17D00227000
|
trusted library allocation
|
page read and write
|
![malicious](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABwAAAAYCAYAAADpnJ2CAAAAGXRFWHRTb2Z0d2FyZQBBZG9iZSBJbWFnZVJlYWR5ccllPAAAAppJREFUeNqsVkFoU0EQnZ/W2haM0R71kIAe4sWKB70ULLSei3oRBI13bXMQD1rSoD3b1LuNIPQiGgQvWjDgxR5EvZiDQnOoRzV80dRqrPOWP5/9m92ftOnAsvt358/beTOzux455Gv6yBx3BdqZFEfqn+dsC54DLM3dO24p2rlkGLRuTiYcyvdcYInDh6xjhw3qCMjeneFuyqY8ePUK7b1wPvweODup5hwyFdjq6KF1Z8nlR9SXzVJzYTGc23hQVnNYc8hSbAx5RzMuwINrn+hb5ihtd40lz7FcaPOQwVI9ZGWcFALbbZQWusnKPadPKQrRMO5CUjprXuDdaFAGTgFtiBmS5N/6lzBLfz9+wol0Lo5SkRNM7ftEXKLoXkmWbvk+/bpzl37euKnGANN1OpWJx96hBJ66gIamr1F/d9TR3zer1Czdpz/cOyQHwDUepM3iHpq+rnYPL7b8H5Eih1EINiMCmr3kPm5JRXOztBhSr0ndetKkXlcVGH5sjI3zj+tM43wA7qtaRJNvrEEHuhJT2LCepTZKD3x4S/7FS9T6WIvUGbwcnr1N/ceyCqjFHiCe8ESvRejtf/6Mvh8/2UZpgjOnwoPIdjZfrIRgIsOzt4LjbEIZ7GNQjPU1nV7YMKTKWGWhNB8J/mo06IiZ0KRvBIaFfomry4ZgeNpJg7SdUZMceFAW4Z7nYHhgciLMWmTl5ssVFTebvjZXZu9y5klT5NbAwPxZ4iJgWId3GKs5ptcUzUZDZ9B5eKPIcRO0ajXVS4lsLD1UJ47oDOYuh6UguuhFxzy8Pct9iCNu1KxHV2110KkzWCb2iRFcmq926aYYZ8Bq7AUcKFR2AaxigsW9afKSQD1Ivqs3TeAlXlulHsCKthcb5L8AAwCehEsTSl88KQAAAABJRU5ErkJggg==) |
|
|
Name: |
00000000.00000002.2171350376.0000017D00227000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
17D00227000
|
Size: |
2236416
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected XWorm |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara signature match |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
402000
|
remote allocation
|
page execute and read and write
|
![malicious](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABwAAAAYCAYAAADpnJ2CAAAAGXRFWHRTb2Z0d2FyZQBBZG9iZSBJbWFnZVJlYWR5ccllPAAAAppJREFUeNqsVkFoU0EQnZ/W2haM0R71kIAe4sWKB70ULLSei3oRBI13bXMQD1rSoD3b1LuNIPQiGgQvWjDgxR5EvZiDQnOoRzV80dRqrPOWP5/9m92ftOnAsvt358/beTOzux455Gv6yBx3BdqZFEfqn+dsC54DLM3dO24p2rlkGLRuTiYcyvdcYInDh6xjhw3qCMjeneFuyqY8ePUK7b1wPvweODup5hwyFdjq6KF1Z8nlR9SXzVJzYTGc23hQVnNYc8hSbAx5RzMuwINrn+hb5ihtd40lz7FcaPOQwVI9ZGWcFALbbZQWusnKPadPKQrRMO5CUjprXuDdaFAGTgFtiBmS5N/6lzBLfz9+wol0Lo5SkRNM7ftEXKLoXkmWbvk+/bpzl37euKnGANN1OpWJx96hBJ66gIamr1F/d9TR3zer1Czdpz/cOyQHwDUepM3iHpq+rnYPL7b8H5Eih1EINiMCmr3kPm5JRXOztBhSr0ndetKkXlcVGH5sjI3zj+tM43wA7qtaRJNvrEEHuhJT2LCepTZKD3x4S/7FS9T6WIvUGbwcnr1N/ceyCqjFHiCe8ESvRejtf/6Mvh8/2UZpgjOnwoPIdjZfrIRgIsOzt4LjbEIZ7GNQjPU1nV7YMKTKWGWhNB8J/mo06IiZ0KRvBIaFfomry4ZgeNpJg7SdUZMceFAW4Z7nYHhgciLMWmTl5ssVFTebvjZXZu9y5klT5NbAwPxZ4iJgWId3GKs5ptcUzUZDZ9B5eKPIcRO0ajXVS4lsLD1UJ47oDOYuh6UguuhFxzy8Pct9iCNu1KxHV2110KkzWCb2iRFcmq926aYYZ8Bq7AUcKFR2AaxigsW9afKSQD1Ivqs3TeAlXlulHsCKthcb5L8AAwCehEsTSl88KQAAAABJRU5ErkJggg==) |
|
|
Name: |
00000005.00000002.4595386745.0000000000402000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
402000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected XWorm |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara signature match |
System Summary |
|
|
2861000
|
trusted library allocation
|
page read and write
|
![malicious](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABwAAAAYCAYAAADpnJ2CAAAAGXRFWHRTb2Z0d2FyZQBBZG9iZSBJbWFnZVJlYWR5ccllPAAAAppJREFUeNqsVkFoU0EQnZ/W2haM0R71kIAe4sWKB70ULLSei3oRBI13bXMQD1rSoD3b1LuNIPQiGgQvWjDgxR5EvZiDQnOoRzV80dRqrPOWP5/9m92ftOnAsvt358/beTOzux455Gv6yBx3BdqZFEfqn+dsC54DLM3dO24p2rlkGLRuTiYcyvdcYInDh6xjhw3qCMjeneFuyqY8ePUK7b1wPvweODup5hwyFdjq6KF1Z8nlR9SXzVJzYTGc23hQVnNYc8hSbAx5RzMuwINrn+hb5ihtd40lz7FcaPOQwVI9ZGWcFALbbZQWusnKPadPKQrRMO5CUjprXuDdaFAGTgFtiBmS5N/6lzBLfz9+wol0Lo5SkRNM7ftEXKLoXkmWbvk+/bpzl37euKnGANN1OpWJx96hBJ66gIamr1F/d9TR3zer1Czdpz/cOyQHwDUepM3iHpq+rnYPL7b8H5Eih1EINiMCmr3kPm5JRXOztBhSr0ndetKkXlcVGH5sjI3zj+tM43wA7qtaRJNvrEEHuhJT2LCepTZKD3x4S/7FS9T6WIvUGbwcnr1N/ceyCqjFHiCe8ESvRejtf/6Mvh8/2UZpgjOnwoPIdjZfrIRgIsOzt4LjbEIZ7GNQjPU1nV7YMKTKWGWhNB8J/mo06IiZ0KRvBIaFfomry4ZgeNpJg7SdUZMceFAW4Z7nYHhgciLMWmTl5ssVFTebvjZXZu9y5klT5NbAwPxZ4iJgWId3GKs5ptcUzUZDZ9B5eKPIcRO0ajXVS4lsLD1UJ47oDOYuh6UguuhFxzy8Pct9iCNu1KxHV2110KkzWCb2iRFcmq926aYYZ8Bq7AUcKFR2AaxigsW9afKSQD1Ivqs3TeAlXlulHsCKthcb5L8AAwCehEsTSl88KQAAAABJRU5ErkJggg==) |
|
|
Name: |
00000005.00000002.4597786659.0000000002861000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2861000
|
Size: |
217088
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected XWorm |
Stealing of Sensitive Information, Remote Access Functionality |
|
URLs found in memory or binary data |
Networking |
|
|
17D0045A000
|
trusted library allocation
|
page read and write
|
![malicious](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABwAAAAYCAYAAADpnJ2CAAAAGXRFWHRTb2Z0d2FyZQBBZG9iZSBJbWFnZVJlYWR5ccllPAAAAppJREFUeNqsVkFoU0EQnZ/W2haM0R71kIAe4sWKB70ULLSei3oRBI13bXMQD1rSoD3b1LuNIPQiGgQvWjDgxR5EvZiDQnOoRzV80dRqrPOWP5/9m92ftOnAsvt358/beTOzux455Gv6yBx3BdqZFEfqn+dsC54DLM3dO24p2rlkGLRuTiYcyvdcYInDh6xjhw3qCMjeneFuyqY8ePUK7b1wPvweODup5hwyFdjq6KF1Z8nlR9SXzVJzYTGc23hQVnNYc8hSbAx5RzMuwINrn+hb5ihtd40lz7FcaPOQwVI9ZGWcFALbbZQWusnKPadPKQrRMO5CUjprXuDdaFAGTgFtiBmS5N/6lzBLfz9+wol0Lo5SkRNM7ftEXKLoXkmWbvk+/bpzl37euKnGANN1OpWJx96hBJ66gIamr1F/d9TR3zer1Czdpz/cOyQHwDUepM3iHpq+rnYPL7b8H5Eih1EINiMCmr3kPm5JRXOztBhSr0ndetKkXlcVGH5sjI3zj+tM43wA7qtaRJNvrEEHuhJT2LCepTZKD3x4S/7FS9T6WIvUGbwcnr1N/ceyCqjFHiCe8ESvRejtf/6Mvh8/2UZpgjOnwoPIdjZfrIRgIsOzt4LjbEIZ7GNQjPU1nV7YMKTKWGWhNB8J/mo06IiZ0KRvBIaFfomry4ZgeNpJg7SdUZMceFAW4Z7nYHhgciLMWmTl5ssVFTebvjZXZu9y5klT5NbAwPxZ4iJgWId3GKs5ptcUzUZDZ9B5eKPIcRO0ajXVS4lsLD1UJ47oDOYuh6UguuhFxzy8Pct9iCNu1KxHV2110KkzWCb2iRFcmq926aYYZ8Bq7AUcKFR2AaxigsW9afKSQD1Ivqs3TeAlXlulHsCKthcb5L8AAwCehEsTSl88KQAAAABJRU5ErkJggg==) |
|
|
Name: |
00000000.00000002.2171350376.0000017D0045A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
17D0045A000
|
Size: |
8994816
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected XWorm |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara signature match |
System Summary |
|
|
17D00CEF000
|
trusted library allocation
|
page read and write
|
