371000
|
unkown
|
page execute read
|
 |
|
|
Name: |
00000009.00000002.3365824204.0000000000371000.00000020.00000001.01000000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
371000
|
Size: |
217088
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected Amadeys stealer DLL |
Stealing of Sensitive Information |
|
Yara signature match |
System Summary |
|
|
5C70000
|
direct allocation
|
page read and write
|
 |
|
|
Name: |
00000004.00000002.2390701649.0000000005C70000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
5C70000
|
Size: |
339968
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Found malware configuration |
AV Detection |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected Amadeys stealer DLL |
Stealing of Sensitive Information |
|
Sample uses string decryption to hide its real strings |
AV Detection |
|
Yara signature match |
System Summary |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3BD000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000009.00000002.3365976757.00000000003BD000.00000008.00000001.01000000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
3BD000
|
Size: |
36864
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
8EE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3178747683.00000000008EE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EE000
|
Size: |
45056
|
|
8DD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3160660801.00000000008DD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DD000
|
Size: |
24576
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
13FC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2193532201.00000000013FC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13FC000
|
Size: |
24576
|
|
13FC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2192903515.00000000013FC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13FC000
|
Size: |
24576
|
|
8FE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3224355203.00000000008FE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FE000
|
Size: |
8192
|
|
1461000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2193731948.0000000001461000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1461000
|
Size: |
12288
|
|
8EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3119398938.00000000008EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EA000
|
Size: |
53248
|
|
2B70000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2389301409.0000000002B70000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2B70000
|
Size: |
32768
|
|
4C70000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2390018001.0000000004C70000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4C70000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
6C934000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2191072215.000000006C934000.00000002.00000001.01000000.0000000B.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
6C934000
|
Size: |
192512
|
|
8F7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3251532109.00000000008F7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F7000
|
Size: |
8192
|
|
8DB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3333767878.00000000008DB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DB000
|
Size: |
12288
|
|
8F6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3357007704.00000000008F6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F6000
|
Size: |
12288
|
|
8F7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3336565204.00000000008F7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F7000
|
Size: |
8192
|
|
140E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2188989902.000000000140E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
140E000
|
Size: |
8192
|
|
8D3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3349786515.00000000008D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8D3000
|
Size: |
12288
|
|
10FA000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2195415980.00000000010FA000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
10FA000
|
Size: |
8192
|
|
8EE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3223552497.00000000008EE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EE000
|
Size: |
45056
|
|
145C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2192254147.000000000145C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
145C000
|
Size: |
8192
|
|
8D8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3218204920.00000000008D8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8D8000
|
Size: |
12288
|
|
1103000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.2195500945.0000000001103000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1103000
|
Size: |
122880
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
FD1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000002.2195285176.0000000000FD1000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
FD1000
|
Size: |
901120
|
|
6E555000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2191450115.000000006E555000.00000004.00000001.01000000.0000000E.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
6E555000
|
Size: |
4096
|
|
850000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3366133731.0000000000850000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
850000
|
Size: |
24576
|
|
10AD000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.2112277735.00000000010AD000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
10AD000
|
Size: |
315392
|
|
17AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2193985286.00000000017AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
17AE000
|
Size: |
8192
|
|
8F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3271655162.00000000008F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F1000
|
Size: |
8192
|
|
8DC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3118148485.00000000008DC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DC000
|
Size: |
28672
|
|
924000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3333767878.0000000000924000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
924000
|
Size: |
4096
|
|
8CA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3277343022.00000000008CA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8CA000
|
Size: |
8192
|
|
8D9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3206914319.00000000008D9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8D9000
|
Size: |
4096
|
|
8F7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3118251855.00000000008F7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F7000
|
Size: |
12288
|
|
8E1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3287156807.00000000008E1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E1000
|
Size: |
16384
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3336080047.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
4096
|
|
F2C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2188865663.0000000000F2C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
F2C000
|
Size: |
16384
|
|
6C833000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000003.00000002.2190537492.000000006C833000.00000008.00000001.01000000.0000000F.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
6C833000
|
Size: |
36864
|
|
EAE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3367498510.0000000000EAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
EAE000
|
Size: |
8192
|
|
B4C000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000002.00000002.2193139705.0000000000B4C000.00000008.00000001.01000000.00000004.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
B4C000
|
Size: |
12288
|
|
493B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3367571436.000000000493B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
493B000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3275012624.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
4096
|
|
91C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3359698304.000000000091C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
91C000
|
Size: |
20480
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3353818349.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
4096
|
|
10AD000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.2195374865.00000000010AD000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
10AD000
|
Size: |
315392
|
|
B9B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3366626141.0000000000B9B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
B9B000
|
Size: |
626688
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
6C80D000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2190468444.000000006C80D000.00000002.00000001.01000000.0000000F.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
6C80D000
|
Size: |
12288
|
|
8D7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3217456927.00000000008D7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8D7000
|
Size: |
16384
|
|
496C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2389833724.000000000496C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
496C000
|
Size: |
16384
|
|
8F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3258828239.00000000008F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F1000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
8EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3218136592.00000000008EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EA000
|
Size: |
4096
|
|
589D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2390462106.000000000589D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
589D000
|
Size: |
458752
|
|
91D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3356712486.000000000091D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
91D000
|
Size: |
16384
|
|
8EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3349334097.00000000008EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EA000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4A5E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3367571436.0000000004A5E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4A5E000
|
Size: |
512000
|
|
A20000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000000.2116069331.0000000000A20000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
A20000
|
Size: |
4096
|
|
521F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2390097843.000000000521F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
521F000
|
Size: |
4096
|
|
8EE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3177622418.00000000008EE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EE000
|
Size: |
45056
|
|
918000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3353818349.0000000000918000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
918000
|
Size: |
12288
|
|
8BC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3300929834.00000000008BC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8BC000
|
Size: |
8192
|
|
8E9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3245092157.00000000008E9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E9000
|
Size: |
57344
|
|
14D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2193866323.00000000014D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14D0000
|
Size: |
16384
|
|
3BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2194984607.00000000003BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3BE000
|
Size: |
8192
|
|
8EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3116976956.00000000008EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EA000
|
Size: |
65536
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
8D7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3245119224.00000000008D7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8D7000
|
Size: |
28672
|
|
8F7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3120536170.00000000008F7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F7000
|
Size: |
12288
|
|
8E1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3330582235.00000000008E1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E1000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
8F5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3287156807.00000000008F5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F5000
|
Size: |
16384
|
|
6F7000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2195044865.00000000006F7000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6F7000
|
Size: |
4096
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3359463454.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
4096
|
|
6C87D000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000003.00000002.2190787333.000000006C87D000.00000008.00000001.01000000.0000000D.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
6C87D000
|
Size: |
86016
|
|
32DE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2189493372.00000000032DE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32DE000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
15D7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2189069192.00000000015D7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
15D7000
|
Size: |
163840
|
|
8E7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3300877880.00000000008E7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E7000
|
Size: |
12288
|
|
8D3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3132497975.00000000008D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8D3000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
8E6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3336080047.00000000008E6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E6000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4DB9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3367751694.0000000004DB9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4DB9000
|
Size: |
4096
|
|
4AB0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2389914085.0000000004AB0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4AB0000
|
Size: |
4096
|
|
EEF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3367520790.0000000000EEF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
EEF000
|
Size: |
4096
|
|
17E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2189215940.00000000017E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17E0000
|
Size: |
36864
|
|
91C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3336080047.000000000091C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
91C000
|
Size: |
36864
|
|
8E5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3366133731.00000000008E5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E5000
|
Size: |
61440
|
|
7D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2195083812.00000000007D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7D0000
|
Size: |
4096
|
|
488B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2194757810.000000000488B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
488B000
|
Size: |
20480
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3357007704.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
4096
|
|
8F8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3331326152.00000000008F8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F8000
