2BF5000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000008.00000002.3743374835.0000000002BF5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BF5000
|
Size: |
5648384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected RisePro Stealer |
Stealing of Sensitive Information, Remote Access Functionality |
|
Found many strings related to Crypto-Wallets (likely being stolen) |
Stealing of Sensitive Information |
|
Yara detected Credential Stealer |
Stealing of Sensitive Information |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
SQL strings found in memory and binary data |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
9392000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3751493099.0000000009392000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9392000
|
Size: |
12288
|
|
4BFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3748243352.0000000004BFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4BFE000
|
Size: |
8192
|
|
61AB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1432686079.00000000061AB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
61AB000
|
Size: |
1200128
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
11E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000002A.00000002.1545175332.00000000011E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
42
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
11E0000
|
Size: |
4096
|
|
7B20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1486797320.0000000007B20000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7B20000
|
Size: |
40960
|
|
5B9B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3749757809.0000000005B9B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5B9B000
|
Size: |
20480
|
|
384F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000027.00000002.1501292127.000000000384F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
39
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
384F000
|
Size: |
4096
|
|
2D4B000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000002F.00000002.1703908012.0000000002D4B000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
47
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
2D4B000
|
Size: |
4096
|
|
558A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3749464296.000000000558A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
558A000
|
Size: |
24576
|
|
5199000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1366723527.0000000005199000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5199000
|
Size: |
1024000
|
|
50DD000
|
stack
|
page read and write
|
|
|
|
Name: |
0000002F.00000002.1704793723.00000000050DD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
47
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
50DD000
|
Size: |
12288
|
|
BBC000
|
stack
|
page read and write
|
|
|
|
Name: |
0000002A.00000002.1533420276.0000000000BBC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
42
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BBC000
|
Size: |
16384
|
|
891E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1491949278.000000000891E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
891E000
|
Size: |
8192
|
|
8DCE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1495179117.0000000008DCE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8DCE000
|
Size: |
8192
|
|
7B30000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.1487095423.0000000007B30000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7B30000
|
Size: |
12288
|
|
757A000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1455118225.000000000757A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
757A000
|
Size: |
24576
|
|
10BD000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000002A.00000002.1535105107.00000000010BD000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
42
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
10BD000
|
Size: |
4096
|
|
8912000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1491949278.0000000008912000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8912000
|
Size: |
8192
|
|
EC5000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3741975564.0000000000EC5000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
EC5000
|
Size: |
4096
|
|
F76000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3742181371.0000000000F76000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F76000
|
Size: |
544768
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
78EF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1460222661.00000000078EF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
78EF000
|
Size: |
4096
|
|
CC9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000032.00000002.1898903847.0000000000CC9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
50
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CC9000
|
Size: |
12288
|
|
5180000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3749118449.0000000005180000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
5180000
|
Size: |
4096
|
|
5810000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3749607353.0000000005810000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5810000
|
Size: |
4096
|
|
4F8B000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1366342940.0000000004F8B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4F8B000
|
Size: |
20480
|
|
12F3000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000002D.00000002.1607638493.00000000012F3000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
45
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
12F3000
|
Size: |
4096
|
|
5140000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3748860865.0000000005140000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5140000
|
Size: |
65536
|
|
CD6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000032.00000002.1898903847.0000000000CD6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
50
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CD6000
|
Size: |
172032
|
|
2A20000
|
heap
|
page read and write
|
|
|
|
Name: |
00000032.00000002.1900306245.0000000002A20000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
50
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A20000
|
Size: |
4096
|
|
C66000
|
heap
|
page read and write
|
|
|
|
Name: |
00000029.00000002.1535264260.0000000000C66000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
41
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C66000
|
Size: |
188416
|
|
4F1D000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1366229241.0000000004F1D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4F1D000
|
Size: |
12288
|
|
8900000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1491949278.0000000008900000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8900000
|
Size: |
49152
|
|
3340000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1364492363.0000000003340000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3340000
|
Size: |
16384
|
|
56F0000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
0000002F.00000002.1704924587.00000000056F0000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
47
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
56F0000
|
Size: |
4096
|
|
75BE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1455442280.00000000075BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
75BE000
|
Size: |
8192
|
|
79CE000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1475283967.00000000079CE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
79CE000
|
Size: |
4096
|
|
64FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3750005855.00000000064FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
64FE000
|
Size: |
8192
|
|
33FB000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1364594472.00000000033FB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33FB000
|
Size: |
45056
|
|
11F2000
|
heap
|
page read and write
|
|
|
|
Name: |
0000002D.00000002.1607110732.00000000011F2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
45
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11F2000
|
Size: |
24576
|
|
1050000
|
heap
|
page read and write
|
|
|
|
Name: |
0000002D.00000002.1606850125.0000000001050000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
45
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1050000
|
Size: |
8192
|
|
8D80000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.1495105251.0000000008D80000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
8D80000
|
Size: |
28672
|
|
D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000032.00000002.1898903847.0000000000D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
50
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D01000
|
Size: |
4096
|
|
10B4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000002A.00000002.1534940037.00000000010B4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
42
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
10B4000
|
Size: |
4096
|
|
4D2E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1365716247.0000000004D2E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4D2E000
|
Size: |
8192
|
|
3673000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.1364941308.0000000003673000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
3673000
|
Size: |
4096
|
|
11E7000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000002A.00000002.1545212789.00000000011E7000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
42
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
11E7000
|
Size: |
4096
|
|
F3B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3742181371.0000000000F3B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F3B000
|
Size: |
233472
|
|
799F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1464831316.000000000799F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
799F000
|
Size: |
4096
|
|
7B2D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1486797320.0000000007B2D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7B2D000
|
Size: |
8192
|
|
1360000
|
heap
|
page read and write
|
|
|
|
Name: |
0000002F.00000002.1702955372.0000000001360000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
47
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1360000
|
Size: |
24576
|
|
AF9000
|
stack
|
page read and write
|
|
|
|
Name: |
00000032.00000002.1897698261.0000000000AF9000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
50
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
AF9000
|
Size: |
28672
|
|
63EE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3749951643.00000000063EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
63EE000
|
Size: |
8192
|
|
EB2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3741895400.0000000000EB2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
EB2000
|
Size: |
4096
|
|
11ED000
|
heap
|
page read and write
|
|
|
|
Name: |
0000002D.00000002.1607110732.00000000011ED000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
45
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11ED000
|
Size: |
8192
|
|
BDD000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000029.00000002.1534886210.0000000000BDD000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
41
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
BDD000
|
Size: |
4096
|
|
EAD000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3741868861.0000000000EAD000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
EAD000
|
Size: |
4096
|
|
E90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3741722724.0000000000E90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
E90000
|
Size: |
8192
|
|
8EBD000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1495220454.0000000008EBD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8EBD000
|
Size: |
12288
|
|
EAA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3741817291.0000000000EAA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
EAA000
|
Size: |
12288
|
|
8926000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1491949278.0000000008926000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8926000
|
Size: |
8192
|
|
10C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000002A.00000002.1535154964.00000000010C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
42
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
10C0000
|
Size: |
12288
|
|
1320000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000002D.00000002.1607774312.0000000001320000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
45
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1320000
|
Size: |
4096
|
|
8830000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1491319155.0000000008830000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8830000
|
Size: |
4096
|
|
68F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3750190430.00000000068F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
68F0000
|
Size: |
167936
|
|
2C50000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
0000002A.00000002.1545592896.0000000002C50000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
42
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
2C50000
|
Size: |
4096
|
|
7CF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1488706805.0000000007CF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7CF0000
|
Size: |
65536
|
|
