7fff0d484000
|
|
page read and write
|
|
|
|
Name: |
5424.1.00007fff0d463000.00007fff0d484000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7fff0d484000
|
Size: |
135168
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
7f0781077000
|
|
page read and write
|
|
|
|
Name: |
5424.1.00007f0781075000.00007f0781077000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f0781077000
|
Size: |
8192
|
|
55d933f27000
|
|
page execute and read and write
|
|
|
|
Name: |
5424.1.000055d931f29000.000055d933f27000.rwx.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page execute and read and write
|
Base address: |
55d933f27000
|
Size: |
33546240
|
|
7f07816ba000
|
|
page read and write
|
|
|
|
Name: |
5424.1.00007f07816b8000.00007f07816ba000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f07816ba000
|
Size: |
8192
|
|
55d931c95000
|
|
page execute read
|
|
|
|
Name: |
5424.1.000055d931a6a000.000055d931c95000.r-x.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page execute read
|
Base address: |
55d931c95000
|
Size: |
2273280
|
|
5f2000
|
|
page read and write
|
|
|
|
Name: |
5424.1.00000000005b2000.00000000005f2000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
5f2000
|
Size: |
262144
|
|
31f000
|
|
page execute read
|
|
|
|
Name: |
5424.1.0000000000010000.000000000031f000.r-x.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page execute read
|
Base address: |
31f000
|
Size: |
3207168
|
|
7f07813a8000
|
|
page read and write
|
|
|
|
Name: |
5424.1.00007f07813a5000.00007f07813a8000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f07813a8000
|
Size: |
12288
|
|
55d933f3e000
|
|
page read and write
|
|
|
|
Name: |
5424.1.000055d933f28000.000055d933f3e000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
55d933f3e000
|
Size: |
90112
|
|
7f07801d0000
|
|
page read and write
|
|
|
|
Name: |
5424.1.00007f078014f000.00007f07801d0000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f07801d0000
|
Size: |
528384
|
|
7f0781037000
|
|
page read and write
|
|
|
|
Name: |
5424.1.00007f0781033000.00007f0781037000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f0781037000
|
Size: |
16384
|
|
7fff0d504000
|
|
page execute read
|
|
|
|
Name: |
5424.1.00007fff0d503000.00007fff0d504000.r-x.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page execute read
|
Base address: |
7fff0d504000
|
Size: |
4096
|
|
4000801000
|
|
page read and write
|
|
|
|
Name: |
5424.1.0000004000001000.0000004000801000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
4000801000
|
Size: |
8388608
|
|
7f07816b2000
|
|
page read and write
|
|
|
|
Name: |
5424.1.00007f07816b1000.00007f07816b2000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f07816b2000
|
Size: |
4096
|
|
7f0781589000
|
|
page read and write
|
|
|
|
Name: |
5424.1.00007f0781587000.00007f0781589000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f0781589000
|
Size: |
8192
|
|
55d935e16000
|
|
page read and write
|
|
|
|
Name: |
5424.1.000055d935d90000.000055d935e16000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
55d935e16000
|
Size: |
548864
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
5b2000
|
|
page read and write
|
|
|
|
Name: |
5424.1.0000000000570000.00000000005b2000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
5b2000
|
Size: |
270336
|
|
7f07809d8000
|
|
page read and write
|
|
|
|
Name: |
5424.1.00007f07801d1000.00007f07809d8000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f07809d8000
|
Size: |
8417280
|
|
55d931f1e000
|
|
page read and write
|
|
|
|
Name: |
5424.1.000055d931ef4000.000055d931f1e000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
55d931f1e000
|
Size: |
172032
|
|
7f077c021000
|
|
page read and write
|
|
|
|
Name: |
5424.1.00007f077c000000.00007f077c021000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f077c021000
|
Size: |
135168
|
|
7f07809e6000
|
|
page read and write
|
|
|
|
Name: |
5424.1.00007f07809e4000.00007f07809e6000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f07809e6000
|
Size: |
8192
|
|
7f078105a000
|
|
page read and write
|
|
|
|
Name: |
5424.1.00007f0781056000.00007f078105a000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f078105a000
|
Size: |
16384
|
|
55d931f29000
|
|
page read and write
|
|
|
|
Name: |
5424.1.000055d931f1e000.000055d931f29000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
55d931f29000
|
Size: |
45056
|
|
7f07816ff000
|
|
page read and write
|
|
|
|
Name: |
5424.1.00007f07816fe000.00007f07816ff000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f07816ff000
|
Size: |
4096
|
|
7f0780c96000
|
|
page read and write
|
|
|
|
Name: |
5424.1.00007f0780c94000.00007f0780c96000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f0780c96000
|
Size: |
8192
|
|