|
Size: |
4096
|
|
8DC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3145351878.00000000008DC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DC000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
922000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3358870376.0000000000922000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
922000
|
Size: |
12288
|
|
2FC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3365740143.00000000002FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2FC000
|
Size: |
16384
|
|
4E2E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3367751694.0000000004E2E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4E2E000
|
Size: |
24576
|
|
F8B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2193232588.0000000000F8B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
F8B000
|
Size: |
20480
|
|
ADB000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000003.00000000.2135104715.0000000000ADB000.00000008.00000001.01000000.00000009.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
ADB000
|
Size: |
4096
|
|
2C27000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2389435788.0000000002C27000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C27000
|
Size: |
57344
|
|
1464000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.2137286758.0000000001464000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1464000
|
Size: |
8192
|
|
8DC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3109257898.00000000008DC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DC000
|
Size: |
16384
|
|
13DC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2192658569.00000000013DC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13DC000
|
Size: |
126976
|
|
8E9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3266142445.00000000008E9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E9000
|
Size: |
20480
|
|
8EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3349088987.00000000008EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EA000
|
Size: |
61440
|
|
922000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3359463454.0000000000922000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
922000
|
Size: |
12288
|
|
8CA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3300790093.00000000008CA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8CA000
|
Size: |
8192
|
|
6C7B0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2189999757.000000006C7B0000.00000002.00000001.01000000.0000000F.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
6C7B0000
|
Size: |
4096
|
|
1101000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.2195474167.0000000001101000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1101000
|
Size: |
4096
|
|
920000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3332561534.0000000000920000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
920000
|
Size: |
4096
|
|
6EAF4000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2191565293.000000006EAF4000.00000004.00000001.01000000.0000000C.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
6EAF4000
|
Size: |
4096
|
|
8FC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3204418097.00000000008FC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FC000
|
Size: |
20480
|
|
922000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3362221003.0000000000922000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
922000
|
Size: |
12288
|
|
531E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2390136652.000000000531E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
531E000
|
Size: |
8192
|
|
8EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3219058504.00000000008EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EA000
|
Size: |
12288
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3232658327.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
4096
|
|
3DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2191930496.0000000003DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3DD0000
|
Size: |
4096
|
|
6EAF5000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2191581894.000000006EAF5000.00000002.00000001.01000000.0000000C.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
6EAF5000
|
Size: |
8192
|
|
8EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3178617313.00000000008EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EA000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
C60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3367467035.0000000000C60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C60000
|
Size: |
53248
|
|
1465000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2189030351.0000000001465000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1465000
|
Size: |
4096
|
|
3050000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2389750563.0000000003050000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3050000
|
Size: |
20480
|
|
8DD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3162055219.00000000008DD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DD000
|
Size: |
24576
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
8FD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3119398938.00000000008FD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FD000
|
Size: |
8192
|
|
91E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3349334097.000000000091E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
91E000
|
Size: |
12288
|
|
8F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3268337946.00000000008F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F1000
|
Size: |
8192
|
|
8FC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3177556614.00000000008FC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FC000
|
Size: |
20480
|
|
178E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2189197103.000000000178E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
178E000
|
Size: |
8192
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3268874007.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
4096
|
|
10111000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2189975676.0000000010111000.00000002.00000001.01000000.00000010.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
10111000
|
Size: |
8192
|
|
1010F000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2189955628.000000001010F000.00000004.00000001.01000000.00000010.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1010F000
|
Size: |
8192
|
|
4AD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.2389191738.0000000004AD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4AD0000
|
Size: |
4096
|
|
A21000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000002.00000002.2192981518.0000000000A21000.00000020.00000001.01000000.00000004.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
A21000
|
Size: |
901120
|
|
8E9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3268562083.00000000008E9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E9000
|
Size: |
20480
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
8E9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3350095455.00000000008E9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E9000
|
Size: |
65536
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3268562083.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
4096
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3329858973.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
4096
|
|
5684000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2390348510.0000000005684000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5684000
|
Size: |
290816
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1380000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2193337695.0000000001380000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1380000
|
Size: |
8192
|
|
8D3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3331326152.00000000008D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8D3000
|
Size: |
45056
|
|
91A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3362221003.000000000091A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
91A000
|
Size: |
4096
|
|
8FD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3132474013.00000000008FD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FD000
|
Size: |
16384
|
|
8EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3217263957.00000000008EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EA000
|
Size: |
8192
|
|
8DC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3336080047.00000000008DC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DC000
|
Size: |
8192
|
|
8FE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3223614885.00000000008FE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FE000
|
Size: |
8192
|
|
91D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3357007704.000000000091D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
91D000
|
Size: |
16384
|
|
6C974000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000003.00000002.2191190874.000000006C974000.00000008.00000001.01000000.0000000B.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
6C974000
|
Size: |
176128
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
940000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2195147455.0000000000940000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
940000
|
Size: |
24576
|
|
8EE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3224243633.00000000008EE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EE000
|
Size: |
45056
|
|
8F4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3273128281.00000000008F4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F4000
|
Size: |
12288
|
|
918000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3331326152.0000000000918000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
918000
|
Size: |
28672
|
|
ADB000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2188825842.0000000000ADB000.00000004.00000001.01000000.00000009.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
ADB000
|
Size: |
4096
|
|
8E9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3271655162.00000000008E9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E9000
|
Size: |
20480
|
|
8D7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3206617283.00000000008D7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8D7000
|
Size: |
12288
|
|
8D4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3160660801.00000000008D4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8D4000
|
Size: |
4096
|
|
918000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3287156807.0000000000918000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
918000
|
Size: |
45056
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
8E9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3329858973.00000000008E9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E9000
|
Size: |
4096
|
|
918000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3331676409.0000000000918000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
918000
|
Size: |
28672
|
|
4C5E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2389994212.0000000004C5E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4C5E000
|
Size: |
8192
|
|
8DD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3221944798.00000000008DD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DD000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
AD0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.2134989650.0000000000AD0000.00000002.00000001.01000000.00000009.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
AD0000
|
Size: |
4096
|
|
8F7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3359698304.00000000008F7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F7000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3277313846.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
4096
|
|
918000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3356712486.0000000000918000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
918000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
922000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3349559030.0000000000922000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
922000
|
Size: |
12288
|
|
820000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2195106739.0000000000820000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
820000
|
Size: |
20480
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3251458896.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
4096
|
|
8FD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3145433758.00000000008FD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FD000
|
Size: |
16384
|
|
8FC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3177367154.00000000008FC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FC000
|
Size: |
20480
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3232605693.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
4096
|
|
10FA000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.2112370632.00000000010FA000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
10FA000
|
Size: |
24576
|
|
8D7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3207094030.00000000008D7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8D7000
|
Size: |
8192
|
|
8DE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3208674544.00000000008DE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DE000
|
Size: |
20480
|
|
8FB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3206432742.00000000008FB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FB000
|
Size: |
24576
|
|
8E1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3331326152.00000000008E1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E1000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
8FC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3178722434.00000000008FC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FC000
|
Size: |
20480
|
|
918000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3359698304.0000000000918000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
918000
|
Size: |
12288
|
|
8E6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3333767878.00000000008E6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E6000
|
Size: |
77824
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1459000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2192539376.0000000001459000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1459000
|
Size: |
8192
|
|
8E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3333767878.00000000008E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E0000
|
Size: |
12288
|
|
8D9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3356712486.00000000008D9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8D9000
|
Size: |
4096
|
|
8FD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3160771296.00000000008FD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FD000
|
Size: |
16384
|
|
361F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2194548653.000000000361F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
