148F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1298019347.000000000148F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
148F000
|
Size: |
8192
|
|
13D4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1297787293.00000000013D4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13D4000
|
Size: |
4096
|
|
13D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3676267766.00000000013D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13D0000
|
Size: |
16384
|
|
13D4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1297770096.00000000013D4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13D4000
|
Size: |
4096
|
|
145A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3676294936.000000000145A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
145A000
|
Size: |
8192
|
|
324D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3676426093.000000000324D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
324D000
|
Size: |
2002944
|
|
13D4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1297741270.00000000013D4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13D4000
|
Size: |
4096
|
|
1483000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3676294936.0000000001483000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1483000
|
Size: |
8192
|
|
13D4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1270997819.00000000013D4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13D4000
|
Size: |
4096
|
|
620000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1226749287.0000000000620000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
620000
|
Size: |
4096
|
|
1450000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3676294936.0000000001450000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1450000
|
Size: |
32768
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
F2B000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.3676191336.0000000000F2B000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F2B000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
12FC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3676226503.00000000012FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
12FC000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
13D4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1297801783.00000000013D4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13D4000
|
Size: |
4096
|
|
13F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1271050917.00000000013F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
13F0000
|
Size: |
167936
|
|
13D4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1297755964.00000000013D4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13D4000
|
Size: |
4096
|
|
148F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3676294936.000000000148F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
148F000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
3090000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3676387440.0000000003090000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3090000
|
Size: |
8192
|
|
145E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3676294936.000000000145E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
145E000
|
Size: |
114688
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
13D4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1297639142.00000000013D4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13D4000
|
Size: |
4096
|
|
72D000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.3673911110.000000000072D000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
72D000
|
Size: |
135168
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
13D4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1297713504.00000000013D4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13D4000
|
Size: |
4096
|
|
143D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3676281426.000000000143D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
143D000
|
Size: |
12288
|
|
30A1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1270972170.00000000030A1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30A1000
|
Size: |
65536
|
|
77B000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3674514286.000000000077B000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
77B000
|
Size: |
16384
|
|
1340000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3676252464.0000000001340000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1340000
|
Size: |
4096
|
|
1330000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3676239115.0000000001330000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1330000
|
Size: |
4096
|
|
74E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3674141825.000000000074E000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
74E000
|
Size: |
20480
|
|
1487000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1298019347.0000000001487000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1487000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
620000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.3673171120.0000000000620000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
620000
|
Size: |
4096
|
|
30A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3676399533.00000000030A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30A0000
|
Size: |
4096
|
|
A08000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000002.3675660855.0000000000A08000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
A08000
|
Size: |
5386240
|
|
A07000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3675561236.0000000000A07000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
A07000
|
Size: |
4096
|
|
30A1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1297521615.00000000030A1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30A1000
|
Size: |
225280
|
|
FCC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3676207136.0000000000FCC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FCC000
|
Size: |
16384
|
|
3230000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3676411224.0000000003230000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3230000
|
Size: |
12288
|
|
A08000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000000.1226916673.0000000000A08000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
A08000
|
Size: |
5386240
|
|
147B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3676294936.000000000147B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
147B000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
621000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000002.3673360794.0000000000621000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
621000
|
Size: |
1097728
|
|
F2B000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1227307455.0000000000F2B000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F2B000
|
Size: |
16384
|
|
353E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3676527115.000000000353E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
353E000
|
Size: |
8192
|
|
781000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000002.3674641802.0000000000781000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
781000
|
Size: |
2646016
|
|
753000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000002.3674343562.0000000000753000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
753000
|
Size: |
163840
|
|