CD2000
|
unkown
|
page readonly
|
 |
|
|
Name: |
00000000.00000000.865114588.0000000000CD2000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
CD2000
|
Size: |
36864
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Found malware configuration |
AV Detection |
|
Yara detected Njrat |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
May infect USB drives |
Spreading |
Replication Through Removable Media
|
Yara signature match |
System Summary |
|
|
C94000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930379801.0000000000C94000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C94000
|
Size: |
24576
|
|
AFB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.934506352.0000000000AFB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
AFB000
|
Size: |
4096
|
|
1A70000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3318522902.0000000001A70000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1A70000
|
Size: |
8192
|
|
120A000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3317448514.000000000120A000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
120A000
|
Size: |
4096
|
|
C9D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930712607.0000000000C9D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C9D000
|
Size: |
196608
|
|
CD8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930067106.0000000000CD8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CD8000
|
Size: |
16384
|
|
C9E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930935125.0000000000C9E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C9E000
|
Size: |
40960
|
|
CFB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.933477004.0000000000CFB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CFB000
|
Size: |
20480
|
|
55BB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3320717826.00000000055BB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
55BB000
|
Size: |
20480
|
|
CAC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.931028246.0000000000CAC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CAC000
|
Size: |
20480
|
|
CA8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930921275.0000000000CA8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CA8000
|
Size: |
36864
|
|
CAA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.932514534.0000000000CAA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CAA000
|
Size: |
8192
|
|
C5C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.932321594.0000000000C5C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C5C000
|
Size: |
16384
|
|
CC3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930363113.0000000000CC3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CC3000
|
Size: |
24576
|
|
10F9000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3315862161.00000000010F9000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
10F9000
|
Size: |
28672
|
|
CB1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.933838275.0000000000CB1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CB1000
|
Size: |
40960
|
|
CBE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.934873107.0000000000CBE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CBE000
|
Size: |
8192
|
|
C9D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.933261859.0000000000C9D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C9D000
|
Size: |
20480
|
|
15D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3318291053.00000000015D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
15D0000
|
Size: |
65536
|
|
CAE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.932274191.0000000000CAE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CAE000
|
Size: |
32768
|
|
D09000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.933477004.0000000000D09000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D09000
|
Size: |
24576
|
|
CD3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930860813.0000000000CD3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CD3000
|
Size: |
69632
|
|
C7B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.933573261.0000000000C7B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C7B000
|
Size: |
139264
|
|
C9C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.929932002.0000000000C9C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C9C000
|
Size: |
270336
|
|
CC9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930750894.0000000000CC9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CC9000
|
Size: |
16384
|
|
AEE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.934506352.0000000000AEE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
AEE000
|
Size: |
8192
|
|
CC3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.933336156.0000000000CC3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CC3000
|
Size: |
102400
|
|
D0C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.933913245.0000000000D0C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D0C000
|
Size: |
12288
|
|
73B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.934424273.000000000073B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
73B000
|
Size: |
20480
|
|
CF7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.933179073.0000000000CF7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CF7000
|
Size: |
8192
|
|
C6A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930539003.0000000000C6A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C6A000
|
Size: |
499712
|
|
CE6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930539003.0000000000CE6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE6000
|
Size: |
4096
|
|
CBC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.931358009.0000000000CBC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CBC000
|
Size: |
28672
|
|
CDA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.934939615.0000000000CDA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CDA000
|
Size: |
8192
|
|
3458000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3318568599.0000000003458000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3458000
|
Size: |
24576
|
|
19C8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3318453478.00000000019C8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
19C8000
|
Size: |
8192
|
|
5295000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.933515295.0000000005295000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5295000
|
Size: |
81920
|
|
52A1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.933770763.00000000052A1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
52A1000
|
Size: |
12288
|
|
C56000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.932307218.0000000000C56000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C56000
|
Size: |
40960
|
|
C5C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930067106.0000000000C5C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C5C000
|
Size: |
12288
|
|
CAC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.932373998.0000000000CAC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CAC000
|
Size: |
8192
|
|
55FC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3320739028.00000000055FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
55FC000
|
Size: |
16384
|
|
34A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3318568599.00000000034A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
34A0000
|
Size: |
5246976
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
CDC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930023946.0000000000CDC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CDC000
|
Size: |
8192
|
|