![malicious](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABwAAAAYCAYAAADpnJ2CAAAAGXRFWHRTb2Z0d2FyZQBBZG9iZSBJbWFnZVJlYWR5ccllPAAAAppJREFUeNqsVkFoU0EQnZ/W2haM0R71kIAe4sWKB70ULLSei3oRBI13bXMQD1rSoD3b1LuNIPQiGgQvWjDgxR5EvZiDQnOoRzV80dRqrPOWP5/9m92ftOnAsvt358/beTOzux455Gv6yBx3BdqZFEfqn+dsC54DLM3dO24p2rlkGLRuTiYcyvdcYInDh6xjhw3qCMjeneFuyqY8ePUK7b1wPvweODup5hwyFdjq6KF1Z8nlR9SXzVJzYTGc23hQVnNYc8hSbAx5RzMuwINrn+hb5ihtd40lz7FcaPOQwVI9ZGWcFALbbZQWusnKPadPKQrRMO5CUjprXuDdaFAGTgFtiBmS5N/6lzBLfz9+wol0Lo5SkRNM7ftEXKLoXkmWbvk+/bpzl37euKnGANN1OpWJx96hBJ66gIamr1F/d9TR3zer1Czdpz/cOyQHwDUepM3iHpq+rnYPL7b8H5Eih1EINiMCmr3kPm5JRXOztBhSr0ndetKkXlcVGH5sjI3zj+tM43wA7qtaRJNvrEEHuhJT2LCepTZKD3x4S/7FS9T6WIvUGbwcnr1N/ceyCqjFHiCe8ESvRejtf/6Mvh8/2UZpgjOnwoPIdjZfrIRgIsOzt4LjbEIZ7GNQjPU1nV7YMKTKWGWhNB8J/mo06IiZ0KRvBIaFfomry4ZgeNpJg7SdUZMceFAW4Z7nYHhgciLMWmTl5ssVFTebvjZXZu9y5klT5NbAwPxZ4iJgWId3GKs5ptcUzUZDZ9B5eKPIcRO0ajXVS4lsLD1UJ47oDOYuh6UguuhFxzy8Pct9iCNu1KxHV2110KkzWCb2iRFcmq926aYYZ8Bq7AUcKFR2AaxigsW9afKSQD1Ivqs3TeAlXlulHsCKthcb5L8AAwCehEsTSl88KQAAAABJRU5ErkJggg==) |
|
|
Name: |
00000000.00000002.2171350376.0000017D00CEF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
17D00CEF000
|
Size: |
6053888
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected XWorm |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara signature match |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
7FFD34A20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2208879558.00007FFD34A20000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFD34A20000
|
Size: |
65536
|
|
17D7B58C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2202278077.0000017D7B58C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17D7B58C000
|
Size: |
12288
|
|
7FFD34A70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2209790771.00007FFD34A70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFD34A70000
|
Size: |
65536
|
|
BA1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4595766092.0000000000BA1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BA1000
|
Size: |
40960
|
|
C6B000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.4597140745.0000000000C6B000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
C6B000
|
Size: |
4096
|
|
2750000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.4597737049.0000000002750000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
2750000
|
Size: |
4096
|
|
4EBC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4604296310.0000000004EBC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4EBC000
|
Size: |
16384
|
|
5E9C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4605172986.0000000005E9C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5E9C000
|
Size: |
16384
|
|
6BDC47E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2170805588.0000006BDC47E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6BDC47E000
|
Size: |
8192
|
|
4D40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4604217891.0000000004D40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D40000
|
Size: |
32768
|
|
17D7B8E6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2204173448.0000017D7B8E6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17D7B8E6000
|
Size: |
8192
|
|
BCA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4595766092.0000000000BCA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BCA000
|
Size: |
49152
|
|
17D7B020000
|
heap
|
page readonly
|
|
|
|
Name: |
00000000.00000002.2199828411.0000017D7B020000.00000002.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page readonly
|
Base address: |
17D7B020000
|
Size: |
4096
|
|
17D013D8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2171350376.0000017D013D8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
17D013D8000
|
Size: |
1642496
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
BD7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4595766092.0000000000BD7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BD7000
|
Size: |
98304
|
|
7FFD34941000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2206529810.00007FFD34941000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFD34941000
|
Size: |
32768
|
|
5F9E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4605205284.0000000005F9E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5F9E000
|
Size: |
8192
|
|
17D012BA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2171350376.0000017D012BA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
17D012BA000
|
Size: |
184320
|
|
613C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4605326870.000000000613C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
613C000
|
Size: |
16384
|
|
545E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4604638481.000000000545E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
545E000
|
Size: |
8192
|
|
17D012E9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2171350376.0000017D012E9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
17D012E9000
|
Size: |
974848
|
|
17D00001000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2171350376.0000017D00001000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
17D00001000
|
Size: |
532480
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
7FFD34846000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2205796577.00007FFD34846000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFD34846000
|
Size: |
24576
|
|
6BDC5FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2170891320.0000006BDC5FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6BDC5FE000
|
Size: |
8192
|
|
17D7B4FC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2200173851.0000017D7B4FC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17D7B4FC000
|
Size: |
315392
|
|
3861000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4604122464.0000000003861000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3861000
|
Size: |
20480
|
|
531E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4604597914.000000000531E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