7CD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1488348586.0000000007CD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7CD0000
|
Size: |
65536
|
|
2CF0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000002D.00000002.1607998705.0000000002CF0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
45
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
2CF0000
|
Size: |
8192
|
|
E70000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000029.00000002.1545198520.0000000000E70000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
41
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
E70000
|
Size: |
8192
|
|
BC0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000029.00000002.1534482738.0000000000BC0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
41
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
BC0000
|
Size: |
4096
|
|
5110000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000032.00000002.1900896714.0000000005110000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
50
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
5110000
|
Size: |
4096
|
|
782E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1458408832.000000000782E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
782E000
|
Size: |
8192
|
|
E90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000029.00000002.1545273324.0000000000E90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
41
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
E90000
|
Size: |
65536
|
|
139E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000002D.00000002.1607920338.000000000139E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
45
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
139E000
|
Size: |
8192
|
|
107E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3742845341.000000000107E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
107E000
|
Size: |
8192
|
|
1206000
|
heap
|
page read and write
|
|
|
|
Name: |
0000002D.00000002.1607110732.0000000001206000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
45
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1206000
|
Size: |
167936
|
|
6270000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3749817891.0000000006270000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6270000
|
Size: |
12288
|
|
10C0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000002D.00000002.1606966941.00000000010C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
45
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10C0000
|
Size: |
20480
|
|
4D70000
|
heap
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.1365781833.0000000004D70000.00000002.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page readonly
|
Base address: |
4D70000
|
Size: |
4096
|
|
EBA000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3741934084.0000000000EBA000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
EBA000
|
Size: |
8192
|
|
9D5000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000002.1292316063.00000000009D5000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
9D5000
|
Size: |
8192
|
|
287F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000029.00000002.1545447643.000000000287F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
41
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
287F000
|
Size: |
4096
|
|
568A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3749501738.000000000568A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
568A000
|
Size: |
24576
|
|
1090000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000032.00000002.1900058269.0000000001090000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
50
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1090000
|
Size: |
8192
|
|
ECB000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3742012568.0000000000ECB000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
ECB000
|
Size: |
4096
|
|
155F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000002F.00000002.1703400885.000000000155F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
47
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
155F000
|
Size: |
4096
|
|
6CFA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3750998307.0000000006CFA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6CFA000
|
Size: |
24576
|
|
CF8000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3741556972.0000000000CF8000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
CF8000
|
Size: |
32768
|
|
32D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000025.00000002.1498870137.000000000032D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
37
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
32D000
|
Size: |
12288
|
|
5118000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3748483055.0000000005118000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5118000
|
Size: |
32768
|
|
2881000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000029.00000002.1545493506.0000000002881000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
41
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2881000
|
Size: |
45056
|
|
1050000
|
heap
|
page read and write
|
|
|
|
Name: |
0000002A.00000002.1534369762.0000000001050000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
42
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1050000
|
Size: |
20480
|
|
367D000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.1364987300.000000000367D000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
367D000
|
Size: |
12288
|
|
2DAE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000002F.00000002.1704356341.0000000002DAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
47
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2DAE000
|
Size: |
8192
|
|
74FE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1453726437.00000000074FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
74FE000
|
Size: |
8192
|
|
7900000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1460936622.0000000007900000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7900000
|
Size: |
36864
|
|
870000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1292001883.0000000000870000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
870000
|
Size: |
1458176
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
ED0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000029.00000002.1545377920.0000000000ED0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
41
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
ED0000
|
Size: |
8192
|
|
69B8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3750190430.00000000069B8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
69B8000
|
Size: |
32768
|
|
5C9F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3749794568.0000000005C9F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5C9F000
|
Size: |
4096
|
|
95C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3741480653.000000000095C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
95C000
|
Size: |
16384
|
|
7EEE8000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.1496071711.000000007EEE8000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7EEE8000
|
Size: |
4096
|
|
2C4E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000002D.00000002.1607970222.0000000002C4E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
45
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2C4E000
|
Size: |
8192
|
|
3B31000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000032.00000002.1900794732.0000000003B31000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
50
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3B31000
|
Size: |
8192
|
|
116E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3742912908.000000000116E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
116E000
|
Size: |
8192
|
|
2A70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3743100159.0000000002A70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A70000
|
Size: |
65536
|
|
50E8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3748334565.00000000050E8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
50E8000
|
Size: |
32768
|
|
89FA000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1494325832.00000000089FA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
89FA000
|
Size: |
4096
|
|
500E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1366414452.000000000500E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
500E000
|
Size: |
8192
|
|
7C9D000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1487684725.0000000007C9D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7C9D000
|
Size: |
12288
|
|
BD3000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000029.00000002.1534619698.0000000000BD3000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
41
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
BD3000
|
Size: |
4096
|
|
2A60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3743044185.0000000002A60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A60000
|
Size: |
65536
|
|
EA3000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000032.00000002.1899670551.0000000000EA3000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
50
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
EA3000
|
Size: |
4096
|
|
79BE000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1472338361.00000000079BE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
79BE000
|
Size: |
16384
|
|
3850000
|
heap
|
page read and write
|
|
|
|
Name: |
00000027.00000002.1501431812.0000000003850000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
39
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3850000
|
Size: |
4096
|
|
7927000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1461893240.0000000007927000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7927000
|
Size: |
12288
|
|
75C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000032.00000002.1895933713.000000000075C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
50
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
75C000
|
Size: |
16384
|
|
7F0C0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3751617380.000000007F0C0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7F0C0000
|
Size: |
4096
|
|
3660000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1364902635.0000000003660000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3660000
|
Size: |
12288
|
|
7A31000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1486550832.0000000007A31000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A31000
|
Size: |
8192
|
|
733E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3751433989.000000000733E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
733E000
|
Size: |
8192
|
|
62D7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1432686079.00000000062D7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
62D7000
|
Size: |
28672
|
|
116F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1294898920.000000000116F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
116F000
|
Size: |
4096
|
|
365C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000027.00000002.1501138405.000000000365C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
39
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
365C000
|
Size: |
36864
|
|
1106000
|
heap
|
page read and write
|
|
|
|
Name: |
0000002A.00000002.1535260163.0000000001106000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
42
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1106000
|
Size: |
180224
|
|
108F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000032.00000002.1900020292.000000000108F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
50
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
108F000
|
Size: |
4096
|
|
D3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3741598018.0000000000D3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
D3E000
|
Size: |
8192
|
|
3408000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1364594472.0000000003408000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3408000
|
Size: |
233472
|
|
78F0000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.1460764607.00000000078F0000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
78F0000
|
Size: |
4096
|
|
5B37000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1366723527.0000000005B37000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5B37000
|
Size: |
229376
|
|
2A5D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3743021291.0000000002A5D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2A5D000
|
Size: |
12288
|
|
CC3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000032.00000002.1898903847.0000000000CC3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
50
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CC3000
|
Size: |
20480
|
|
E2E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000029.00000002.1545043353.0000000000E2E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
41
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
E2E000
|
Size: |
8192
|
|
6A00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3750902097.0000000006A00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6A00000
|
Size: |
36864
|
|
5F2000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000029.00000000.1519174884.00000000005F2000.00000002.00000001.01000000.00000009.sdmp
|
