size: |
8192
|
|
325E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3321120297.000000000325E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
325E000
|
Size: |
8192
|
|
B12000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.2296929073.0000000000B12000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B12000
|
Size: |
8192
|
|
522B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3323455371.000000000522B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
522B000
|
Size: |
2002944
|
|
5A8000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000007.00000000.2076506242.00000000005A8000.00000008.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
5A8000
|
Size: |
12288
|
|
41AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3321976474.00000000041AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
41AE000
|
Size: |
8192
|
|
393E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3322187599.000000000393E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
393E000
|
Size: |
8192
|
|
4AA0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000003.2056753675.0000000004AA0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4AA0000
|
Size: |
4096
|
|
4A80000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000003.2285295569.0000000004A80000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4A80000
|
Size: |
4096
|
|
3D9F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3322064259.0000000003D9F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3D9F000
|
Size: |
4096
|
|
361F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3321560194.000000000361F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
361F000
|
Size: |
4096
|
|
311E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3321055270.000000000311E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
311E000
|
Size: |
8192
|
|
37BF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3321975330.00000000037BF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
37BF000
|
Size: |
4096
|
|
439F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3322309742.000000000439F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
439F000
|
Size: |
4096
|
|
4A80000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000003.2285065373.0000000004A80000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4A80000
|
Size: |
4096
|
|
32FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3321637476.00000000032FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
32FE000
|
Size: |
8192
|
|
311F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3321124326.000000000311F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
311F000
|
Size: |
4096
|
|
ECA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3320441207.0000000000ECA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
ECA000
|
Size: |
8192
|
|
31BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3321501466.00000000031BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
31BE000
|
Size: |
8192
|
|
B90000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3320358930.0000000000B90000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B90000
|
Size: |
4096
|
|
3C1F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3321715395.0000000003C1F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3C1F000
|
Size: |
4096
|
|
2C17000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3320753700.0000000002C17000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C17000
|
Size: |
12288
|
|
4CAE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3323210410.0000000004CAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4CAE000
|
Size: |
8192
|
|
321F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3321083409.000000000321F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
321F000
|
Size: |
4096
|
|
806000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3319492334.0000000000806000.00000040.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
806000
|
Size: |
4096
|
|
5342000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2202132987.0000000005342000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
5342000
|
Size: |
16384
|
|
F58000
|
unkown
|
page write copy
|
|
|
|
Name: |
0000000A.00000002.3319884627.0000000000F58000.00000008.00000001.01000000.00000005.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
F58000
|
Size: |
12288
|
|
F58000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000008.00000002.3319515508.0000000000F58000.00000008.00000001.01000000.00000005.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
F58000
|
Size: |
12288
|
|
3DDE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3322102803.0000000003DDE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3DDE000
|
Size: |
8192
|
|
610000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3319079187.0000000000610000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
610000
|
Size: |
4096
|
|
471000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
00000006.00000000.2075757972.0000000000471000.00000080.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
471000
|
Size: |
593920
|
|
492E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3322595536.000000000492E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
492E000
|
Size: |
8192
|
|
329E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3321292112.000000000329E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
329E000
|
Size: |
8192
|
|
4A80000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000003.2285486754.0000000004A80000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4A80000
|
Size: |
4096
|
|
B0A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.2296929073.0000000000B0A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B0A000
|
Size: |
4096
|
|
806000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
00000006.00000000.2075868393.0000000000806000.00000080.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
806000
|
Size: |
1429504
|
|
41EE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3322163101.00000000041EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
41EE000
|
Size: |
8192
|
|
1312000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
0000000A.00000002.3320641568.0000000001312000.00000080.00000001.01000000.00000005.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
1312000
|
Size: |
4096
|
|
425F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3322233993.000000000425F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
425F000
|
Size: |
4096
|
|
352F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3321288782.000000000352F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
352F000
|
Size: |
4096
|
|
301E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3321079766.000000000301E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
301E000
|
Size: |
8192
|
|
5A8000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000006.00000000.2075850136.00000000005A8000.00000008.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
5A8000
|
Size: |
12288
|
|
DF0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3319585035.0000000000DF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DF0000
|
Size: |
4096
|
|
3427000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3321013714.0000000003427000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3427000
|
Size: |
12288
|
|
4B9E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3323435510.0000000004B9E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4B9E000
|
Size: |
8192
|
|
48A0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000003.2082424160.00000000048A0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
48A0000
|
Size: |
4096
|
|
2EFF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3321226545.0000000002EFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2EFF000
|
Size: |
4096
|
|
406F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3322016966.000000000406F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
406F000
|
Size: |
4096
|
|
DA5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3320364058.0000000000DA5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DA5000
|
Size: |
12288
|
|
42AF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3322021348.00000000042AF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
42AF000
|
Size: |
4096
|
|
2EDE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3321016275.0000000002EDE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2EDE000
|
Size: |
8192
|
|
4AA0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000003.2056708919.0000000004AA0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4AA0000
|
Size: |
4096
|
|
11B6000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.3319930362.00000000011B6000.00000040.00000001.01000000.00000005.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
11B6000
|
Size: |
4096
|
|
2C20000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3320786744.0000000002C20000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C20000
|
Size: |
4096
|
|
A60000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3319294984.0000000000A60000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A60000
|
Size: |
4096
|
|
3CAE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3321636029.0000000003CAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3CAE000
|
Size: |
8192
|
|
807000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
00000006.00000002.3319991390.0000000000807000.00000080.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
807000
|
Size: |
1417216
|
|
F0C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3320441207.0000000000F0C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F0C000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
41AF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3322115352.00000000041AF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
41AF000
|
Size: |
4096
|
|
3E2E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3321896495.0000000003E2E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3E2E000
|
Size: |
8192
|
|
11B7000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
00000008.00000002.3320094232.00000000011B7000.00000080.00000001.01000000.00000005.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
11B7000
|
Size: |
1417216
|
|
49B0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000003.2083364687.00000000049B0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
49B0000
|
Size: |
12288
|
|
442F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3322284686.000000000442F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
442F000
|
Size: |
4096
|
|
B12000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3319335738.0000000000B12000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B12000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
10F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3320500879.00000000010F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10F0000
|
Size: |
16384
|
|
30DF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3321018712.00000000030DF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
30DF000
|
Size: |
4096
|
|
5250000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000003.2202583374.0000000005250000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
5250000
|
Size: |
4096
|
|
371F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3321406596.000000000371F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
371F000
|
Size: |
4096
|
|
447E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3322986580.000000000447E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
447E000
|
Size: |
8192
|
|
7F7000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.3319492640.00000000007F7000.00000040.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
7F7000
|
Size: |
40960
|
|
1298000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2095211059.0000000001298000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1298000
|
Size: |
4096
|
|
12A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3320619593.00000000012A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12A0000
|
Size: |
8192
|
|
5250000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000003.2202373260.0000000005250000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
5250000
|
Size: |
8192
|
|