531E000
|
Size: |
8192
|
|
6BDC93E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2171134087.0000006BDC93E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6BDC93E000
|
Size: |
8192
|
|
83B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4595487345.000000000083B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
83B000
|
Size: |
20480
|
|
7FFD34975000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2206882180.00007FFD34975000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFD34975000
|
Size: |
20480
|
|
B1E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4595766092.0000000000B1E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B1E000
|
Size: |
49152
|
|
17D7AFE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2199767707.0000017D7AFE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
17D7AFE0000
|
Size: |
4096
|
|
541E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4604618839.000000000541E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
541E000
|
Size: |
8192
|
|
7FFD34980000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.2207149711.00007FFD34980000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7FFD34980000
|
Size: |
12288
|
|
17D79662000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2198509821.0000017D79662000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17D79662000
|
Size: |
20480
|
|
49FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4604195983.00000000049FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
49FE000
|
Size: |
8192
|
|
EC0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.4597295569.0000000000EC0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
EC0000
|
Size: |
65536
|
|
6BDC57F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2170862205.0000006BDC57F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6BDC57F000
|
Size: |
4096
|
|
17D7B8E3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2204173448.0000017D7B8E3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17D7B8E3000
|
Size: |
4096
|
|
17D7B5A7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2202618381.0000017D7B5A7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17D7B5A7000
|
Size: |
983040
|
|
5710000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4604823053.0000000005710000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5710000
|
Size: |
8192
|
|
E9E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4597253268.0000000000E9E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
E9E000
|
Size: |
8192
|
|
285E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4597759080.000000000285E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
285E000
|
Size: |
8192
|
|
B7C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4595766092.0000000000B7C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B7C000
|
Size: |
131072
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
599E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4604930287.000000000599E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
599E000
|
Size: |
8192
|
|
C5A000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.4597101047.0000000000C5A000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
C5A000
|
Size: |
4096
|
|
2720000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4597647774.0000000002720000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2720000
|
Size: |
65536
|
|
7FFD34792000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2205212713.00007FFD34792000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFD34792000
|
Size: |
4096
|
|
7FFD34950000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.2206663389.00007FFD34950000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7FFD34950000
|
Size: |
20480
|
|
7FFD34AE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2211262274.00007FFD34AE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFD34AE0000
|
Size: |
24576
|
|
B2B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4595766092.0000000000B2B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B2B000
|
Size: |
32768
|
|
6BDC8BA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2171108229.0000006BDC8BA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6BDC8BA000
|
Size: |
24576
|
|
ED0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4597371415.0000000000ED0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
ED0000
|
Size: |
20480
|
|
60F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4605270172.00000000060F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60F0000
|
Size: |
16384
|
|
17D7968C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2198509821.0000017D7968C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17D7968C000
|
Size: |
8192
|
|
6275000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4605377883.0000000006275000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6275000
|
Size: |
36864
|
|
C43000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4596966622.0000000000C43000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
C43000
|
Size: |
40960
|
|
5670000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4604680999.0000000005670000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5670000
|
Size: |
4096
|
|
C90000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4597179958.0000000000C90000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C90000
|
Size: |
16384
|
|
17D7B850000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.2204112547.0000017D7B850000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
17D7B850000
|
Size: |
4096
|
|
5C1D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4604984550.0000000005C1D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5C1D000
|
Size: |
12288
|
|
7FFD34AD7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2211090829.00007FFD34AD7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFD34AD7000