TargetID: |
41
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
5F2000
|
Size: |
45056
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
1394000
|
heap
|
page read and write
|
|
|
|
Name: |
0000002F.00000002.1702955372.0000000001394000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
47
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1394000
|
Size: |
188416
|
|
743E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3751463329.000000000743E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
743E000
|
Size: |
8192
|
|
5A9A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3749718104.0000000005A9A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5A9A000
|
Size: |
24576
|
|
F80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000032.00000002.1899984100.0000000000F80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
50
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F80000
|
Size: |
8192
|
|
7D10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1489127427.0000000007D10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D10000
|
Size: |
65536
|
|
FDF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000029.00000002.1545417349.0000000000FDF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
41
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FDF000
|
Size: |
4096
|
|
33D0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1364594472.00000000033D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33D0000
|
Size: |
28672
|
|
7944000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1461893240.0000000007944000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7944000
|
Size: |
4096
|
|
10F9000
|
heap
|
page read and write
|
|
|
|
Name: |
0000002A.00000002.1535260163.00000000010F9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
42
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10F9000
|
Size: |
12288
|
|
78AE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1459707728.00000000078AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
78AE000
|
Size: |
8192
|
|
898C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1493627402.000000000898C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
898C000
|
Size: |
167936
|
|
50E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3748334565.00000000050E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
50E0000
|
Size: |
12288
|
|
10D0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000002A.00000002.1535260163.00000000010D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
42
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10D0000
|
Size: |
24576
|
|
2BC1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3743374835.0000000002BC1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BC1000
|
Size: |
184320
|
|
891A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1491949278.000000000891A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
891A000
|
Size: |
8192
|
|
1040000
|
heap
|
page read and write
|
|
|
|
Name: |
0000002D.00000002.1606190334.0000000001040000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
45
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1040000
|
Size: |
4096
|
|
74BE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1453416975.00000000074BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
74BE000
|
Size: |
8192
|
|
691D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3750190430.000000000691D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
691D000
|
Size: |
86016
|
|
1200000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000002A.00000002.1545290590.0000000001200000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
42
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1200000
|
Size: |
4096
|
|
870000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000005.00000000.1273115537.0000000000870000.00000008.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
870000
|
Size: |
1458176
|
|
4E9E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1366165192.0000000004E9E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4E9E000
|
Size: |
8192
|
|
1350000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
0000002D.00000002.1607901763.0000000001350000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
45
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
1350000
|
Size: |
4096
|
|
124E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000002A.00000002.1545350426.000000000124E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
42
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
124E000
|
Size: |
8192
|
|
2B2F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000032.00000002.1900630475.0000000002B2F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
50
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2B2F000
|
Size: |
4096
|
|
7CE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1488625898.0000000007CE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7CE0000
|
Size: |
65536
|
|
3680000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1365012824.0000000003680000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3680000
|
Size: |
32768
|
|
F06000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3742108571.0000000000F06000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F06000
|
Size: |
20480
|
|
2DEF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000025.00000002.1499583412.0000000002DEF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
37
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2DEF000
|
Size: |
4096
|
|
100A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3742181371.000000000100A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
100A000
|
Size: |
36864
|
|
11E0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000002F.00000002.1702367565.00000000011E0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
47
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11E0000
|
Size: |
4096
|
|
599E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3749687735.000000000599E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
599E000
|
Size: |
8192
|
|
103E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000002A.00000002.1534166570.000000000103E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
42
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
103E000
|
Size: |
8192
|
|
132B000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000002D.00000002.1607859135.000000000132B000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
45
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
132B000
|
Size: |
4096
|
|
11CF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000002D.00000002.1607036393.00000000011CF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
45
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
11CF000
|
Size: |
4096
|
|
3674000
|
heap
|
page read and write
|
|
|
|
Name: |
00000027.00000002.1501138405.0000000003674000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
39
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3674000
|
Size: |
8192
|
|
1340000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000002D.00000002.1607879490.0000000001340000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
45
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1340000
|
Size: |
4096
|
|
36C9000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1365372955.00000000036C9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
36C9000
|
Size: |
4096
|
|
348E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000027.00000002.1500748075.000000000348E000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
39
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
348E000
|
Size: |
8192
|
|
C6D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1292333023.0000000000C6D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C6D000
|
Size: |
12288
|
|
882E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1491208957.000000000882E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
882E000
|
Size: |
8192
|
|
4F40000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1366255006.0000000004F40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4F40000
|
Size: |
4096
|
|
4C5E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3748271090.0000000004C5E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4C5E000
|
Size: |
8192
|
|
2EF7000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1364254785.0000000002EF7000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2EF7000
|
Size: |
36864
|
|
3390000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1364572477.0000000003390000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3390000
|
Size: |
4096
|
|
4FDE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000002F.00000002.1704763968.0000000004FDE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
47
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4FDE000
|
Size: |
8192
|
|
5120000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3748622337.0000000005120000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5120000
|
Size: |
65536
|
|
1368000
|
heap
|
page read and write
|
|
|
|
Name: |
0000002F.00000002.1702955372.0000000001368000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
47
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1368000
|
Size: |
81920
|
|
390000
|
heap
|
page read and write
|
|
|
|
Name: |
00000025.00000002.1498895281.0000000000390000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
37
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
390000
|
Size: |
4096
|
|
88C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1491626471.00000000088C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
88C0000
|
Size: |
49152
|
|
10D7000
|
heap
|
page read and write
|
|
|
|
Name: |
0000002A.00000002.1535260163.00000000010D7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
42
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10D7000
|
Size: |
86016
|
|
34CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000027.00000002.1500819356.00000000034CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
39
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
34CE000
|
Size: |
8192
|
|
F3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000032.00000002.1899912833.0000000000F3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
50
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
F3E000
|
Size: |
8192
|
|
36A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1365238902.00000000036A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
36A0000
|
Size: |
4096
|
|
7935000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1461893240.0000000007935000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7935000
|
Size: |
32768
|
|
3881000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000029.00000002.1545546537.0000000003881000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
41
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3881000
|
Size: |
8192
|
|
EC7000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3741994389.0000000000EC7000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
EC7000
|
Size: |
4096
|
|
3530000
|
heap
|
page read and write
|
|
|
|
Name: |
00000027.00000002.1500967577.0000000003530000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
39
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3530000
|
Size: |
24576
|
|
7C5E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1487647806.0000000007C5E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7C5E000
|
Size: |
8192
|
|
8D50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1494969747.0000000008D50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8D50000
|
Size: |
8192
|
|
11EB000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000002A.00000002.1545251679.00000000011EB000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
42
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
11EB000
|
Size: |
4096
|
|
1320000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1294968420.0000000001320000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1320000
|
Size: |
8192
|
|
1300000
|
heap
|
page read and write
|
|
|
|
Name: |
0000002F.00000002.1702811155.0000000001300000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
47
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1300000
|
Size: |
4096
|
|
5250000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3749234174.0000000005250000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5250000
|
Size: |
233472
|
|
F10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3742163029.0000000000F10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F10000
|
Size: |
4096
|
|
79C6000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1474366941.00000000079C6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
79C6000
|
Size: |
24576
|
|
841000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000005.00000002.1291552512.0000000000841000.00000020.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
841000
|
Size: |
147456
|
|
636E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3749893651.000000000636E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
636E000
|
Size: |
8192
|
|
33D8000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1364594472.00000000033D8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33D8000
|
Size: |
139264
|
|