361F000
|
Size: |
4096
|
|
5B21000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000004.00000003.2225433321.0000000005B21000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5B21000
|
Size: |
217088
|
|
6DE84000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2191347966.000000006DE84000.00000004.00000001.01000000.0000000A.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
6DE84000
|
Size: |
4096
|
|
918000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3358870376.0000000000918000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
918000
|
Size: |
12288
|
|
1404000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2193553573.0000000001404000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1404000
|
Size: |
73728
|
|
1101000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.2112410083.0000000001101000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1101000
|
Size: |
4096
|
|
8DC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3120536170.00000000008DC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DC000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
8EE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3219156500.00000000008EE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EE000
|
Size: |
32768
|
|
8F8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3331676409.00000000008F8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F8000
|
Size: |
4096
|
|
2BDA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2389435788.0000000002BDA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2BDA000
|
Size: |
86016
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
6C99F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2191226595.000000006C99F000.00000002.00000001.01000000.0000000B.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
6C99F000
|
Size: |
32768
|
|
8E9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3268209847.00000000008E9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E9000
|
Size: |
20480
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
AFD000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000000.2116222876.0000000000AFD000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
AFD000
|
Size: |
315392
|
|
8FD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3121898397.00000000008FD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FD000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
6EAF3000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2191543903.000000006EAF3000.00000002.00000001.01000000.0000000C.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
6EAF3000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
6C878000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2190762975.000000006C878000.00000002.00000001.01000000.0000000D.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
6C878000
|
Size: |
20480
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
13FB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2192510706.00000000013FB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13FB000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
918000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3359463454.0000000000918000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
918000
|
Size: |
12288
|
|
922000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3359858965.0000000000922000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
922000
|
Size: |
4096
|
|
1479000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2191763092.0000000001479000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1479000
|
Size: |
16384
|
|
8D3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3300790093.00000000008D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8D3000
|
Size: |
32768
|
|
8DB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3204418097.00000000008DB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DB000
|
Size: |
32768
|
|
8EE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3219058504.00000000008EE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EE000
|
Size: |
32768
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3358870376.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
4096
|
|
91E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3354854258.000000000091E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
91E000
|
Size: |
12288
|
|
31D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2194503685.00000000031D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
31D0000
|
Size: |
4096
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3349088987.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
4096
|
|
2BB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2389395510.0000000002BB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2BB0000
|
Size: |
4096
|
|
8EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3215962268.00000000008EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EA000
|
Size: |
57344
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
8EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3131010591.00000000008EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EA000
|
Size: |
65536
|
|
91B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3350317355.000000000091B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
91B000
|
Size: |
24576
|
|
532E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2390174035.000000000532E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
532E000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
8E9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3259586789.00000000008E9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E9000
|
Size: |
20480
|
|
8EE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3228479925.00000000008EE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EE000
|
Size: |
45056
|
|
918000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3349334097.0000000000918000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
918000
|
Size: |
20480
|
|
156E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2189051450.000000000156E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
156E000
|
Size: |
8192
|
|
918000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3354297313.0000000000918000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
918000
|
Size: |
12288
|
|
918000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3362049615.0000000000918000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
918000
|
Size: |
12288
|
|
8D3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3109375742.00000000008D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8D3000
|
Size: |
8192
|
|
1464000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.2137304315.0000000001464000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1464000
|
Size: |
8192
|
|
924000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3332561534.0000000000924000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
924000
|
Size: |
4096
|
|
8EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3206533355.00000000008EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EA000
|
Size: |
69632
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
8F8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3119518337.00000000008F8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F8000
|
Size: |
8192
|
|
3B9000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3365951281.00000000003B9000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
3B9000
|
Size: |
16384
|
|
164B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2189069192.000000000164B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
164B000
|
Size: |
24576
|
|
6C7B1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000003.00000002.2190036676.000000006C7B1000.00000020.00000001.01000000.0000000F.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
6C7B1000
|
Size: |
376832
|
|
145C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2193706885.000000000145C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
145C000
|
Size: |
8192
|
|
8D3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3277343022.00000000008D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8D3000
|
Size: |
45056
|
|
8DE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3218773710.00000000008DE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DE000
|
Size: |
20480
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3362049615.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
4096
|
|
16AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2193919888.00000000016AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
16AE000
|
Size: |
8192
|
|
8DB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3215412339.00000000008DB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DB000
|
Size: |
32768
|
|
8EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3208788355.00000000008EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EA000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3359698304.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
4096
|
|
6C83C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2190594882.000000006C83C000.00000004.00000001.01000000.0000000F.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
6C83C000
|
Size: |
4096
|
|
FE0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2188937108.0000000000FE0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FE0000
|
Size: |
4096
|
|
8E1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3104407329.00000000008E1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E1000
|
Size: |
4096
|
|
6EAF0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2191505753.000000006EAF0000.00000002.00000001.01000000.0000000C.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
6EAF0000
|
Size: |
4096
|
|
8FC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3174791940.00000000008FC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FC000
|
Size: |
20480
|
|
8DD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3178617313.00000000008DD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DD000
|
Size: |
24576
|
|
14D6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2193866323.00000000014D6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14D6000
|
Size: |
12288
|
|
948000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2195147455.0000000000948000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
948000
|
Size: |
163840
|
|
8C3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3366133731.00000000008C3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8C3000
|
Size: |
8192
|
|
145B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2191823653.000000000145B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
145B000
|
Size: |
12288
|
|
8DD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3266142445.00000000008DD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DD000
|
Size: |
4096
|
|
91F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3300849938.000000000091F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
91F000
|
Size: |
24576
|
|
8F6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3359463454.00000000008F6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F6000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
8FD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3121974449.00000000008FD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FD000
|
Size: |
8192
|
|
145C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2192490307.000000000145C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
145C000
|
Size: |
8192
|
|
8CA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3258871597.00000000008CA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8CA000
|
Size: |
8192
|
|
6C8A1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000003.00000002.2190921034.000000006C8A1000.00000020.00000001.01000000.0000000B.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
6C8A1000
|
Size: |
602112
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3331676409.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
4096
|
|
FDD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2188913328.0000000000FDD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FDD000
|
Size: |
12288
|
|
8F8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3366133731.00000000008F8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F8000
|
Size: |
4096
|
|
4CE0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2390063848.0000000004CE0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CE0000
|
Size: |
139264
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
8DC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3131010591.00000000008DC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DC000
|
Size: |
28672
|
|
8EC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3216739904.00000000008EC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EC000
|
Size: |
49152
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
8D4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3268562083.00000000008D4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8D4000
|
Size: |
40960
|
|
12FB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2188954139.00000000012FB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
12FB000
|
Size: |
20480
|
|
8CA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3260502080.00000000008CA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8CA000
|
Size: |
8192
|
|
8BA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3366133731.00000000008BA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8BA000
|
Size: |
20480
|
|
8FE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3222385479.00000000008FE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FE000
|
Size: |
8192
|
|
8DF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3300735047.00000000008DF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DF000
|
Size: |
16384
|
|
142E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2192690800.000000000142E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
142E000
|
Size: |
172032
|
|
1469000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2193752212.0000000001469000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1469000
|
Size: |
20480
|
|
8D7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3204526058.00000000008D7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8D7000
|
Size: |
16384
|
|
8F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3266142445.00000000008F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F1000
|
Size: |
8192
|
|
4DBD000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3367751694.0000000004DBD000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4DBD000
|
Size: |
458752
|
|
8DE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3217336809.00000000008DE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DE000
|
Size: |
20480
|
|
8FD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3131010591.00000000008FD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FD000
|
Size: |
16384
|
|