|
Size: |
4096
|
|
17D10236000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2191177841.0000017D10236000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
17D10236000
|
Size: |
2375680
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
7FFD3479D000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.2205485126.00007FFD3479D000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7FFD3479D000
|
Size: |
12288
|
|
17D7B747000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.2203951859.0000017D7B747000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
17D7B747000
|
Size: |
8192
|
|
17D7AFD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2199746102.0000017D7AFD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17D7AFD0000
|
Size: |
4096
|
|
6BDC2FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2170706714.0000006BDC2FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6BDC2FE000
|
Size: |
8192
|
|
7FFD34930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2206419419.00007FFD34930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFD34930000
|
Size: |
65536
|
|
2897000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4597786659.0000000002897000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2897000
|
Size: |
4268032
|
|
6BDC275000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2170641200.0000006BDC275000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6BDC275000
|
Size: |
45056
|
|
6BDCABE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2171219693.0000006BDCABE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6BDCABE000
|
Size: |
8192
|
|
7FFD34972000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2206882180.00007FFD34972000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFD34972000
|
Size: |
8192
|
|
B08000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4595766092.0000000000B08000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B08000
|
Size: |
86016
|
|
7FFD34850000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.2206037965.00007FFD34850000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7FFD34850000
|
Size: |
36864
|
|
6244000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4605377883.0000000006244000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6244000
|
Size: |
4096
|
|
17D1002A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2191177841.0000017D1002A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
17D1002A000
|
Size: |
262144
|
|
17D1006E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2191177841.0000017D1006E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
17D1006E000
|
Size: |
364544
|
|
6BDC839000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2171085815.0000006BDC839000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6BDC839000
|
Size: |
28672
|
|
7FFD34A60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2209505701.00007FFD34A60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFD34A60000
|
Size: |
65536
|
|
555E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4604661012.000000000555E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
555E000
|
Size: |
8192
|
|
5B1C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4604950809.0000000005B1C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5B1C000
|
Size: |
16384
|
|
17D7968A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2198509821.0000017D7968A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17D7968A000
|
Size: |
4096
|
|
7FFD349C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2207869971.00007FFD349C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFD349C0000
|
Size: |
65536
|
|
C30000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4596884996.0000000000C30000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
C30000
|
Size: |
4096
|
|
C97000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4597179958.0000000000C97000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C97000
|
Size: |
8192
|
|
7FFD34AF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2211310223.00007FFD34AF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFD34AF0000
|
Size: |
49152
|
|
3869000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4604122464.0000000003869000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3869000
|
Size: |
4096
|
|
17D00087000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2171350376.0000017D00087000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
17D00087000
|
Size: |
1675264
|
|
7FFD34A10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2208622682.00007FFD34A10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFD34A10000
|
Size: |
65536
|
|
7FFD34A00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2208451055.00007FFD34A00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFD34A00000
|
Size: |
65536
|
|
17D7B030000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2199853329.0000017D7B030000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
17D7B030000
|
Size: |
65536
|
|
17D10001000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2191177841.0000017D10001000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
17D10001000
|
Size: |
53248
|
|
C52000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4597060947.0000000000C52000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
C52000
|
Size: |
4096
|
|
595E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4604909002.000000000595E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
595E000
|
Size: |
8192
|
|
7FFD3494A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2206529810.00007FFD3494A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFD3494A000
|
Size: |
24576
|
|
D9F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4597233330.0000000000D9F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
D9F000
|
Size: |
4096
|
|