890E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1491949278.000000000890E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
890E000
|
Size: |
8192
|
|
2D00000
|
heap
|
page read and write
|
|
|
|
Name: |
0000002D.00000002.1608026105.0000000002D00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
45
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D00000
|
Size: |
4096
|
|
2D13000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000002F.00000002.1703540609.0000000002D13000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
47
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
2D13000
|
Size: |
4096
|
|
F30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3742181371.0000000000F30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F30000
|
Size: |
40960
|
|
5296000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1366723527.0000000005296000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5296000
|
Size: |
3637248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2AFC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000025.00000002.1499439748.0000000002AFC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
37
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AFC000
|
Size: |
24576
|
|
1382000
|
heap
|
page read and write
|
|
|
|
Name: |
0000002F.00000002.1702955372.0000000001382000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
47
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1382000
|
Size: |
20480
|
|
3D11000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000002D.00000002.1608085184.0000000003D11000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
45
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3D11000
|
Size: |
8192
|
|
2EBC000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1364224839.0000000002EBC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2EBC000
|
Size: |
16384
|
|
2B31000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000032.00000002.1900717475.0000000002B31000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
50
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B31000
|
Size: |
45056
|
|
6141000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1432686079.0000000006141000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6141000
|
Size: |
28672
|
|
7680000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1456388680.0000000007680000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7680000
|
Size: |
315392
|
|
8BE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1494586953.0000000008BE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8BE0000
|
Size: |
65536
|
|
795000
|
heap
|
page read and write
|
|
|
|
Name: |
00000032.00000002.1896010491.0000000000795000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
50
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
795000
|
Size: |
12288
|
|
574C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1366723527.000000000574C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
574C000
|
Size: |
102400
|
|
7D60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1490278849.0000000007D60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D60000
|
Size: |
65536
|
|
8B40000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.1494356511.0000000008B40000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
8B40000
|
Size: |
4096
|
|
4DC000
|
remote allocation
|
page execute read
|
|
|
|
Name: |
00000008.00000002.3739989611.00000000004DC000.00000020.00000400.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute read
|
Base address: |
4DC000
|
Size: |
368640
|
|
3FA1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000002F.00000002.1704687691.0000000003FA1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
47
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3FA1000
|
Size: |
8192
|
|
50B0000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.1366520016.00000000050B0000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
50B0000
|
Size: |
12288
|
|
56A7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1366723527.00000000056A7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
56A7000
|
Size: |
663552
|
|
88D2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1491807732.00000000088D2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
88D2000
|
Size: |
20480
|
|
865000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000000.1273087149.0000000000865000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
865000
|
Size: |
45056
|
|
C53000
|
heap
|
page read and write
|
|
|
|
Name: |
00000029.00000002.1535264260.0000000000C53000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
41
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C53000
|
Size: |
36864
|
|
E94000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3741775837.0000000000E94000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
E94000
|
Size: |
12288
|
|
EDB000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000032.00000002.1899882686.0000000000EDB000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
50
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
EDB000
|
Size: |
4096
|
|
7E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000032.00000002.1896943633.00000000007E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
50
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E0000
|
Size: |
4096
|
|
62A0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3749859669.00000000062A0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
62A0000
|
Size: |
12288
|
|
79B3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1464831316.00000000079B3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
79B3000
|
Size: |
16384
|
|
F60000
|
heap
|
page read and write
|
|
|
|
Name: |
0000002D.00000002.1606157505.0000000000F60000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
45
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F60000
|
Size: |
4096
|
|
6149000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1432686079.0000000006149000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6149000
|
Size: |
102400
|
|
7042F000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.1495964942.000000007042F000.00000002.00000001.01000000.00000007.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7042F000
|
Size: |
12288
|
|
70426000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.1495871431.0000000070426000.00000002.00000001.01000000.00000007.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
70426000
|
Size: |
28672
|
|
79A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000029.00000002.1533366292.000000000079A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
41
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
79A000
|
Size: |
24576
|
|
5766000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1366723527.0000000005766000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5766000
|
Size: |
61440
|
|
323D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000027.00000002.1500627129.000000000323D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
39
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
323D000
|
Size: |
12288
|
|
3670000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1364924229.0000000003670000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3670000
|
Size: |
12288
|
|
C0E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000032.00000002.1898054604.0000000000C0E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
50
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C0E000
|
Size: |
8192
|
|
2C4D000
|
stack
|
page read and write
|
|
|
|
Name: |
0000002A.00000002.1545551552.0000000002C4D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
42
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2C4D000
|
Size: |
12288
|
|
12F4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000002D.00000002.1607673432.00000000012F4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
45
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
12F4000
|
Size: |
4096
|
|
66AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3750095307.00000000066AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
66AE000
|
Size: |
8192
|
|
71FA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3751355697.00000000071FA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
71FA000
|
Size: |
24576
|
|
4E4E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000002A.00000002.1546016869.0000000004E4E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
42
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4E4E000
|
Size: |
8192
|
|
7C1E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1487607685.0000000007C1E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7C1E000
|
Size: |
8192
|
|
753E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1455043070.000000000753E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
753E000
|
Size: |
8192
|
|
3650000
|
heap
|
page read and write
|
|
|
|
Name: |
00000027.00000002.1501138405.0000000003650000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
39
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3650000
|
Size: |
40960
|
|
2E90000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
0000002F.00000002.1704532636.0000000002E90000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
47
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
2E90000
|
Size: |
4096
|
|
F7A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1294826709.0000000000F7A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F7A000
|
Size: |
8192
|
|
2F9F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000002F.00000002.1704604341.0000000002F9F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
47
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2F9F000
|
Size: |
4096
|
|
70411000
|
unkown
|
page execute read
|
|
|
|
Name: |
0000000B.00000002.1495778662.0000000070411000.00000020.00000001.01000000.00000007.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
70411000
|
Size: |
86016
|
|
330E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1364452911.000000000330E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
330E000
|
Size: |
8192
|
|
5611000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1366723527.0000000005611000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5611000
|
Size: |
585728
|
|
6EFA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3751275248.0000000006EFA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6EFA000
|
Size: |
24576
|
|
538000
|
remote allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3740383819.0000000000538000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
538000
|
Size: |
1445888
|
|
10F2000
|
heap
|
page read and write
|
|
|
|
Name: |
0000002A.00000002.1535260163.00000000010F2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
42
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10F2000
|
Size: |
24576
|
|
9C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3741510307.00000000009C0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9C0000
|
Size: |
4096
|
|
25AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000025.00000002.1499290175.00000000025AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
37
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
25AE000
|
Size: |
8192
|
|
EFA000
|
stack
|
page read and write
|
|
|
|
Name: |
0000002A.00000002.1533504517.0000000000EFA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
42
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
EFA000
|
Size: |
24576
|
|
11D8000
|
heap
|
page read and write
|
|
|
|
Name: |
0000002D.00000002.1607110732.00000000011D8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
45
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11D8000
|
Size: |
81920
|
|
EF0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3742053935.0000000000EF0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
EF0000
|
Size: |
65536
|
|
10FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3742890658.00000000010FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
10FE000
|
Size: |
8192
|
|
591B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3749634149.000000000591B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
591B000
|
Size: |
20480
|
|
6A10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3750902097.0000000006A10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6A10000
|
Size: |
32768
|
|
2CB1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000002A.00000002.1545750697.0000000002CB1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
42
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CB1000
|
Size: |
45056
|
|
D7F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3741621358.0000000000D7F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
D7F000
|
Size: |
4096
|
|
8780000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1491054666.0000000008780000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8780000
|
Size: |
8192
|
|
2C0F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000002A.00000002.1545498462.0000000002C0F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
42
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2C0F000
|
Size: |
4096
|
|
C0B000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000029.00000002.1535220227.0000000000C0B000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
41