5639000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3320764017.0000000005639000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5639000
|
Size: |
28672
|
|
CFC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930860813.0000000000CFC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CFC000
|
Size: |
16384
|
|
B40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.934630696.0000000000B40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B40000
|
Size: |
4096
|
|
5290000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.931720590.0000000005290000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5290000
|
Size: |
81920
|
|
C7B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.931372612.0000000000C7B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C7B000
|
Size: |
266240
|
|
CE6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930970400.0000000000CE6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE6000
|
Size: |
4096
|
|
CBD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.932622995.0000000000CBD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CBD000
|
Size: |
90112
|
|
CC2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.934888233.0000000000CC2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CC2000
|
Size: |
4096
|
|
CC3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.931241226.0000000000CC3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CC3000
|
Size: |
36864
|
|
C94000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.929932002.0000000000C94000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C94000
|
Size: |
24576
|
|
11C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3316020966.00000000011C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
11C0000
|
Size: |
8192
|
|
CC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.933823942.0000000000CC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CC0000
|
Size: |
12288
|
|
C60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.932228403.0000000000C60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C60000
|
Size: |
110592
|
|
12BA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3317605096.00000000012BA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12BA000
|
Size: |
151552
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
D6A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3315676011.0000000000D6A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
D6A000
|
Size: |
24576
|
|
BA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.934645437.0000000000BA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BA0000
|
Size: |
4096
|
|
CB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.934833575.0000000000CB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CB0000
|
Size: |
4096
|
|
52AA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.934034727.00000000052AA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
52AA000
|
Size: |
8192
|
|
CB8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930429162.0000000000CB8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CB8000
|
Size: |
16384
|
|
EDE000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000001.00000002.934974480.0000000000EDE000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
EDE000
|
Size: |
8192
|
|
CFC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930654754.0000000000CFC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CFC000
|
Size: |
16384
|
|
11EA000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3317226773.00000000011EA000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
11EA000
|
Size: |
4096
|
|
19BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3318435232.00000000019BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
19BE000
|
Size: |
8192
|
|
5251000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.931720590.0000000005251000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5251000
|
Size: |
212992
|
|
BB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.934660053.0000000000BB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BB0000
|
Size: |
16384
|
|
D08000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.932246825.0000000000D08000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D08000
|
Size: |
8192
|
|
11E2000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3317180114.00000000011E2000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
11E2000
|
Size: |
24576
|
|
529B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.935305478.000000000529B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
529B000
|
Size: |
8192
|
|
C30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.934304100.0000000000C30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C30000
|
Size: |
86016
|
|
CEA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930654754.0000000000CEA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CEA000
|
Size: |
8192
|
|
CD3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.931338212.0000000000CD3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CD3000
|
Size: |
184320
|
|
CB1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930827272.0000000000CB1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CB1000
|
Size: |
98304
|
|
CA3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.932429351.0000000000CA3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CA3000
|
Size: |
36864
|
|
C5F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.932392429.0000000000C5F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C5F000
|
Size: |
4096
|
|
11F7000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3317351600.00000000011F7000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
11F7000
|
Size: |
4096
|
|
5251000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.933134277.0000000005251000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5251000
|
Size: |
372736
|
|
CD3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.932496763.0000000000CD3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CD3000
|
Size: |
36864
|
|
52A7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.933855101.00000000052A7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
52A7000
|
Size: |
8192
|
|
CB2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.933892707.0000000000CB2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CB2000
|
Size: |
36864
|
|
DD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3315740485.0000000000DD0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DD0000
|
Size: |
4096
|
|
5250000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.935270522.0000000005250000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5250000
|
Size: |
4096
|
|
CD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930211544.0000000000CD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CD0000
|
Size: |
12288
|
|
C6A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.932392429.0000000000C6A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C6A000
|
Size: |
69632
|
|
D0E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.934957936.0000000000D0E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D0E000
|
Size: |
4096
|
|
C24000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.934689981.0000000000C24000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C24000
|
Size: |
45056
|
|
5293000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.932129866.0000000005293000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5293000
|
Size: |
8192
|
|
CCB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.933645082.0000000000CCB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CCB000