8EE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3176097693.00000000008EE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EE000
|
Size: |
45056
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3274281345.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
4096
|
|
8E9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3354297313.00000000008E9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E9000
|
Size: |
65536
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
8FD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3118148485.00000000008FD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FD000
|
Size: |
8192
|
|
AD1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000003.00000002.2188782443.0000000000AD1000.00000020.00000001.01000000.00000009.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
AD1000
|
Size: |
24576
|
|
8E1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3216094100.00000000008E1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E1000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
8D3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3104596497.00000000008D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8D3000
|
Size: |
8192
|
|
8D3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2598670131.00000000008D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8D3000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
8FD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3160660801.00000000008FD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FD000
|
Size: |
16384
|
|
901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3224243633.0000000000901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
901000
|
Size: |
4096
|
|
1590000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2189069192.0000000001590000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1590000
|
Size: |
24576
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
AD1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000003.00000000.2135011921.0000000000AD1000.00000020.00000001.01000000.00000009.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
AD1000
|
Size: |
24576
|
|
3783000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2189675713.0000000003783000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3783000
|
Size: |
626688
|
|
B53000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000002.2193204882.0000000000B53000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B53000
|
Size: |
122880
|
|
8E5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3362049615.00000000008E5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E5000
|
Size: |
61440
|
|
B51000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000000.2116275279.0000000000B51000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B51000
|
Size: |
4096
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3268164907.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
4096
|
|
8CA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3217456927.00000000008CA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8CA000
|
Size: |
8192
|
|
3401000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2189493372.0000000003401000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3401000
|
Size: |
512000
|
|
3C40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2194689714.0000000003C40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3C40000
|
Size: |
4096
|
|
2C23000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2389435788.0000000002C23000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C23000
|
Size: |
4096
|
|
8F6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3275012624.00000000008F6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F6000
|
Size: |
8192
|
|
1468000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2191804611.0000000001468000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1468000
|
Size: |
24576
|
|
4CD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2390042830.0000000004CD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD0000
|
Size: |
4096
|
|
8FD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3119495785.00000000008FD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FD000
|
Size: |
8192
|
|
8C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3366133731.00000000008C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8C0000
|
Size: |
4096
|
|
8CA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3104596497.00000000008CA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8CA000
|
Size: |
8192
|
|
8D3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3160795286.00000000008D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8D3000
|
Size: |
4096
|
|
918000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3300589553.0000000000918000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
918000
|
Size: |
20480
|
|
8DC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3349088987.00000000008DC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DC000
|
Size: |
8192
|
|
312E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2194425228.000000000312E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
312E000
|
Size: |
8192
|
|
8DC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3216609939.00000000008DC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DC000
|
Size: |
28672
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3350095455.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
4096
|
|
8E9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3260429837.00000000008E9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E9000
|
Size: |
20480
|
|
8D7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3224405505.00000000008D7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8D7000
|
Size: |
28672
|
|
1103000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.2112456579.0000000001103000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1103000
|
Size: |
122880
|
|
3630000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2189657811.0000000003630000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3630000
|
Size: |
4096
|
|
6E557000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2191487952.000000006E557000.00000002.00000001.01000000.0000000E.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
6E557000
|
Size: |
8192
|
|
924000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3287459281.0000000000924000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
924000
|
Size: |
4096
|
|
8DD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3175811531.00000000008DD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DD000
|
Size: |
24576
|
|
6C811000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2190468444.000000006C811000.00000002.00000001.01000000.0000000F.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
6C811000
|
Size: |
139264
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
141D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2193553573.000000000141D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
141D000
|
Size: |
8192
|
|
1465000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.2137244518.0000000001465000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1465000
|
Size: |
4096
|
|
8CB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3109375742.00000000008CB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8CB000
|
Size: |
4096
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3362288634.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
4096
|
|
8DC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3116976956.00000000008DC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DC000
|
Size: |
28672
|
|
6DE80000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2191305330.000000006DE80000.00000002.00000001.01000000.0000000A.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
6DE80000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3056000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2189251276.0000000003056000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3056000
|
Size: |
733184
|
|
8BF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3300929834.00000000008BF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8BF000
|
Size: |
4096
|
|
8D6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3353818349.00000000008D6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8D6000
|
Size: |
16384
|
|
8FE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3224243633.00000000008FE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FE000
|
Size: |
8192
|
|
133E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2193293292.000000000133E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
133E000
|
Size: |
8192
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3228479925.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
4096
|
|
918000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3362288634.0000000000918000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
918000
|
Size: |
8192
|
|
30B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2194940230.000000000030B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
30B000
|
Size: |
20480
|
|
B4A000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2193118389.0000000000B4A000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
B4A000
|
Size: |
8192
|
|
8EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3160660801.00000000008EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EA000
|
Size: |
65536
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
922000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3357007704.0000000000922000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
922000
|
Size: |
12288
|
|
34EF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2389797252.00000000034EF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
34EF000
|
Size: |
4096
|
|
FD1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000000.2112162096.0000000000FD1000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
FD1000
|
Size: |
901120
|
|
4AAD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2389892810.0000000004AAD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4AAD000
|
Size: |
12288
|
|
1420000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2192254147.0000000001420000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1420000
|
Size: |
229376
|
|
3A6000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3365880709.00000000003A6000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
3A6000
|
Size: |
65536
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
918000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3357007704.0000000000918000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
918000
|
Size: |
16384
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3260383461.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
4096
|
|
8EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3219575151.00000000008EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EA000
|
Size: |
49152
|
|
8FE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3228657972.00000000008FE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FE000
|
Size: |
8192
|
|
4A6D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2389853034.0000000004A6D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4A6D000
|
Size: |
12288
|
|
8F8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3329858973.00000000008F8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F8000
|
Size: |
4096
|
|
8E6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3214508944.00000000008E6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E6000
|
Size: |
4096
|
|
141D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2192369554.000000000141D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
141D000
|
Size: |
12288
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3356712486.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
4096
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3366133731.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
4096
|
|
8EF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3251532109.00000000008EF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EF000
|
Size: |
28672
|
|
5770000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2390462106.0000000005770000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
5770000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
8E1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3277343022.00000000008E1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E1000
|
Size: |
16384
|
|
2F2F000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2389675661.0000000002F2F000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2F2F000
|
Size: |
4096
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3287156807.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
4096
|
|
918000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3350095455.0000000000918000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
918000
|
Size: |
36864
|
|
8E9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3353818349.00000000008E9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E9000
|
Size: |
65536
|
|
8CC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3336080047.00000000008CC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8CC000
|
Size: |
12288
|
|
8EB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3336080047.00000000008EB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EB000
|
Size: |
57344
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
8E7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3300735047.00000000008E7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E7000
|
Size: |
12288
|
|
8EB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3218023614.00000000008EB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EB000
|
Size: |
4096
|
|
13D9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2192752891.00000000013D9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13D9000
|
Size: |
12288
|
|
91C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3359463454.000000000091C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
91C000
|
Size: |
20480
|
|
8EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3218773710.00000000008EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EA000
|
Size: |
12288
|
|
924000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3329858973.0000000000924000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
924000
|
Size: |
4096
|
|
91E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3354297313.000000000091E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
91E000
|
Size: |
12288
|
|
8E9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3287156807.00000000008E9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E9000
|
Size: |
12288
|
|
3C20000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2194669902.0000000003C20000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3C20000
|
Size: |
4096
|
|
8CA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3131199577.00000000008CA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8CA000
|
Size: |
8192
|
|