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
C0B000
|
Size: |
4096
|
|
12E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000002D.00000002.1607613578.00000000012E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
45
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
12E0000
|
Size: |
4096
|
|
88F0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1491863503.00000000088F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
88F0000
|
Size: |
4096
|
|
50E4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3748334565.00000000050E4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
50E4000
|
Size: |
4096
|
|
EAD000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000032.00000002.1899755640.0000000000EAD000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
50
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
EAD000
|
Size: |
4096
|
|
4D5D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3748301652.0000000004D5D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4D5D000
|
Size: |
12288
|
|
10ED000
|
heap
|
page read and write
|
|
|
|
Name: |
0000002A.00000002.1535260163.00000000010ED000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
42
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10ED000
|
Size: |
8192
|
|
5141000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1366723527.0000000005141000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5141000
|
Size: |
356352
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2D60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000002F.00000002.1704327974.0000000002D60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
47
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D60000
|
Size: |
4096
|
|
11D0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000002D.00000002.1607110732.00000000011D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
45
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11D0000
|
Size: |
28672
|
|
E30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1293169320.0000000000E30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E30000
|
Size: |
20480
|
|
7EED0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.1496032914.000000007EED0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7EED0000
|
Size: |
4096
|
|
333D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000027.00000002.1500656130.000000000333D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
39
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
333D000
|
Size: |
12288
|
|
1327000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000002D.00000002.1607796403.0000000001327000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
45
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1327000
|
Size: |
4096
|
|
2A1F000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000025.00000002.1499389544.0000000002A1F000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
37
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2A1F000
|
Size: |
4096
|
|
338F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1364542063.000000000338F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
338F000
|
Size: |
4096
|
|
7D40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1489542751.0000000007D40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D40000
|
Size: |
65536
|
|
E93000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3741757075.0000000000E93000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
E93000
|
Size: |
4096
|
|
79BB000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1472338361.00000000079BB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
79BB000
|
Size: |
8192
|
|
4EDE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1366204848.0000000004EDE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4EDE000
|
Size: |
8192
|
|
54E0000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
0000002D.00000002.1608328289.00000000054E0000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
45
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
54E0000
|
Size: |
4096
|
|
10C4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000002A.00000002.1535154964.00000000010C4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
42
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
10C4000
|
Size: |
8192
|
|
136F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000002A.00000002.1545453123.000000000136F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
42
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
136F000
|
Size: |
4096
|
|
CA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000032.00000002.1898903847.0000000000CA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
50
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CA0000
|
Size: |
24576
|
|
F7E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1294826709.0000000000F7E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F7E000
|
Size: |
69632
|
|
2CA0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000002A.00000002.1545709102.0000000002CA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
42
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2CA0000
|
Size: |
4096
|
|
88B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1491562045.00000000088B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
88B0000
|
Size: |
49152
|
|
C60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000032.00000002.1898195519.0000000000C60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
50
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C60000
|
Size: |
4096
|
|
51A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3749138902.00000000051A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
51A0000
|
Size: |
16384
|
|
6984000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3750190430.0000000006984000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6984000
|
Size: |
172032
|
|
6430000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3749979280.0000000006430000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6430000
|
Size: |
4096
|
|
EF9000
|
stack
|
page read and write
|
|
|
|
Name: |
0000002D.00000002.1606122185.0000000000EF9000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
45
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
EF9000
|
Size: |
28672
|
|
EB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000032.00000002.1899783591.0000000000EB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
50
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
EB0000
|
Size: |
12288
|
|
D90000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3741639924.0000000000D90000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D90000
|
Size: |
16384
|
|
402000
|
remote allocation
|
page execute read
|
|
|
|
Name: |
00000008.00000002.3739028968.0000000000402000.00000020.00000400.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute read
|
Base address: |
402000
|
Size: |
888832
|
|
5190000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000002D.00000002.1608199257.0000000005190000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
45
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5190000
|
Size: |
65536
|
|
B9E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000029.00000002.1534225470.0000000000B9E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
41
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B9E000
|
Size: |
8192
|
|
790000
|
heap
|
page read and write
|
|
|
|
Name: |
00000032.00000002.1896010491.0000000000790000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
50
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
790000
|
Size: |
16384
|
|
EC2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3741956592.0000000000EC2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
EC2000
|
Size: |
4096
|
|
4D4E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000002D.00000002.1608110125.0000000004D4E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
45
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4D4E000
|
Size: |
8192
|
|
79F6000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1477941420.00000000079F6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
79F6000
|
Size: |
167936
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
BE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000029.00000002.1534984301.0000000000BE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
41
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
BE0000
|
Size: |
12288
|
|
3E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000025.00000002.1499117996.00000000003E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
37
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3E0000
|
Size: |
4096
|
|
9D5000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000000.1273273817.00000000009D5000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
9D5000
|
Size: |
8192
|
|
5AD3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1366723527.0000000005AD3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5AD3000
|
Size: |
126976
|
|
8922000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1491949278.0000000008922000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8922000
|
Size: |
8192
|
|
4EA0000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000029.00000002.1545696262.0000000004EA0000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
41
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
4EA0000
|
Size: |
4096
|
|
5100000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3748457746.0000000005100000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
5100000
|
Size: |
4096
|
|
840000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000000.1273040837.0000000000840000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
840000
|
Size: |
4096
|
|
6934000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3750190430.0000000006934000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6934000
|
Size: |
8192
|
|
2D11000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000002D.00000002.1608045595.0000000002D11000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
45
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D11000
|
Size: |
45056
|
|
51B0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3749168696.00000000051B0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
51B0000
|
Size: |
65536
|
|
8770000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.1491012634.0000000008770000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
8770000
|
Size: |
40960
|
|
70FA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3751316374.00000000070FA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
70FA000
|
Size: |
24576
|
|
5776000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1366723527.0000000005776000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5776000
|
Size: |
3522560
|
|
50FB000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1366631961.00000000050FB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
50FB000
|
Size: |
20480
|
|
1350000
|
heap
|
page read and write
|
|
|
|
Name: |
0000002F.00000002.1702918433.0000000001350000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
47
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1350000
|
Size: |
8192
|
|
2F70000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1364278480.0000000002F70000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F70000
|
Size: |
4096
|
|
36A2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1365298693.00000000036A2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
36A2000
|
Size: |
12288
|
|
88A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1491514348.00000000088A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
88A0000
|
Size: |
16384
|
|
ED7000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000032.00000002.1899847136.0000000000ED7000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
50
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
ED7000
|
Size: |
4096
|
|
C37000
|
heap
|
page read and write
|
|
|
|
Name: |
00000029.00000002.1535264260.0000000000C37000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
41
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C37000
|
Size: |
102400
|
|
4DE0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.1365940416.0000000004DE0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
4DE0000
|
Size: |
65536
|
|
2B13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000025.00000003.1498182175.0000000002B13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
37
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B13000
|
Size: |
8192
|
|
D6D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1293040616.0000000000D6D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
D6D000
|
Size: |
12288
|
|
767A000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1456042312.000000000767A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
767A000
|
Size: |
24576
|
|
E80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3741696277.0000000000E80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
E80000
|
Size: |
12288
|
|
7CB0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.1488134102.0000000007CB0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7CB0000
|
Size: |
12288
|
|
6DFA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3751223430.0000000006DFA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6DFA000