|
Size: |
69632
|
|
52A9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.933442538.00000000052A9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
52A9000
|
Size: |
12288
|
|
52A7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.934034727.00000000052A7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
52A7000
|
Size: |
8192
|
|
CB7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930350898.0000000000CB7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CB7000
|
Size: |
20480
|
|
52AB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.935319949.00000000052AB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
52AB000
|
Size: |
4096
|
|
11DA000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3317059518.00000000011DA000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
11DA000
|
Size: |
8192
|
|
11C7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3316020966.00000000011C7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
11C7000
|
Size: |
4096
|
|
1146000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.935150432.0000000001146000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1146000
|
Size: |
36864
|
|
5270000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.935284960.0000000005270000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5270000
|
Size: |
135168
|
|
C5B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930052351.0000000000C5B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C5B000
|
Size: |
16384
|
|
43E1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3320602129.00000000043E1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
43E1000
|
Size: |
24576
|
|
4B20000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.934220697.0000000004B20000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B20000
|
Size: |
4096
|
|
CEA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930970400.0000000000CEA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CEA000
|
Size: |
8192
|
|
CAD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.932482299.0000000000CAD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CAD000
|
Size: |
4096
|
|
CBB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.933803341.0000000000CBB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CBB000
|
Size: |
32768
|
|
CFC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930539003.0000000000CFC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CFC000
|
Size: |
16384
|
|
4D00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.935202244.0000000004D00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D00000
|
Size: |
4096
|
|
C9C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930379801.0000000000C9C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C9C000
|
Size: |
86016
|
|
C48000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.934727758.0000000000C48000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C48000
|
Size: |
53248
|
|
557D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3320690804.000000000557D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
557D000
|
Size: |
12288
|
|
1260000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3317605096.0000000001260000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1260000
|
Size: |
237568
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
514F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.935223433.000000000514F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
514F000
|
Size: |
4096
|
|
CB6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930843953.0000000000CB6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CB6000
|
Size: |
77824
|
|
CD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930750894.0000000000CD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CD0000
|
Size: |
81920
|
|
C5F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.933379205.0000000000C5F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C5F000
|
Size: |
4096
|
|
C59000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930067106.0000000000C59000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C59000
|
Size: |
8192
|
|
C5F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.929932002.0000000000C5F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C5F000
|
Size: |
208896
|
|
CB5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930429162.0000000000CB5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CB5000
|
Size: |
8192
|
|
1202000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3317417896.0000000001202000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1202000
|
Size: |
4096
|
|
5295000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.932045339.0000000005295000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5295000
|
Size: |
61440
|
|
CEA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930750894.0000000000CEA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CEA000
|
Size: |
8192
|
|
122A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3317605096.000000000122A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
122A000
|
Size: |
8192
|
|
C60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.933305425.0000000000C60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C60000
|
Size: |
249856
|
|
C9D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.932514534.0000000000C9D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C9D000
|
Size: |
24576
|
|
CD8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.933707220.0000000000CD8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CD8000
|
Size: |
16384
|
|
CAE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930475392.0000000000CAE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CAE000
|
Size: |
12288
|
|
CAD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.932514534.0000000000CAD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CAD000
|
Size: |
4096
|
|
CD9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.933723686.0000000000CD9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CD9000
|
Size: |
12288
|
|
CB2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.932463857.0000000000CB2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CB2000
|
Size: |
16384
|
|
5530000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3320674525.0000000005530000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5530000
|
Size: |
4096
|
|
C5A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.934762413.0000000000C5A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C5A000
|
Size: |
16384
|
|
C30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.934352043.0000000000C30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C30000
|
Size: |
86016
|
|
15E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3318328930.00000000015E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
15E0000
|
Size: |
12288
|
|
5292000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.933598994.0000000005292000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5292000
|
Size: |
12288
|
|
1880000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3318347216.0000000001880000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1880000
|
Size: |
12288
|
|
C7C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.934776268.0000000000C7C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C7C000
|
Size: |
135168
|
|
CAE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.933685408.0000000000CAE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CAE000
|
Size: |
86016
|
|