5451000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2390174035.0000000005451000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5451000
|
Size: |
512000
|
|
8FE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3219575151.00000000008FE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FE000
|
Size: |
8192
|
|
8F3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3300589553.00000000008F3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F3000
|
Size: |
4096
|
|
8EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3216609939.00000000008EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EA000
|
Size: |
57344
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
918000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3349786515.0000000000918000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
918000
|
Size: |
36864
|
|
8EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3109257898.00000000008EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EA000
|
Size: |
24576
|
|
918000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3333767878.0000000000918000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
918000
|
Size: |
16384
|
|
8F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3268562083.00000000008F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F1000
|
Size: |
8192
|
|
370000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3365798779.0000000000370000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
370000
|
Size: |
4096
|
|
8EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3208674544.00000000008EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EA000
|
Size: |
53248
|
|
91E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3349559030.000000000091E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
91E000
|
Size: |
12288
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3300589553.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
4096
|
|
141D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2192849156.000000000141D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
141D000
|
Size: |
8192
|
|
8FD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3132373581.00000000008FD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FD000
|
Size: |
16384
|
|
901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3224329081.0000000000901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
901000
|
Size: |
4096
|
|
13B8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2193357085.00000000013B8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13B8000
|
Size: |
110592
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
8DC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3221528603.00000000008DC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DC000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2D0E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2389583665.0000000002D0E000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2D0E000
|
Size: |
8192
|
|
1464000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.2137224153.0000000001464000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1464000
|
Size: |
8192
|
|
922000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3349334097.0000000000922000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
922000
|
Size: |
12288
|
|
147A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2193803802.000000000147A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
147A000
|
Size: |
12288
|
|
FD0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.2195265384.0000000000FD0000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
FD0000
|
Size: |
4096
|
|
B53000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000000.2116291194.0000000000B53000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B53000
|
Size: |
122880
|
|
8DC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3121898397.00000000008DC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DC000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
91E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3353818349.000000000091E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
91E000
|
Size: |
12288
|
|
B53000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3366626141.0000000000B53000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
B53000
|
Size: |
290816
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
1001E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2189840391.000000001001E000.00000002.00000001.01000000.00000010.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1001E000
|
Size: |
819200
|
|
8F6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3358870376.00000000008F6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F6000
|
Size: |
12288
|
|
8FE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3221917998.00000000008FE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FE000
|
Size: |
8192
|
|
8DC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3104407329.00000000008DC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DC000
|
Size: |
12288
|
|
8DD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3177367154.00000000008DD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DD000
|
Size: |
24576
|
|
8F7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3217231959.00000000008F7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F7000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
924000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3331326152.0000000000924000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
924000
|
Size: |
4096
|
|
33D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3365766737.000000000033D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
33D000
|
Size: |
12288
|
|
18EF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2194277874.00000000018EF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
18EF000
|
Size: |
4096
|
|
13D7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2192821685.00000000013D7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13D7000
|
Size: |
8192
|
|
91D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3362049615.000000000091D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
91D000
|
Size: |
16384
|
|
6DE71000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000003.00000002.2191276145.000000006DE71000.00000020.00000001.01000000.0000000A.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
6DE71000
|
Size: |
57344
|
|
858000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3366133731.0000000000858000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
858000
|
Size: |
372736
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
B51000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000002.2193184869.0000000000B51000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B51000
|
Size: |
4096
|
|
8D8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2598670131.00000000008D8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8D8000
|
Size: |
4096
|
|
8DE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3214508944.00000000008DE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DE000
|
Size: |
20480
|
|
8FD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3145351878.00000000008FD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FD000
|
Size: |
16384
|
|
8F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3268209847.00000000008F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F1000
|
Size: |
8192
|
|
498C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2194778169.000000000498C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
498C000
|
Size: |
16384
|
|
579E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3369993694.000000000579E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
579E000
|
Size: |
8192
|
|
8CA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3160795286.00000000008CA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8CA000
|
Size: |
8192
|
|
3CC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2194735588.0000000003CC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3CC0000
|
Size: |
12288
|
|
6E556000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000003.00000002.2191469920.000000006E556000.00000008.00000001.01000000.0000000E.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
6E556000
|
Size: |
4096
|
|
1464000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.2137264761.0000000001464000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1464000
|
Size: |
8192
|
|
8B4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3300929834.00000000008B4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8B4000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
30EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2194344228.00000000030EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30EA000
|
Size: |
20480
|
|
8E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3336080047.00000000008E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E0000
|
Size: |
12288
|
|
8FD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3131164135.00000000008FD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FD000
|
Size: |
16384
|
|
8ED000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3174831448.00000000008ED000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8ED000
|
Size: |
49152
|
|
371E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2194582334.000000000371E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
371E000
|
Size: |
8192
|
|
8CC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2598670131.00000000008CC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8CC000
|
Size: |
4096
|
|
8E9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3258828239.00000000008E9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E9000
|
Size: |
20480
|
|
370000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2194962186.0000000000370000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
370000
|
Size: |
4096
|
|
322D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2189393361.000000000322D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
322D000
|
Size: |
626688
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
6C851000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000003.00000002.2190705594.000000006C851000.00000020.00000001.01000000.0000000D.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
6C851000
|
Size: |
159744
|
|
13B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2193357085.00000000013B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13B0000
|
Size: |
28672
|
|
6E554000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2191426192.000000006E554000.00000002.00000001.01000000.0000000E.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
6E554000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
8FE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3228479925.00000000008FE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FE000
|
Size: |
8192
|
|
8DA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3206533355.00000000008DA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DA000
|
Size: |
4096
|
|
921000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3287459281.0000000000921000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
921000
|
Size: |
8192
|
|
8FD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3162055219.00000000008FD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FD000
|
Size: |
16384
|
|
91D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3359858965.000000000091D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
91D000
|
Size: |
16384
|
|
920000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3331676409.0000000000920000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
920000
|
Size: |
4096
|
|
918000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3329858973.0000000000918000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
918000
|
Size: |
36864
|
|
8F8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3362049615.00000000008F8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F8000
|
Size: |
4096
|
|
1464000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.2137361152.0000000001464000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1464000
|
Size: |
8192
|
|
8E4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3349786515.00000000008E4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E4000
|
Size: |
8192
|
|
8EB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3274495409.00000000008EB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EB000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
6E551000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000003.00000002.2191406343.000000006E551000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
6E551000
|
Size: |
12288
|
|
8FE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3221501430.00000000008FE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FE000
|
Size: |
8192
|
|
2BF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2389435788.0000000002BF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2BF0000
|
Size: |
196608
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
142A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2193632461.000000000142A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
142A000
|
Size: |
12288
|
|
6C894000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2190844713.000000006C894000.00000002.00000001.01000000.0000000D.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
6C894000
|
Size: |
16384
|
|
8D7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3250753823.00000000008D7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8D7000
|
Size: |
28672
|
|
8F8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3119398938.00000000008F8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F8000
|
Size: |
8192
|
|
8E9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3349786515.00000000008E9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E9000
|
Size: |
65536
|
|
56CC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2390348510.00000000056CC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
56CC000
|
Size: |
626688
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
91E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3349088987.000000000091E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
91E000
|
Size: |
12288
|
|
922000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3354297313.0000000000922000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
922000
|
Size: |
12288
|
|
B4F000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2193165829.0000000000B4F000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
B4F000
|
Size: |
8192
|
|
4990000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2194806467.0000000004990000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4990000
|
Size: |
16384
|
|
8EE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3232396564.00000000008EE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EE000
|
Size: |
49152
|
|
8FE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3222473436.00000000008FE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FE000