|
Size: |
24576
|
|
2BF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000025.00000002.1499549198.0000000002BF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
37
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2BF0000
|
Size: |
4096
|
|
2D20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000002F.00000002.1703732416.0000000002D20000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
47
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D20000
|
Size: |
12288
|
|
5B70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1366723527.0000000005B70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5B70000
|
Size: |
512000
|
|
109E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000002D.00000002.1606933014.000000000109E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
45
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
109E000
|
Size: |
8192
|
|
3448000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1364594472.0000000003448000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3448000
|
Size: |
552960
|
|
8D53000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1494969747.0000000008D53000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8D53000
|
Size: |
4096
|
|
4D6E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1365760225.0000000004D6E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4D6E000
|
Size: |
8192
|
|
8BCE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1494439976.0000000008BCE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8BCE000
|
Size: |
8192
|
|
E9D000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3741798751.0000000000E9D000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
E9D000
|
Size: |
4096
|
|
2BBE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3743332439.0000000002BBE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2BBE000
|
Size: |
8192
|
|
11A0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000002F.00000002.1690912648.00000000011A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
47
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11A0000
|
Size: |
20480
|
|
13A0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000002D.00000002.1607947048.00000000013A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
45
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13A0000
|
Size: |
8192
|
|
36CB000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1365372955.00000000036CB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
36CB000
|
Size: |
12288
|
|
7B8A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1487307282.0000000007B8A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7B8A000
|
Size: |
8192
|
|
1014000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3742181371.0000000001014000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1014000
|
Size: |
110592
|
|
7D50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1490037189.0000000007D50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D50000
|
Size: |
65536
|
|
C90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000032.00000002.1898818546.0000000000C90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
50
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
C90000
|
Size: |
4096
|
|
8916000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1491949278.0000000008916000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8916000
|
Size: |
8192
|
|
8760000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1490991031.0000000008760000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8760000
|
Size: |
4096
|
|
E9F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000032.00000002.1899635904.0000000000E9F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
50
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
E9F000
|
Size: |
4096
|
|
7042D000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1495923297.000000007042D000.00000004.00000001.01000000.00000007.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7042D000
|
Size: |
8192
|
|
2D47000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000002F.00000002.1703887113.0000000002D47000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
47
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
2D47000
|
Size: |
4096
|
|
4E17000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1366065791.0000000004E17000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4E17000
|
Size: |
8192
|
|
F7E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000032.00000002.1899949132.0000000000F7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
50
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
F7E000
|
Size: |
8192
|
|
4CE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1365575116.0000000004CE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4CE0000
|
Size: |
4096
|
|
2D00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000002F.00000002.1703511239.0000000002D00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
47
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D00000
|
Size: |
4096
|
|
555F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000002F.00000002.1704898457.000000000555F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
47
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
555F000
|
Size: |
4096
|
|
51DE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000002D.00000002.1608269305.00000000051DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
45
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
51DE000
|
Size: |
8192
|
|
C4E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000032.00000002.1898100493.0000000000C4E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
50
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C4E000
|
Size: |
8192
|
|
841000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000005.00000000.1273059870.0000000000841000.00000020.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
841000
|
Size: |
147456
|
|
12FE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000002F.00000002.1702424351.00000000012FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
47
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
12FE000
|
Size: |
8192
|
|
25C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000025.00000002.1499313889.00000000025C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
37
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25C0000
|
Size: |
12288
|
|
516A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3749002809.000000000516A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
516A000
|
Size: |
24576
|
|
5130000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.1366679848.0000000005130000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
5130000
|
Size: |
4096
|
|
4E4E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000002D.00000002.1608170944.0000000004E4E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
45
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4E4E000
|
Size: |
8192
|
|
DC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1293071019.0000000000DC0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DC0000
|
Size: |
4096
|
|
2D14000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000002F.00000002.1703574800.0000000002D14000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
47
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D14000
|
Size: |
4096
|
|
6630000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3750068933.0000000006630000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6630000
|
Size: |
4096
|
|
4E5C000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1366135584.0000000004E5C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4E5C000
|
Size: |
16384
|
|
653E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3750039587.000000000653E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
653E000
|
Size: |
8192
|
|
2AB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3743289598.0000000002AB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AB0000
|
Size: |
4096
|
|
3BC1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3748181990.0000000003BC1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3BC1000
|
Size: |
36864
|
|
7D00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1489043503.0000000007D00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D00000
|
Size: |
65536
|
|
799D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1464831316.000000000799D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
799D000
|
Size: |
4096
|
|
7920000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1461893240.0000000007920000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7920000
|
Size: |
20480
|
|
11F9000
|
heap
|
page read and write
|
|
|
|
Name: |
0000002D.00000002.1607110732.00000000011F9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
45
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11F9000
|
Size: |
12288
|
|
2FFE000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1364409211.0000000002FFE000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2FFE000
|
Size: |
8192
|
|
E80000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000029.00000002.1545239356.0000000000E80000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
41
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
E80000
|
Size: |
4096
|
|
10B3000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000002A.00000002.1534800613.00000000010B3000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
42
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
10B3000
|
Size: |
4096
|
|
B5E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000029.00000002.1533596639.0000000000B5E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
41
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B5E000
|
Size: |
8192
|
|
2AA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3743233324.0000000002AA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AA0000
|
Size: |
65536
|
|
79EB000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1477941420.00000000079EB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
79EB000
|
Size: |
12288
|
|
A10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000029.00000002.1533486446.0000000000A10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
41
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A10000
|
Size: |
4096
|
|
D95000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3741639924.0000000000D95000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D95000
|
Size: |
16384
|
|
F00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3742108571.0000000000F00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F00000
|
Size: |
16384
|
|
62E8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1432686079.00000000062E8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
62E8000
|
Size: |
20480
|
|
68EE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3750165655.00000000068EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
68EE000
|
Size: |
8192
|
|
7D70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1490752259.0000000007D70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D70000
|
Size: |
65536
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Found many strings related to Crypto-Wallets (likely being stolen) |
Stealing of Sensitive Information |
|
|
A40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000029.00000002.1533541033.0000000000A40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
41
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A40000
|
Size: |
20480
|
|
52CF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000002A.00000002.1546521456.00000000052CF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
42
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
52CF000
|
Size: |
4096
|
|
545E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000002F.00000002.1704829459.000000000545E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
47
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
545E000
|
Size: |
8192
|
|
52DF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000002D.00000002.1608302516.00000000052DF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
45
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
52DF000
|
Size: |
4096
|
|
1170000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3742937129.0000000001170000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1170000
|
Size: |
16384
|
|
2960000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000032.00000002.1900272435.0000000002960000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
50
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
2960000
|
Size: |
4096
|
|
87ED000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1491147144.00000000087ED000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
87ED000
|
Size: |
12288
|
|
7D80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1490938294.0000000007D80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D80000
|
Size: |
65536
|
|
7D30000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1489452820.0000000007D30000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D30000
|
Size: |
65536
|
|
1388000
|
heap
|
page read and write
|
|
|
|
Name: |
0000002F.00000002.1702955372.0000000001388000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