7FFD349E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2208230985.00007FFD349E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFD349E0000
|
Size: |
65536
|
|
7FFD34790000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2205212713.00007FFD34790000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFD34790000
|
Size: |
4096
|
|
C56000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.4597079153.0000000000C56000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
C56000
|
Size: |
8192
|
|
7FFD34AA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2210675847.00007FFD34AA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFD34AA0000
|
Size: |
65536
|
|
5219000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4604552417.0000000005219000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5219000
|
Size: |
28672
|
|
6BDC4FB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2170837838.0000006BDC4FB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6BDC4FB000
|
Size: |
20480
|
|
17D7B420000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2200072563.0000017D7B420000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
17D7B420000
|
Size: |
4096
|
|
56B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4604700313.00000000056B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
56B0000
|
Size: |
61440
|
|
17D795A8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2198509821.0000017D795A8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17D795A8000
|
Size: |
36864
|
|
17D02036000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2171350376.0000017D02036000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
17D02036000
|
Size: |
638976
|
|
C34000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4596925825.0000000000C34000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
C34000
|
Size: |
4096
|
|
17D7B564000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2202278077.0000017D7B564000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17D7B564000
|
Size: |
57344
|
|
60E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4605226323.00000000060E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60E0000
|
Size: |
32768
|
|
17D7B90B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2204863572.0000017D7B90B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17D7B90B000
|
Size: |
49152
|
|
7FFD349B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2207657547.00007FFD349B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFD349B0000
|
Size: |
65536
|
|
C40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4596966622.0000000000C40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
C40000
|
Size: |
8192
|
|
ED7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4597371415.0000000000ED7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
ED7000
|
Size: |
12288
|
|
7FFD349A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2207459089.00007FFD349A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFD349A0000
|
Size: |
65536
|
|
BF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4595766092.0000000000BF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BF0000
|
Size: |
32768
|
|
5700000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4604807072.0000000005700000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5700000
|
Size: |
4096
|
|
7FFD34A30000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2209017409.00007FFD34A30000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFD34A30000
|
Size: |
65536
|
|
C50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4597040277.0000000000C50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
C50000
|
Size: |
4096
|
|
7FFD34793000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.2205328616.00007FFD34793000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7FFD34793000
|
Size: |
4096
|
|
ABE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4595714114.0000000000ABE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
ABE000
|
Size: |
8192
|
|
17D0044E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2171350376.0000017D0044E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
17D0044E000
|
Size: |
20480
|
|
B3A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4595766092.0000000000B3A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B3A000
|
Size: |
4096
|
|
17D100C8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2191177841.0000017D100C8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
17D100C8000
|
Size: |
4096
|
|
B00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4595766092.0000000000B00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B00000
|
Size: |
24576
|
|
17D7B8F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2204173448.0000017D7B8F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17D7B8F1000
|
Size: |
20480
|
|
7F780000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.4605540739.000000007F780000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7F780000
|
Size: |
4096
|
|
17D0156C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2171350376.0000017D0156C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
17D0156C000
|
Size: |
802816
|
|
6BDCA3B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2171192897.0000006BDCA3B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6BDCA3B000
|
Size: |
20480
|
|
17D7B590000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2202586983.0000017D7B590000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17D7B590000
|
Size: |
4096
|
|
6BDC73F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2170977683.0000006BDC73F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6BDC73F000
|
Size: |
4096
|
|
17D7B075000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2199961249.0000017D7B075000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17D7B075000
|
Size: |
24576
|
|