|
Size: |
8192
|
|
8FC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3176028917.00000000008FC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FC000
|
Size: |
20480
|
|
8EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3118148485.00000000008EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EA000
|
Size: |
65536
|
|
8EE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3222385479.00000000008EE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EE000
|
Size: |
32768
|
|
91E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3334028995.000000000091E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
91E000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
8FC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3178617313.00000000008FC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FC000
|
Size: |
20480
|
|
8ED000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3217263957.00000000008ED000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8ED000
|
Size: |
40960
|
|
1464000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.2137419255.0000000001464000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1464000
|
Size: |
8192
|
|
8E9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3250753823.00000000008E9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E9000
|
Size: |
57344
|
|
B4A000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000002.00000000.2116259329.0000000000B4A000.00000008.00000001.01000000.00000004.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
B4A000
|
Size: |
24576
|
|
560E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3369869734.000000000560E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
560E000
|
Size: |
8192
|
|
900000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3245038601.0000000000900000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
900000
|
Size: |
16384
|
|
8DA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3218773710.00000000008DA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DA000
|
Size: |
4096
|
|
4C90000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3367751694.0000000004C90000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4C90000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
6C973000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2191170039.000000006C973000.00000004.00000001.01000000.0000000B.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
6C973000
|
Size: |
4096
|
|
2F6E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2389709162.0000000002F6E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2F6E000
|
Size: |
8192
|
|
922000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3354854258.0000000000922000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
922000
|
Size: |
12288
|
|
8E9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3357007704.00000000008E9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E9000
|
Size: |
45056
|
|
10FC000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000002.2195435635.00000000010FC000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
10FC000
|
Size: |
12288
|
|
8EE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3177367154.00000000008EE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EE000
|
Size: |
45056
|
|
13D8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2193404645.00000000013D8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13D8000
|
Size: |
4096
|
|
137E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2193315637.000000000137E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
137E000
|
Size: |
8192
|
|
54BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3369778078.00000000054BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
54BE000
|
Size: |
8192
|
|
924000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3331676409.0000000000924000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
924000
|
Size: |
4096
|
|
8EC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3221447880.00000000008EC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EC000
|
Size: |
40960
|
|
8EE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3178617313.00000000008EE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EE000
|
Size: |
45056
|
|
1469000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2192330787.0000000001469000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1469000
|
Size: |
20480
|
|
8DB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3216024777.00000000008DB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DB000
|
Size: |
32768
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
6FB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2195044865.00000000006FB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6FB000
|
Size: |
20480
|
|
922000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3350317355.0000000000922000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
922000
|
Size: |
12288
|
|
6C965000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2191072215.000000006C965000.00000002.00000001.01000000.0000000B.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
6C965000
|
Size: |
57344
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
8E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3349088987.00000000008E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E0000
|
Size: |
24576
|
|
30E6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2194344228.00000000030E6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30E6000
|
Size: |
8192
|
|
922000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3356712486.0000000000922000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
922000
|
Size: |
12288
|
|
147D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2191731622.000000000147D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
147D000
|
Size: |
204800
|
|
2D50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2389626912.0000000002D50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D50000
|
Size: |
16384
|
|
142F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2193657412.000000000142F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
142F000
|
Size: |
167936
|
|
A3B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2389271280.0000000000A3B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
A3B000
|
Size: |
20480
|
|
8FD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3120536170.00000000008FD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FD000
|
Size: |
8192
|
|
1459000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2192419126.0000000001459000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1459000
|
Size: |
8192
|
|
8DC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3287156807.00000000008DC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DC000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
8CB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3132497975.00000000008CB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8CB000
|
Size: |
4096
|
|
8E6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3209576839.00000000008E6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E6000
|
Size: |
69632
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3232396564.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
4096
|
|
8FE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3232396564.00000000008FE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FE000
|
Size: |
12288
|
|
316E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2194455320.000000000316E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
316E000
|
Size: |
8192
|
|
8DC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3259586789.00000000008DC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DC000
|
Size: |
8192
|
|
3040000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2189233949.0000000003040000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3040000
|
Size: |
12288
|
|
1464000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2191690677.0000000001464000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1464000
|
Size: |
307200
|
|
8E6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3208674544.00000000008E6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E6000
|
Size: |
8192
|
|
A20000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000002.2192962117.0000000000A20000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
A20000
|
Size: |
4096
|
|
6DE82000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2191328070.000000006DE82000.00000004.00000001.01000000.0000000A.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
6DE82000
|
Size: |
4096
|
|
4C1D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2389974019.0000000004C1D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4C1D000
|
Size: |
12288
|
|
1425000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2193604721.0000000001425000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1425000
|
Size: |
8192
|
|
7DC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3366084826.00000000007DC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7DC000
|
Size: |
16384
|
|
145C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2192419126.000000000145C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
145C000
|
Size: |
8192
|
|
8F9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3162144324.00000000008F9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F9000
|
Size: |
4096
|
|
8D3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3260502080.00000000008D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8D3000
|
Size: |
45056
|
|
8E5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3353818349.00000000008E5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E5000
|
Size: |
4096
|
|
8FE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3232605693.00000000008FE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FE000
|
Size: |
12288
|
|
91C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3358870376.000000000091C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
91C000
|
Size: |
20480
|
|
8FE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3221447880.00000000008FE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FE000
|
Size: |
8192
|
|
8EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3120536170.00000000008EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EA000
|
Size: |
49152
|
|
81B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3366107235.000000000081B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
81B000
|
Size: |
20480
|
|
8EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3177367154.00000000008EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EA000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
31D3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2194503685.00000000031D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
31D3000
|
Size: |
12288
|
|
8C2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3300929834.00000000008C2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8C2000
|
Size: |
4096
|
|
2BD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2389435788.0000000002BD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2BD0000
|
Size: |
36864
|
|
8C7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3366133731.00000000008C7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8C7000
|
Size: |
40960
|
|
8FE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3219677457.00000000008FE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FE000
|
Size: |
8192
|
|
1598000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2189069192.0000000001598000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1598000
|
Size: |
73728
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
8E5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3354297313.00000000008E5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E5000
|
Size: |
4096
|
|
89C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3300929834.000000000089C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
89C000
|
Size: |
94208
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
8EC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3209648472.00000000008EC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EC000
|
Size: |
45056
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
6C8A0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2190899192.000000006C8A0000.00000002.00000001.01000000.0000000B.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
6C8A0000
|
Size: |
4096
|
|
8DC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3132373581.00000000008DC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DC000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
8E5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3358870376.00000000008E5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E5000
|
Size: |
61440
|
|
8EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3162055219.00000000008EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EA000
|
Size: |
65536
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
547D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3369725797.000000000547D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
547D000
|
Size: |
12288
|
|
13DA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2193423318.00000000013DA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13DA000
|
Size: |
8192
|
|
8CA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3224405505.00000000008CA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8CA000
|
Size: |
8192
|
|
3057000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2389750563.0000000003057000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3057000
|
Size: |
32768
|
|
8E9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3250914851.00000000008E9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E9000
|
Size: |
57344
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3333767878.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
4096
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3228637989.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
4096
|
|
145E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2191653254.000000000145E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
145E000
|
Size: |
331776
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3250675876.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
4096
|
|
8EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3174711250.00000000008EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EA000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
373B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2189675713.000000000373B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
373B000
|
Size: |
290816
|
|
8DB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3245150100.00000000008DB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DB000
|
Size: |
12288
|
|
8F5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3258781198.00000000008F5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F5000
|
Size: |
16384
|
|