47
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1388000
|
Size: |
8192
|
|
69C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000029.00000002.1533265557.000000000069C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
41
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
69C000
|
Size: |
16384
|
|
69A000
|
remote allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3740383819.000000000069A000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
69A000
|
Size: |
4096
|
|
3159000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3743374835.0000000003159000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3159000
|
Size: |
12288
|
|
4DDC000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1365908478.0000000004DDC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4DDC000
|
Size: |
16384
|
|
7B2B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1486797320.0000000007B2B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7B2B000
|
Size: |
4096
|
|
8BD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1494492561.0000000008BD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8BD0000
|
Size: |
65536
|
|
1250000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000002A.00000002.1545386815.0000000001250000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
42
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1250000
|
Size: |
8192
|
|
7D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000032.00000002.1896881627.00000000007D0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
50
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7D0000
|
Size: |
4096
|
|
5130000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3748759482.0000000005130000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5130000
|
Size: |
20480
|
|
4E10000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1366065791.0000000004E10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4E10000
|
Size: |
16384
|
|
2B13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000025.00000003.1498754874.0000000002B13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
37
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B13000
|
Size: |
4096
|
|
137D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000002F.00000002.1702955372.000000000137D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
47
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
137D000
|
Size: |
8192
|
|
10BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3742868798.00000000010BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
10BE000
|
Size: |
8192
|
|
8B8E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1494404440.0000000008B8E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8B8E000
|
Size: |
8192
|
|
89E3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1494280778.00000000089E3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
89E3000
|
Size: |
12288
|
|
570E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3749537536.000000000570E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
570E000
|
Size: |
8192
|
|
F20000
|
heap
|
page read and write
|
|
|
|
Name: |
0000002A.00000002.1533545939.0000000000F20000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
42
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F20000
|
Size: |
4096
|
|
400000
|
remote allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3738862264.0000000000400000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
400000
|
Size: |
4096
|
|
7B80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1487307282.0000000007B80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7B80000
|
Size: |
24576
|
|
BD4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000029.00000002.1534733217.0000000000BD4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
41
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
BD4000
|
Size: |
4096
|
|
12FD000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000002D.00000002.1607696617.00000000012FD000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
45
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
12FD000
|
Size: |
4096
|
|
2FA1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000002F.00000002.1704627870.0000000002FA1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
47
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2FA1000
|
Size: |
45056
|
|
79D4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1477941420.00000000079D4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
79D4000
|
Size: |
90112
|
|
E20000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.1293150889.0000000000E20000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
E20000
|
Size: |
4096
|
|
F70000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1294826709.0000000000F70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F70000
|
Size: |
32768
|
|
4DF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1366016669.0000000004DF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4DF0000
|
Size: |
65536
|
|
5110000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3748483055.0000000005110000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5110000
|
Size: |
28672
|
|
56A1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1366723527.00000000056A1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
56A1000
|
Size: |
12288
|
|
2C60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000002A.00000002.1545626216.0000000002C60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
42
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C60000
|
Size: |
65536
|
|
795E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1464831316.000000000795E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
795E000
|
Size: |
221184
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
840000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000002.1291365902.0000000000840000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
840000
|
Size: |
4096
|
|
3310000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1364473497.0000000003310000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3310000
|
Size: |
12288
|
|
3DE000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000025.00000002.1499073634.00000000003DE000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
37
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3DE000
|
Size: |
8192
|
|
2DB0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000002F.00000002.1704384033.0000000002DB0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
47
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
2DB0000
|
Size: |
8192
|
|
560F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1366723527.000000000560F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
560F000
|
Size: |
4096
|
|
7CA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1487722278.0000000007CA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7CA0000
|
Size: |
65536
|
|
10A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000002A.00000002.1534642189.00000000010A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
42
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
10A0000
|
Size: |
4096
|
|
3CB1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000002A.00000002.1545905464.0000000003CB1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
42
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3CB1000
|
Size: |
8192
|
|
363F000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000027.00000002.1500995320.000000000363F000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
39
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
363F000
|
Size: |
4096
|
|
8D40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1494708661.0000000008D40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8D40000
|
Size: |
65536
|
|
69AF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3750190430.00000000069AF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
69AF000
|
Size: |
12288
|
|
67AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3750136422.00000000067AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
67AE000
|
Size: |
8192
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000002F.00000002.1704473263.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
47
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
65536
|
|
4C2E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000032.00000002.1900849483.0000000004C2E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
50
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4C2E000
|
Size: |
8192
|
|
D03000
|
heap
|
page read and write
|
|
|
|
Name: |
00000032.00000002.1898903847.0000000000D03000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
50
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D03000
|
Size: |
8192
|
|
5170000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3749096096.0000000005170000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5170000
|
Size: |
8192
|
|
EC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000029.00000002.1545345233.0000000000EC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
41
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EC0000
|
Size: |
4096
|
|
9D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3741531880.00000000009D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D0000
|
Size: |
8192
|
|
5AF3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1366723527.0000000005AF3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5AF3000
|
Size: |
274432
|
|
BE4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000029.00000002.1534984301.0000000000BE4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
41
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
BE4000
|
Size: |
8192
|
|
EB4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000032.00000002.1899783591.0000000000EB4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
50
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
EB4000
|
Size: |
8192
|
|
1300000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000002D.00000002.1607721182.0000000001300000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
45
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1300000
|
Size: |
12288
|
|
EE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3742029598.0000000000EE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
EE0000
|
Size: |
4096
|
|
62F7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1432686079.00000000062F7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
62F7000
|
Size: |
1318912
|
|
106C000
|
stack
|
page read and write
|
|
|
|
Name: |
0000002F.00000002.1690692227.000000000106C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
47
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
106C000
|
Size: |
16384
|
|
72FA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3751394654.00000000072FA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
72FA000
|
Size: |
24576
|
|
7B87000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1487307282.0000000007B87000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7B87000
|
Size: |
8192
|
|
BB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000029.00000002.1534318117.0000000000BB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
41
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BB0000
|
Size: |
8192
|
|
4FCE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1366373597.0000000004FCE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4FCE000
|
Size: |
8192
|
|
89D7000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1494221777.00000000089D7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
89D7000
|
Size: |
20480
|
|
865000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000002.1291776860.0000000000865000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
865000
|
Size: |
45056
|
|
116A000
|
stack
|
page read and write
|
|
|
|
Name: |
0000002F.00000002.1690749056.000000000116A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
47
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
116A000
|
Size: |
24576
|
|
2B11000
|
heap
|
page read and write
|
|
|
|
Name: |
00000025.00000002.1499439748.0000000002B11000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
37
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B11000
|
Size: |
16384
|
|
E1E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1293122064.0000000000E1E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
E1E000
|
Size: |
8192
|
|
4A5D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000029.00000002.1545620907.0000000004A5D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
41
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4A5D000
|
Size: |
12288
|
|
EA3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3741817291.0000000000EA3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
EA3000
|
Size: |
20480
|
|
3674000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1364961681.0000000003674000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3674000
|
Size: |
36864
|
|
7CC0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1488222205.0000000007CC0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7CC0000
|
Size: |
61440
|
|
792B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1461893240.000000000792B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
792B000
|
Size: |
24576
|
|