17D7B490000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2200173851.0000017D7B490000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17D7B490000
|
Size: |
180224
|
|
7FFD34876000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.2206111672.00007FFD34876000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7FFD34876000
|
Size: |
69632
|
|
C33000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.4596905667.0000000000C33000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
C33000
|
Size: |
4096
|
|
7FFD34B00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2211434908.00007FFD34B00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFD34B00000
|
Size: |
4096
|
|
4ED0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4604347383.0000000004ED0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4ED0000
|
Size: |
4096
|
|
56FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4604784603.00000000056FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
56FE000
|
Size: |
8192
|
|
4F5E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4604437704.0000000004F5E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4F5E000
|
Size: |
8192
|
|
17D79690000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2198509821.0000017D79690000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17D79690000
|
Size: |
61440
|
|
B3C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4595766092.0000000000B3C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B3C000
|
Size: |
258048
|
|
591E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4604887327.000000000591E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
591E000
|
Size: |
8192
|
|
7FFD34A50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2209326578.00007FFD34A50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFD34A50000
|
Size: |
65536
|
|
58DD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4604861200.00000000058DD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
58DD000
|
Size: |
12288
|
|
7FFD349F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2208352642.00007FFD349F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFD349F0000
|
Size: |
65536
|
|
4ED3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4604347383.0000000004ED3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4ED3000
|
Size: |
8192
|
|
17D795A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2198509821.0000017D795A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17D795A0000
|
Size: |
28672
|
|
17D7B740000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.2203951859.0000017D7B740000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
17D7B740000
|
Size: |
20480
|
|
6BDC3FD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2170771981.0000006BDC3FD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6BDC3FD000
|
Size: |
12288
|
|
6BDCB3B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2171256861.0000006BDCB3B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6BDCB3B000
|
Size: |
20480
|
|
17D79905000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2199633096.0000017D79905000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17D79905000
|
Size: |
40960
|
|
7FFD34A80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2209956010.00007FFD34A80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFD34A80000
|
Size: |
65536
|
|
4F70000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.4604481859.0000000004F70000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
4F70000
|
Size: |
4096
|
|
A76000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4595650583.0000000000A76000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A76000
|
Size: |
12288
|
|
6BDC7B6000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2171061291.0000006BDC7B6000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6BDC7B6000
|
Size: |
40960
|
|
17D7B450000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2200072563.0000017D7B450000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
17D7B450000
|
Size: |
20480
|
|
6290000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4605477582.0000000006290000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6290000
|
Size: |
4096
|
|
6BDC9BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2171167725.0000006BDC9BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6BDC9BE000
|
Size: |
8192
|
|
970000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4595588871.0000000000970000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
970000
|
Size: |
4096
|
|
C3D000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.4596945750.0000000000C3D000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
C3D000
|
Size: |
4096
|
|
17D79648000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2198509821.0000017D79648000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17D79648000
|
Size: |
4096
|
|
17D79550000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2198424012.0000017D79550000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17D79550000
|
Size: |
16384
|
|
17D01636000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2171350376.0000017D01636000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
17D01636000
|
Size: |
10485760
|
|
17D7B880000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2204173448.0000017D7B880000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17D7B880000
|
Size: |
401408
|
|
17D7964E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2198509821.0000017D7964E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17D7964E000
|
Size: |
20480
|
|
7FFD34794000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2205349523.00007FFD34794000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFD34794000
|
Size: |
36864
|
|
17D79641000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2198509821.0000017D79641000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17D79641000
|
Size: |