8DD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3219709140.00000000008DD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DD000
|
Size: |
8192
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3265977689.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
4096
|
|
921000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3336541113.0000000000921000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
921000
|
Size: |
16384
|
|
B3F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2195218001.0000000000B3F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B3F000
|
Size: |
4096
|
|
922000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3350095455.0000000000922000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
922000
|
Size: |
12288
|
|
3180000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2194480858.0000000003180000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3180000
|
Size: |
4096
|
|
4CF3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.2225232359.0000000004CF3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CF3000
|
Size: |
159744
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3271467590.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
4096
|
|
8EE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3218773710.00000000008EE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EE000
|
Size: |
32768
|
|
8DE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3218136592.00000000008DE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DE000
|
Size: |
20480
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
6EAF1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000003.00000002.2191524351.000000006EAF1000.00000020.00000001.01000000.0000000C.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
6EAF1000
|
Size: |
8192
|
|
3631000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.2137182869.0000000003631000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3631000
|
Size: |
221184
|
|
31D7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2189393361.00000000031D7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
31D7000
|
Size: |
344064
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2B7F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2389301409.0000000002B7F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2B7F000
|
Size: |
4096
|
|
10001000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000003.00000002.2189790315.0000000010001000.00000020.00000001.01000000.00000010.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
10001000
|
Size: |
90112
|
|
5B20000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2390662177.0000000005B20000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5B20000
|
Size: |
36864
|
|
8DD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3174711250.00000000008DD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DD000
|
Size: |
24576
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
918000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3349088987.0000000000918000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
918000
|
Size: |
20480
|
|
91E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3333767878.000000000091E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
91E000
|
Size: |
12288
|
|
8EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3359463454.00000000008EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EA000
|
Size: |
40960
|
|
8DE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3222385479.00000000008DE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DE000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
8F7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3245038601.00000000008F7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F7000
|
Size: |
8192
|
|
6C892000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2190823838.000000006C892000.00000004.00000001.01000000.0000000D.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
6C892000
|
Size: |
4096
|
|
590E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2390462106.000000000590E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
590E000
|
Size: |
24576
|
|
91C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3366133731.000000000091C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
91C000
|
Size: |
4096
|
|
2BA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2389369131.0000000002BA0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2BA0000
|
Size: |
4096
|
|
91D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3362221003.000000000091D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
91D000
|
Size: |
16384
|
|
8FD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3118227951.00000000008FD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FD000
|
Size: |
8192
|
|
924000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3287156807.0000000000924000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
924000
|
Size: |
4096
|
|
8E2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3300877880.00000000008E2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E2000
|
Size: |
4096
|
|
8F3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3271467590.00000000008F3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F3000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
710000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3366050886.0000000000710000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
710000
|
Size: |
20480
|
|
3C0D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2194647299.0000000003C0D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3C0D000
|
Size: |
12288
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3273128281.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
4096
|
|
6DE70000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2191253965.000000006DE70000.00000002.00000001.01000000.0000000A.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
6DE70000
|
Size: |
4096
|
|
8EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3145351878.00000000008EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EA000
|
Size: |
65536
|
|
922000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3353818349.0000000000922000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
922000
|
Size: |
12288
|
|
12F6000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2193273128.00000000012F6000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
12F6000
|
Size: |
40960
|
|
30CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2194325419.00000000030CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
30CE000
|
Size: |
8192
|
|
8FC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3175811531.00000000008FC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FC000
|
Size: |
20480
|
|
8FD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3162144324.00000000008FD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FD000
|
Size: |
16384
|
|
1427000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2192734576.0000000001427000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1427000
|
Size: |
24576
|
|
10000000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2189773306.0000000010000000.00000002.00000001.01000000.00000010.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
10000000
|
Size: |
4096
|
|
8ED000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3218023614.00000000008ED000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8ED000
|
Size: |
36864
|
|
A21000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000002.00000000.2116105767.0000000000A21000.00000020.00000001.01000000.00000004.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
A21000
|
Size: |
901120
|
|
8EF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3109320594.00000000008EF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EF000
|
Size: |
4096
|
|
311F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2189324197.000000000311F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
311F000
|
Size: |
716800
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1465000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2192330787.0000000001465000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1465000
|
Size: |
12288
|
|
AD7000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.2135073330.0000000000AD7000.00000002.00000001.01000000.00000009.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
AD7000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
8EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3132373581.00000000008EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EA000
|
Size: |
65536
|
|
8F6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3356712486.00000000008F6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F6000
|
Size: |
12288
|
|
920000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3331326152.0000000000920000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
920000
|
Size: |
4096
|
|
8EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3121898397.00000000008EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EA000
|
Size: |
65536
|
|
8E9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3275137729.00000000008E9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E9000
|
Size: |
36864
|
|
146F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2193773385.000000000146F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
146F000
|
Size: |
40960
|
|
AFD000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000002.2193073664.0000000000AFD000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
AFD000
|
Size: |
315392
|
|
8F7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3224355203.00000000008F7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F7000
|
Size: |
8192
|
|
8DE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3206533355.00000000008DE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DE000
|
Size: |
20480
|
|
8D8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3216770662.00000000008D8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8D8000
|
Size: |
12288
|
|
3B6000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3365913031.00000000003B6000.00000004.00000001.01000000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3B6000
|
Size: |
12288
|
|
AD7000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2188801509.0000000000AD7000.00000002.00000001.01000000.00000009.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
AD7000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
8EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3215337216.00000000008EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EA000
|
Size: |
57344
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
923000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3359664544.0000000000923000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
923000
|
Size: |
8192
|
|
8DE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3206914319.00000000008DE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DE000
|
Size: |
20480
|
|
569D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3369959040.000000000569D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
569D000
|
Size: |
12288
|
|
147E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2193825321.000000000147E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
147E000
|
Size: |
200704
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
8EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3206914319.00000000008EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EA000
|
Size: |
69632
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
8EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3104523539.00000000008EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EA000
|
Size: |
24576
|
|
3000000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2389730390.0000000003000000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3000000
|
Size: |
4096
|
|
3CB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2194713906.0000000003CB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3CB0000
|
Size: |
24576
|
|
920000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3366133731.0000000000920000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
920000
|
Size: |
20480
|
|
F60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2195244454.0000000000F60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F60000
|
Size: |
4096
|
|
8F3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3265977689.00000000008F3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F3000
|
Size: |
8192
|
|
8CA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3174859331.00000000008CA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8CA000
|
Size: |
8192
|
|
8D3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3258871597.00000000008D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8D3000
|
Size: |
45056
|
|
8C8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3300929834.00000000008C8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8C8000
|
Size: |
8192
|
|
8E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3219575151.00000000008E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E0000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
8EE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3175811531.00000000008EE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EE000
|
Size: |
45056
|
|
1459000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2193657412.0000000001459000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1459000
|
Size: |
8192
|
|
8EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3331326152.00000000008EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EA000
|
Size: |
12288
|
|
1425000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2192539376.0000000001425000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1425000
|
Size: |
32768
|
|
1402000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2192369554.0000000001402000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1402000
|
Size: |
81920
|
|
1010D000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2189840391.000000001010D000.00000002.00000001.01000000.00000010.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1010D000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3331326152.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
4096
|
|
8FE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3223552497.00000000008FE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FE000
|
Size: |
8192
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3349786515.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
4096
|
|
6E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3366027571.00000000006E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6E0000
|
Size: |
8192
|
|
924000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3334028995.0000000000924000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
924000
|
Size: |
4096
|
|
8D9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3208740987.00000000008D9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8D9000
|
Size: |
8192
|
|
1459000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2192254147.0000000001459000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1459000