1140000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.935150432.0000000001140000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1140000
|
Size: |
16384
|
|
1220000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3317605096.0000000001220000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1220000
|
Size: |
36864
|
|
D0E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.934259539.0000000000D0E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D0E000
|
Size: |
4096
|
|
C68000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930067106.0000000000C68000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C68000
|
Size: |
172032
|
|
C6A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.934776268.0000000000C6A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C6A000
|
Size: |
69632
|
|
CA7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.931397876.0000000000CA7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CA7000
|
Size: |
86016
|
|
1890000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3318363020.0000000001890000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1890000
|
Size: |
8192
|
|
7A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.934441677.00000000007A0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A0000
|
Size: |
4096
|
|
CB5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.934856383.0000000000CB5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CB5000
|
Size: |
24576
|
|
C57000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.934084034.0000000000C57000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C57000
|
Size: |
28672
|
|
CA1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.931443538.0000000000CA1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CA1000
|
Size: |
24576
|
|
5150000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.935250514.0000000005150000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5150000
|
Size: |
40960
|
|
AFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.934506352.0000000000AFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
AFE000
|
Size: |
8192
|
|
CFC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.931068086.0000000000CFC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CFC000
|
Size: |
16384
|
|
33E1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3318568599.00000000033E1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33E1000
|
Size: |
217088
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May infect USB drives |
Spreading |
Replication Through Removable Media
|
|
529D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.932080416.000000000529D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
529D000
|
Size: |
28672
|
|
C6A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.931140987.0000000000C6A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C6A000
|
Size: |
614400
|
|
52A7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.933770763.00000000052A7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
52A7000
|
Size: |
8192
|
|
10F6000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3315862161.00000000010F6000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
10F6000
|
Size: |
8192
|
|
11E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3317132542.00000000011E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
11E0000
|
Size: |
8192
|
|
B3D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.934614497.0000000000B3D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B3D000
|
Size: |
12288
|
|
CC1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.934121840.0000000000CC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CC1000
|
Size: |
8192
|
|
C6A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.933379205.0000000000C6A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C6A000
|
Size: |
208896
|
|
FDE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.935013523.0000000000FDE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FDE000
|
Size: |
8192
|
|
CD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930285602.0000000000CD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CD0000
|
Size: |
12288
|
|
CB1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.932358016.0000000000CB1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CB1000
|
Size: |
20480
|
|
52A5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.932080416.00000000052A5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
52A5000
|
Size: |
20480
|
|
C5E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.933364426.0000000000C5E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C5E000
|
Size: |
8192
|
|
CDC000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.865135050.0000000000CDC000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
CDC000
|
Size: |
4096
|
|
C30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.934727758.0000000000C30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C30000
|
Size: |
86016
|
|
C57000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930539003.0000000000C57000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C57000
|
Size: |
32768
|
|
CE6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930654754.0000000000CE6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE6000
|
Size: |
4096
|
|
C7B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.932185435.0000000000C7B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C7B000
|
Size: |
241664
|
|
1A60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3318494224.0000000001A60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1A60000
|
Size: |
65536
|
|
CA9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930458760.0000000000CA9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CA9000
|
Size: |
32768
|
|
CC9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.931304417.0000000000CC9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CC9000
|
Size: |
12288
|
|
D09000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.934259539.0000000000D09000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D09000
|
Size: |
12288
|
|
13AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.935186118.00000000013AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
13AE000
|
Size: |
8192
|
|
121B000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3317571126.000000000121B000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
121B000
|
Size: |
4096
|
|
52A4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.933671066.00000000052A4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
52A4000
|
Size: |
20480
|
|
CBC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930335345.0000000000CBC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CBC000
|
Size: |
16384
|
|
CFB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.933179073.0000000000CFB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CFB000
|
Size: |
81920
|
|
CA7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.931028246.0000000000CA7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CA7000
|
Size: |
4096
|
|
529B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.932568472.000000000529B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
529B000
|
Size: |
8192
|
|
12A2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3317605096.00000000012A2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12A2000
|
Size: |
4096
|
|
CD8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930970400.0000000000CD8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CD8000
|
Size: |
49152
|
|
D00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.932246825.0000000000D00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D00000
