AAA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2976095151.0000000000AAA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AAA000
|
Size: |
8192
|
|
EF6000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.1712420604.0000000000EF6000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
EF6000
|
Size: |
20480
|
|
EB1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000000.1712356012.0000000000EB1000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
EB1000
|
Size: |
270336
|
|
EB0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1712334918.0000000000EB0000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
EB0000
|
Size: |
4096
|
|
59C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2976012608.000000000059C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
59C000
|
Size: |
16384
|
|
EF3000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1712402515.0000000000EF3000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
EF3000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
LummaC encrypted strings found |
HIPS / PFW / Operating System Protection Evasion |
Deobfuscate/Decode Files or Information
|
|
EB1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000002.2976236299.0000000000EB1000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
EB1000
|
Size: |
270336
|
|
EB0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.2976216329.0000000000EB0000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
EB0000
|
Size: |
4096
|
|
AC4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2976095151.0000000000AC4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AC4000
|
Size: |
8192
|
|
F04000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1712439117.0000000000F04000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F04000
|
Size: |
16384
|
|
EFA000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2976324513.0000000000EFA000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
EFA000
|
Size: |
4096
|
|
EF3000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.2976280242.0000000000EF3000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
EF3000
|
Size: |
12288
|
|
AAE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2976095151.0000000000AAE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AAE000
|
Size: |
77824
|
|
5F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2976033753.00000000005F0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5F0000
|
Size: |
4096
|
|
ACA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2976095151.0000000000ACA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
ACA000
|
Size: |
315392
|
|
49C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2975982341.000000000049C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
49C000
|
Size: |
16384
|
|
EF6000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000002.2976300244.0000000000EF6000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
EF6000
|
Size: |
16384
|
|
F04000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.2976347521.0000000000F04000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F04000
|
Size: |
16384
|
|
AA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2976095151.0000000000AA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AA0000
|
Size: |
32768
|
|
970000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2976078005.0000000000970000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
970000
|
Size: |
20480
|
|
8D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2976059366.00000000008D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8D0000
|
Size: |
4096
|
|