|
Size: |
8192
|
|
4CF3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.2225316911.0000000004CF3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CF3000
|
Size: |
159744
|
|
8E1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2598636996.00000000008E1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E1000
|
Size: |
4096
|
|
4BDE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2389935914.0000000004BDE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4BDE000
|
Size: |
8192
|
|
5899000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2390462106.0000000005899000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
5899000
|
Size: |
4096
|
|
8EF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3275173380.00000000008EF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EF000
|
Size: |
12288
|
|
8EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3175811531.00000000008EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EA000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
F90000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2188890924.0000000000F90000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F90000
|
Size: |
4096
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3349334097.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
4096
|
|
6E550000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2191388858.000000006E550000.00000002.00000001.01000000.0000000E.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
6E550000
|
Size: |
4096
|
|
922000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3349088987.0000000000922000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
922000
|
Size: |
12288
|
|
FF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2193251902.0000000000FF0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FF0000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
13D3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2192629335.00000000013D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13D3000
|
Size: |
163840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
8F7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3208617275.00000000008F7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F7000
|
Size: |
8192
|
|
8F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3259586789.00000000008F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F1000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
8E5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3356712486.00000000008E5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E5000
|
Size: |
61440
|
|
4994000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2192885413.0000000004994000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4994000
|
Size: |
4096
|
|
8EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3109348014.00000000008EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EA000
|
Size: |
20480
|
|
3FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2195014625.00000000003FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3FE000
|
Size: |
8192
|
|
1001B000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000003.00000002.2189790315.000000001001B000.00000020.00000001.01000000.00000010.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
1001B000
|
Size: |
8192
|
|
8E1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3104523539.00000000008E1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E1000
|
Size: |
4096
|
|
2D10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2389605352.0000000002D10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D10000
|
Size: |
4096
|
|
17EE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2194083944.00000000017EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
17EE000
|
Size: |
8192
|
|
26E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2195535677.00000000026E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
26E0000
|
Size: |
8192
|
|
8DC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3119398938.00000000008DC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DC000
|
Size: |
28672
|
|
30E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2194344228.00000000030E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30E0000
|
Size: |
20480
|
|
8DE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3209576839.00000000008DE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DE000
|
Size: |
20480
|
|
8EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3104407329.00000000008EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EA000
|
Size: |
24576
|
|
1459000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2192690800.0000000001459000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1459000
|
Size: |
8192
|
|
13E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2193504233.00000000013E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13E0000
|
Size: |
106496
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
10FF000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2195455415.00000000010FF000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
10FF000
|
Size: |
8192
|
|
922000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3362049615.0000000000922000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
922000
|
Size: |
12288
|
|
8E7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3214431469.00000000008E7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E7000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
FD0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.2112106452.0000000000FD0000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
FD0000
|
Size: |
4096
|
|
15AB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2189069192.00000000015AB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
15AB000
|
Size: |
49152
|
|
8E9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3277343022.00000000008E9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E9000
|
Size: |
24576
|
|
ADC000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2188846632.0000000000ADC000.00000002.00000001.01000000.00000009.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
ADC000
|
Size: |
20480
|
|
381E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2194602581.000000000381E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
381E000
|
Size: |
8192
|
|
6DE85000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2191370895.000000006DE85000.00000002.00000001.01000000.0000000A.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
6DE85000
|
Size: |
8192
|
|
8E9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3273375088.00000000008E9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E9000
|
Size: |
20480
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
8FC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3174711250.00000000008FC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FC000
|
Size: |
20480
|
|
1428000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2192867326.0000000001428000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1428000
|
Size: |
20480
|
|
142D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2192419126.000000000142D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
142D000
|
Size: |
176128
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
ADC000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.2135129800.0000000000ADC000.00000002.00000001.01000000.00000009.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
ADC000
|
Size: |
20480
|
|
6C850000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2190680073.000000006C850000.00000002.00000001.01000000.0000000D.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
6C850000
|
Size: |
4096
|
|
8D9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.2598636996.00000000008D9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8D9000
|
Size: |
4096
|
|
8FD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3120680301.00000000008FD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FD000
|
Size: |
8192
|
|
8DE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3104523539.00000000008DE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8DE000
|
Size: |
4096
|
|
3B0B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2194623578.0000000003B0B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3B0B000
|
Size: |
20480
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3354297313.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
4096
|
|
600000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3366000317.0000000000600000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
600000
|
Size: |
4096
|
|
141F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2192539376.000000000141F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
141F000
|
Size: |
4096
|
|
8F9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3232605693.00000000008F9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F9000
|
Size: |
4096
|
|
91E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3300589553.000000000091E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
91E000
|
Size: |
28672
|
|
13FA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2192903515.00000000013FA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13FA000
|
Size: |
4096
|
|
8EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3204418097.00000000008EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EA000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
8F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3260429837.00000000008F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F1000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3259556228.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
4096
|
|
6C840000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2190621149.000000006C840000.00000002.00000001.01000000.0000000F.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
6C840000
|
Size: |
36864
|
|
8F5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3300589553.00000000008F5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F5000
|
Size: |
16384
|
|
8D3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3131199577.00000000008D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8D3000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3279527208.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
4096
|
|
564F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3369901999.000000000564F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
564F000
|
Size: |
4096
|
|
8D9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3209624878.00000000008D9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8D9000
|
Size: |
8192
|
|
8E9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3274416057.00000000008E9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E9000
|
Size: |
36864
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
8B4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3366133731.00000000008B4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8B4000
|
Size: |
20480
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
8E3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3259586789.00000000008E3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E3000
|
Size: |
8192
|
|
AD0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2188757204.0000000000AD0000.00000002.00000001.01000000.00000009.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
AD0000
|
Size: |
4096
|
|
142E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2192539376.000000000142E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
142E000
|
Size: |
172032
|
|
254F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.2113000258.000000000254F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
254F000
|
Size: |
1048576
|
|
146E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.2191780541.000000000146E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
146E000
|
Size: |
45056
|
|
91C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3336512914.000000000091C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
91C000
|
Size: |
36864
|
|
8F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3273245939.00000000008F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F1000
|
Size: |
12288
|
|
1460000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2189007331.0000000001460000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1460000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
8ED000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3217386669.00000000008ED000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8ED000
|
Size: |
40960
|
|
922000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3349786515.0000000000922000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
922000
|
Size: |
12288
|
|
91A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3366133731.000000000091A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
91A000
|
Size: |
4096
|
|
F2D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3367548705.0000000000F2D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
F2D000
|
Size: |
12288
|
|
8CF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3353818349.00000000008CF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8CF000
|
Size: |
16384
|
|
8F8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3362288634.00000000008F8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F8000
|
Size: |
4096
|
|
922000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3359698304.0000000000922000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
922000
|
Size: |
4096
|
|
919000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3334028995.0000000000919000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
919000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
8EC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3214593761.00000000008EC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EC000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3258781198.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
4096
|
|
55BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3369816825.00000000055BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
55BE000
|
Size: |
8192
|
|
8D3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3349517763.00000000008D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8D3000
|
Size: |
12288
|
|
2D56000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2389626912.0000000002D56000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D56000
|
Size: |
12288
|
|
92F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2195128939.000000000092F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
92F000
|
Size: |
4096
|
|
12F6000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2188954139.00000000012F6000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
12F6000
|
Size: |
8192
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3336565204.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
4096
|
|
8F5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3274281345.00000000008F5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F5000
|
Size: |
12288
|
|