256D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000025.00000002.1499226549.000000000256D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
37
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
256D000
|
Size: |
12288
|
|
2FBE000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1364307904.0000000002FBE000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2FBE000
|
Size: |
8192
|
|
2A90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3743175571.0000000002A90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A90000
|
Size: |
65536
|
|
3370000
|
heap
|
page read and write
|
|
|
|
Name: |
00000027.00000002.1500718494.0000000003370000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
39
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3370000
|
Size: |
4096
|
|
7B90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1487487585.0000000007B90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7B90000
|
Size: |
4096
|
|
CA8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000032.00000002.1898903847.0000000000CA8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
50
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CA8000
|
Size: |
98304
|
|
3345000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1364492363.0000000003345000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3345000
|
Size: |
12288
|
|
2A1A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3742990995.0000000002A1A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2A1A000
|
Size: |
24576
|
|
894C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1493627402.000000000894C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
894C000
|
Size: |
241664
|
|
5310000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
0000002A.00000002.1546624084.0000000005310000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
42
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
5310000
|
Size: |
4096
|
|
62EE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1432686079.00000000062EE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
62EE000
|
Size: |
8192
|
|
A00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000029.00000002.1533413989.0000000000A00000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
41
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A00000
|
Size: |
4096
|
|
5F0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000029.00000000.1519058485.00000000005F0000.00000002.00000001.01000000.00000009.sdmp
|
TargetID: |
41
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
5F0000
|
Size: |
4096
|
|
E6E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000029.00000002.1545157565.0000000000E6E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
41
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
E6E000
|
Size: |
8192
|
|
509D000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1366459056.000000000509D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
509D000
|
Size: |
12288
|
|
1040000
|
heap
|
page read and write
|
|
|
|
Name: |
0000002A.00000002.1534238279.0000000001040000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
42
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1040000
|
Size: |
8192
|
|
1060000
|
heap
|
page read and write
|
|
|
|
Name: |
0000002A.00000002.1534553767.0000000001060000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
42
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1060000
|
Size: |
4096
|
|
495D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000029.00000002.1545589090.000000000495D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
41
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
495D000
|
Size: |
12288
|
|
5150000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3748935257.0000000005150000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5150000
|
Size: |
65536
|
|
6169000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1432686079.0000000006169000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6169000
|
Size: |
184320
|
|
5160000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3749002809.0000000005160000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5160000
|
Size: |
36864
|
|
36C0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1365372955.00000000036C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
36C0000
|
Size: |
32768
|
|
C07000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000029.00000002.1535159545.0000000000C07000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
41
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
C07000
|
Size: |
4096
|
|
2D40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000002F.00000002.1703859497.0000000002D40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
47
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D40000
|
Size: |
4096
|
|
63AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3749924275.00000000063AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
63AE000
|
Size: |
8192
|
|
1320000
|
heap
|
page read and write
|
|
|
|
Name: |
0000002F.00000002.1702843106.0000000001320000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
47
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1320000
|
Size: |
8192
|
|
7B7E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1487261290.0000000007B7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7B7E000
|
Size: |
8192
|
|
34D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000027.00000002.1500892305.00000000034D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
39
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
34D0000
|
Size: |
4096
|
|
580A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3749566473.000000000580A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
580A000
|
Size: |
24576
|
|
DD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1293101047.0000000000DD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DD0000
|
Size: |
4096
|
|
7D20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1489264795.0000000007D20000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D20000
|
Size: |
65536
|
|
763D000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1455891953.000000000763D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
763D000
|
Size: |
12288
|
|
3690000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1365191966.0000000003690000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3690000
|
Size: |
4096
|
|
4D88000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1365845263.0000000004D88000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4D88000
|
Size: |
12288
|
|
548E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3749433165.000000000548E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
548E000
|
Size: |
8192
|
|
EA4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000032.00000002.1899731706.0000000000EA4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
50
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
EA4000
|
Size: |
4096
|
|
3950000
|
heap
|
page read and write
|
|
|
|
Name: |
00000027.00000002.1501479759.0000000003950000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
39
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3950000
|
Size: |
12288
|
|
C30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000029.00000002.1535264260.0000000000C30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
41
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C30000
|
Size: |
24576
|
|
7BDE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1487552041.0000000007BDE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7BDE000
|
Size: |
8192
|
|
1304000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000002D.00000002.1607721182.0000000001304000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
45
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1304000
|
Size: |
8192
|
|
50B5000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.1366520016.00000000050B5000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
50B5000
|
Size: |
8192
|
|
1260000
|
heap
|
page read and write
|
|
|
|
Name: |
0000002A.00000002.1545421343.0000000001260000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
42
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1260000
|
Size: |
8192
|
|
3689000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1365012824.0000000003689000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3689000
|
Size: |
16384
|
|
1177000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3742937129.0000000001177000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1177000
|
Size: |
8192
|
|
2A80000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3743156677.0000000002A80000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
2A80000
|
Size: |
4096
|
|
2AF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000025.00000002.1499439748.0000000002AF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
37
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AF0000
|
Size: |
40960
|
|
142F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1295358246.000000000142F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
142F000
|
Size: |
4096
|
|
2D24000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000002F.00000002.1703732416.0000000002D24000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
47
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D24000
|
Size: |
8192
|
|
36A5000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.1365333990.00000000036A5000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
36A5000
|
Size: |
45056
|
|
EB6000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3741913982.0000000000EB6000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
EB6000
|
Size: |
8192
|
|
5139000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3748759482.0000000005139000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5139000
|
Size: |
28672
|
|
2DC0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000002F.00000002.1704448097.0000000002DC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
47
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC0000
|
Size: |
4096
|
|
10A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000032.00000002.1900084159.00000000010A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
50
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
10A0000
|
Size: |
65536
|
|
5FE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000029.00000000.1519232132.00000000005FE000.00000002.00000001.01000000.00000009.sdmp
|
TargetID: |
41
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
5FE000
|
Size: |
4096
|
|
786E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1459178005.000000000786E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
786E000
|
Size: |
8192
|
|
79D2000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1475437609.00000000079D2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
79D2000
|
Size: |
4096
|
|
51CE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000002A.00000002.1546353286.00000000051CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
42
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
51CE000
|
Size: |
8192
|
|
2D1D000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000002F.00000002.1703699551.0000000002D1D000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
47
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
2D1D000
|
Size: |
4096
|
|
887E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1491401993.000000000887E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
887E000
|
Size: |
8192
|
|
12AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1294925290.00000000012AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
12AE000
|
Size: |
8192
|
|
BFC000
|
stack
|
page read and write
|
|
|
|
Name: |
0000002D.00000002.1606026903.0000000000BFC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
45
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BFC000
|
Size: |
16384
|
|
3675000
|
heap
|
page read and write
|
|
|
|
Name: |
00000027.00000003.1500217587.0000000003675000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
39
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3675000
|
Size: |
4096
|
|
2910000
|
heap
|
page read and write
|
|
|
|
Name: |
00000025.00000002.1499356026.0000000002910000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
37
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2910000
|
Size: |
24576
|
|
70410000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.1495438843.0000000070410000.00000002.00000001.01000000.00000007.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
70410000
|
Size: |
4096
|
|
75FE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1455762604.00000000075FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
75FE000
|
Size: |
8192
|
|
1110000
|
heap
|
page read and write
|
|
|
|
Name: |
00000032.00000002.1900234806.0000000001110000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
50
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1110000
|
Size: |
8192
|
|
6947000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3750190430.0000000006947000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6947000
|
Size: |
200704
|
|
799B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1464831316.000000000799B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
799B000
|
Size: |
4096
|
|