8192
|
|
6281000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4605447324.0000000006281000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6281000
|
Size: |
16384
|
|
7FFD34990000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2207263022.00007FFD34990000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFD34990000
|
Size: |
65536
|
|
C67000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.4597118750.0000000000C67000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
C67000
|
Size: |
4096
|
|
17D7BAB0000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2204969982.0000017D7BAB0000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
17D7BAB0000
|
Size: |
65536
|
|
6BDC37E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2170743506.0000006BDC37E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6BDC37E000
|
Size: |
8192
|
|
6BDC6F8000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2170953751.0000006BDC6F8000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6BDC6F8000
|
Size: |
32768
|
|
17D795B2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2198509821.0000017D795B2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17D795B2000
|
Size: |
577536
|
|
7FFD34AD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2211090829.00007FFD34AD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFD34AD0000
|
Size: |
24576
|
|
6BDD58B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2171329880.0000006BDD58B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6BDD58B000
|
Size: |
20480
|
|
17D79540000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2198339996.0000017D79540000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17D79540000
|
Size: |
4096
|
|
2710000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4597511105.0000000002710000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2710000
|
Size: |
65536
|
|
17D7B010000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2199790204.0000017D7B010000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
17D7B010000
|
Size: |
12288
|
|
7FFD34840000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2205697906.00007FFD34840000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFD34840000
|
Size: |
8192
|
|
5D60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4605067818.0000000005D60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5D60000
|
Size: |
45056
|
|
4F1E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4604412141.0000000004F1E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4F1E000
|
Size: |
8192
|
|
7FFD34A90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2210230218.00007FFD34A90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFD34A90000
|
Size: |
65536
|
|
7FFD3484C000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.2205973119.00007FFD3484C000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7FFD3484C000
|
Size: |
12288
|
|
17D01632000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2171350376.0000017D01632000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
17D01632000
|
Size: |
8192
|
|
17D79570000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2198474413.0000017D79570000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17D79570000
|
Size: |
4096
|
|
7FFD34960000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.2206779209.00007FFD34960000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7FFD34960000
|
Size: |
4096
|
|
7DF455780000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.2205171767.00007DF455780000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7DF455780000
|
Size: |
4096
|
|
B9D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4595766092.0000000000B9D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B9D000
|
Size: |
4096
|
|
6BDC67D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2170926868.0000006BDC67D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6BDC67D000
|
Size: |
12288
|
|
5D6D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4605067818.0000000005D6D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5D6D000
|
Size: |
8192
|
|
270C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4597478378.000000000270C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
270C000
|
Size: |
16384
|
|
7FFD347A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2205542477.00007FFD347A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFD347A0000
|
Size: |
40960
|
|
6BDD50E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2171300971.0000006BDD50E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6BDD50E000
|
Size: |
8192
|
|
C20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4596850918.0000000000C20000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
C20000
|
Size: |
8192
|
|
BB6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4595766092.0000000000BB6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BB6000
|
Size: |
4096
|
|
17D7B770000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2204053288.0000017D7B770000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17D7B770000
|
Size: |
16384
|
|
7FFD3497B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2206882180.00007FFD3497B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFD3497B000
|
Size: |
20480
|
|
AFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4595740558.0000000000AFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
AFE000
|
Size: |
8192
|
|
BF9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4595766092.0000000000BF9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BF9000
|
Size: |
24576
|
|
17D7B410000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.2200050631.0000017D7B410000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
17D7B410000
|
Size: |
4096
|
|
7FFD347AB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2205542477.00007FFD347AB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFD347AB000