|
Size: |
12288
|
|
CFC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930970400.0000000000CFC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CFC000
|
Size: |
16384
|
|
CB6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.932107972.0000000000CB6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CB6000
|
Size: |
155648
|
|
CAE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.931081606.0000000000CAE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CAE000
|
Size: |
12288
|
|
C7B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930949690.0000000000C7B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C7B000
|
Size: |
139264
|
|
7EE000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000001.00000002.934463931.00000000007EE000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7EE000
|
Size: |
8192
|
|
529B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.932129866.000000000529B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
529B000
|
Size: |
8192
|
|
D00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.933423230.0000000000D00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D00000
|
Size: |
61440
|
|
11F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3317307796.00000000011F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
11F0000
|
Size: |
4096
|
|
1217000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3317550177.0000000001217000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1217000
|
Size: |
4096
|
|
CB1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.931541620.0000000000CB1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CB1000
|
Size: |
45056
|
|
CAE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.931430492.0000000000CAE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CAE000
|
Size: |
57344
|
|
CD0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.865090162.0000000000CD0000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
CD0000
|
Size: |
4096
|
|
5291000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.933457809.0000000005291000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5291000
|
Size: |
98304
|
|
CC9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930197014.0000000000CC9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CC9000
|
Size: |
40960
|
|
C45000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.934100092.0000000000C45000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C45000
|
Size: |
65536
|
|
347C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3318568599.000000000347C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
347C000
|
Size: |
24576
|
|
CC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930320145.0000000000CC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CC0000
|
Size: |
36864
|
|
CC4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.934903908.0000000000CC4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CC4000
|
Size: |
28672
|
|
159E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3318208567.000000000159E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
159E000
|
Size: |
8192
|
|
52A5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.931720590.00000000052A5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
52A5000
|
Size: |
20480
|
|
C94000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930067106.0000000000C94000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C94000
|
Size: |
24576
|
|
CEA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930539003.0000000000CEA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CEA000
|
Size: |
8192
|
|
1212000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3317515768.0000000001212000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1212000
|
Size: |
4096
|
|
529D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.933855101.000000000529D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
529D000
|
Size: |
16384
|
|
1210000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3317485408.0000000001210000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1210000
|
Size: |
4096
|
|
CBB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.932335839.0000000000CBB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CBB000
|
Size: |
135168
|
|
D0A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.932172199.0000000000D0A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D0A000
|
Size: |
20480
|
|
CD3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.933723686.0000000000CD3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CD3000
|
Size: |
20480
|
|
1195000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3315935818.0000000001195000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1195000
|
Size: |
12288
|
|
BB5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.934660053.0000000000BB5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BB5000
|
Size: |
20480
|
|
CD8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930171181.0000000000CD8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CD8000
|
Size: |
16384
|
|
CEA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930860813.0000000000CEA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CEA000
|
Size: |
8192
|
|
CFE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.931557507.0000000000CFE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CFE000
|
Size: |
8192
|
|
C7B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930379801.0000000000C7B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C7B000
|
Size: |
94208
|
|
C6A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.932288799.0000000000C6A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C6A000
|
Size: |
69632
|
|
CFE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.932210906.0000000000CFE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CFE000
|
Size: |
20480
|
|
544F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.935336688.000000000544F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
544F000
|
Size: |
4096
|
|
11D2000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3316079849.00000000011D2000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
11D2000
|
Size: |
8192
|
|
C9D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.931417678.0000000000C9D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C9D000
|
Size: |
40960
|
|
1A80000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3318545558.0000000001A80000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
1A80000
|
Size: |
4096
|
|
CDC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.931691008.0000000000CDC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CDC000
|
Size: |
208896
|
|
C56000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.933930870.0000000000C56000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C56000
|
Size: |
32768
|
|
11EC000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3317264523.00000000011EC000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
11EC000
|
Size: |
4096
|
|
CD3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930171181.0000000000CD3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CD3000
|
Size: |
4096
|
|
D03000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.932157770.0000000000D03000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D03000
|
Size: |
49152
|
|
CAD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.933261859.0000000000CAD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CAD000
|
Size: |
192512
|
|
CE6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930860813.0000000000CE6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE6000
|
Size: |
4096
|
|
CAD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.932429351.0000000000CAD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CAD000
|
Size: |
4096
|
|
15B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3318245772.00000000015B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
15B0000
|
Size: |
16384
|
|
122E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3317605096.000000000122E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
122E000
|
Size: |
192512
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
C68000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930211544.0000000000C68000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C68000
|
Size: |
172032
|
|
56A0000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3320787611.00000000056A0000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
56A0000
|
Size: |
4096
|
|
CD4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930009148.0000000000CD4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CD4000
|
Size: |
40960
|
|
7F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.934490231.00000000007F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7F0000
|
Size: |
8192
|
|
12A8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3317605096.00000000012A8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12A8000
|
Size: |
4096
|
|
C94000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930211544.0000000000C94000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C94000
|
Size: |
24576
|
|
CCC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.931215295.0000000000CCC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CCC000
|
Size: |
212992
|
|
C9C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930067106.0000000000C9C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C9C000
|
Size: |
229376
|
|
5286000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.931720590.0000000005286000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5286000
|
Size: |
28672
|
|
C57000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930037487.0000000000C57000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C57000
|
Size: |
32768
|
|
3434000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3318568599.0000000003434000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3434000
|
Size: |
24576
|
|
1540000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3317887170.0000000001540000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1540000
|
Size: |
4096
|
|
C5C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.931257868.0000000000C5C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C5C000
|
Size: |
8192
|
|
CD4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.932584409.0000000000CD4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CD4000
|
Size: |
32768
|
|
11FA000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3317379587.00000000011FA000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
11FA000
|
Size: |
4096
|
|
C10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.934689981.0000000000C10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C10000
|
Size: |
69632
|
|
AF3000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.934506352.0000000000AF3000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
AF3000
|
Size: |
20480
|
|
CDC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.933179073.0000000000CDC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CDC000
|
Size: |
106496
|
|
DE0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3315793379.0000000000DE0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DE0000
|
Size: |
8192
|
|
52AA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.933515295.00000000052AA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
52AA000
|
Size: |
8192
|
|
529B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.933598994.000000000529B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
529B000
|
Size: |
57344
|
|
C21000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.934304100.0000000000C21000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C21000
|
Size: |
57344
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
C9C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930211544.0000000000C9C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C9C000
|
Size: |
184320
|
|
C56000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.931199794.0000000000C56000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C56000
|
Size: |
32768
|
|
CB1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930299597.0000000000CB1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CB1000
|
Size: |
98304
|
|
CAD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.934815910.0000000000CAD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CAD000
|
Size: |
4096
|
|
113E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.935130195.000000000113E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
113E000
|
Size: |
8192
|
|
52A5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.932045339.00000000052A5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
52A5000
|
Size: |
20480
|
|
CD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.934068803.0000000000CD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CD0000
|
Size: |
12288
|
|
CD1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.931304417.0000000000CD1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CD1000
|
Size: |
192512
|
|
CB4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.932605726.0000000000CB4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CB4000
|
Size: |
8192
|
|
CE6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930750894.0000000000CE6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE6000
|
Size: |
4096
|
|
CAD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.933234573.0000000000CAD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CAD000
|
Size: |
192512
|
|
CA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.931053775.0000000000CA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CA0000
|
Size: |
28672
|
|
CD1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.934922783.0000000000CD1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CD1000
|
Size: |
8192
|
|
CFC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930750894.0000000000CFC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CFC000
|
Size: |
16384
|
|
54DF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3320657464.00000000054DF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
54DF000
|
Size: |
4096
|
|
52AA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.933551390.00000000052AA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
52AA000
|
Size: |
8192
|
|
C6A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.931257868.0000000000C6A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C6A000
|
Size: |
364544
|
|
152E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3317863292.000000000152E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
152E000
|
Size: |
8192
|
|
1190000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3315935818.0000000001190000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1190000
|
Size: |
16384
|
|
CCD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.930654754.0000000000CCD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CCD000
|
Size: |
94208
|
|
18B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3318378017.00000000018B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
18B0000
|
Size: |
12288
|
|