|
Size: |
4096
|
|
17D7B4BD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2200173851.0000017D7B4BD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17D7B4BD000
|
Size: |
253952
|
|
17D79644000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2198509821.0000017D79644000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17D79644000
|
Size: |
4096
|
|
A70000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4595650583.0000000000A70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A70000
|
Size: |
16384
|
|
17D10010000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2191177841.0000017D10010000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
17D10010000
|
Size: |
69632
|
|
938000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4595530493.0000000000938000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
938000
|
Size: |
32768
|
|
EA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4597275955.0000000000EA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EA0000
|
Size: |
4096
|
|
62D0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.4605493179.00000000062D0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
62D0000
|
Size: |
8192
|
|
17D79900000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2199633096.0000017D79900000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17D79900000
|
Size: |
16384
|
|
7FFD348B0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.2206282039.00007FFD348B0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7FFD348B0000
|
Size: |
98304
|
|
2CAA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4597786659.0000000002CAA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CAA000
|
Size: |
1105920
|
|
A50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4595618293.0000000000A50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A50000
|
Size: |
8192
|
|
17D100D6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2191177841.0000017D100D6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
17D100D6000
|
Size: |
1404928
|
|
26C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4597458764.00000000026C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
26C0000
|
Size: |
4096
|
|
C80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4597160713.0000000000C80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
C80000
|
Size: |
4096
|
|
511D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4604498745.000000000511D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
511D000
|
Size: |
12288
|
|
7FFD349D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2208060568.00007FFD349D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFD349D0000
|
Size: |
65536
|
|
5D5E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4605043966.0000000005D5E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5D5E000
|
Size: |
8192
|
|
17D7AF30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2199722559.0000017D7AF30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17D7AF30000
|
Size: |
4096
|
|
17D00456000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2171350376.0000017D00456000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
17D00456000
|
Size: |
12288
|
|
623D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4605355801.000000000623D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
623D000
|
Size: |
12288
|
|
400000
|
remote allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.4595386745.0000000000400000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
400000
|
Size: |
4096
|
|
7FFD34AC0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2210947962.00007FFD34AC0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFD34AC0000
|
Size: |
65536
|
|
4868000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4604178534.0000000004868000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4868000
|
Size: |
4096
|
|
26BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4597431616.00000000026BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
26BE000
|
Size: |
8192
|
|
17D0044A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2171350376.0000017D0044A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
17D0044A000
|
Size: |
12288
|
|
7FFD34A40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2209143951.00007FFD34A40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFD34A40000
|
Size: |
65536
|
|
60F9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4605270172.00000000060F9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60F9000
|
Size: |
16384
|
|
5C5C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4605009106.0000000005C5C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5C5C000
|
Size: |
16384
|
|
7FFD34AB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2210848153.00007FFD34AB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFD34AB0000
|
Size: |
12288
|
|
5D70000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4605067818.0000000005D70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5D70000
|
Size: |
12288
|
|
17D7BAC0000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2205095905.0000017D7BAC0000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
17D7BAC0000
|
Size: |
4096
|
|
17D7B070000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2199961249.0000017D7B070000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17D7B070000
|
Size: |
12288
|
|
589E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4604841701.000000000589E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
589E000
|
Size: |
8192
|
|
4E7E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.4604271662.0000000004E7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4E7E000
|
Size: |
8192
|
|
17D7B573000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2202278077.0000017D7B573000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17D7B573000
|
Size: |
98304
|
|