502000
|
unkown
|
page readonly
|
 |
|
|
Name: |
00000000.00000000.1196267211.0000000000502000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
502000
|
Size: |
36864
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Found malware configuration |
AV Detection |
|
Yara detected Njrat |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
May infect USB drives |
Spreading |
Replication Through Removable Media
|
Yara signature match |
System Summary |
|
|
E4B000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3661550331.0000000000E4B000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
E4B000
|
Size: |
4096
|
|
8F3000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1268611279.00000000008F3000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8F3000
|
Size: |
20480
|
|
D53000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1261883545.0000000000D53000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D53000
|
Size: |
53248
|
|
D07000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1261308366.0000000000D07000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D07000
|
Size: |
221184
|
|
4EE9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1262250978.0000000004EE9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4EE9000
|
Size: |
12288
|
|
BE0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1270277237.0000000000BE0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BE0000
|
Size: |
8192
|
|
8FB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1268611279.00000000008FB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8FB000
|
Size: |
4096
|
|
4F1B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3662986543.0000000004F1B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4F1B000
|
Size: |
20480
|
|
4D1E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3662812422.0000000004D1E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4D1E000
|
Size: |
8192
|
|
ACE000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1268890701.0000000000ACE000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
ACE000
|
Size: |
8192
|
|
CB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1271752311.0000000000CB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CB0000
|
Size: |
40960
|
|
D1E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1264082955.0000000000D1E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D1E000
|
Size: |
159744
|
|
CD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1268033494.0000000000CD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CD0000
|
Size: |
81920
|
|
E32000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3661449285.0000000000E32000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
E32000
|
Size: |
4096
|
|
D1B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1260930840.0000000000D1B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D1B000
|
Size: |
16384
|
|
D4D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1261244602.0000000000D4D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D4D000
|
Size: |
8192
|
|
2C94000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3661774491.0000000002C94000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C94000
|
Size: |
24576
|
|
D3E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1260484586.0000000000D3E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D3E000
|
Size: |
81920
|
|
8EE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1268611279.00000000008EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8EE000
|
Size: |
8192
|
|
5FD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1268557009.00000000005FD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5FD000
|
Size: |
12288
|
|
500000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1196251354.0000000000500000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
500000
|
Size: |
4096
|
|
D56000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1273623477.0000000000D56000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D56000
|
Size: |
12288
|
|
2C43000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3661774491.0000000002C43000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C43000
|
Size: |
208896
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May infect USB drives |
Spreading |
Replication Through Removable Media
|
|
D53000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1261812856.0000000000D53000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D53000
|
Size: |
53248
|
|
D4A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1261812856.0000000000D4A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D4A000
|
Size: |
24576
|
|
4E1E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3662872401.0000000004E1E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4E1E000
|
Size: |
8192
|
|
CFF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1273471853.0000000000CFF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CFF000
|
Size: |
8192
|
|
D55000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1263686089.0000000000D55000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D55000
|
Size: |
16384
|
|
CF9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1261621019.0000000000CF9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CF9000
|
Size: |
4096
|
|
4EF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1265677899.0000000004EF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4EF4000
|
Size: |
16384
|
|
D4A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1260889663.0000000000D4A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D4A000
|
Size: |
12288
|
|
CF5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1261533515.0000000000CF5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CF5000
|
Size: |
20480
|
|
D4A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1264082955.0000000000D4A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D4A000
|
Size: |
413696
|
|
D4F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1273580946.0000000000D4F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D4F000
|
Size: |
24576
|
|
D52000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1261085886.0000000000D52000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D52000
|
Size: |
57344
|
|
C40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1270732180.0000000000C40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C40000
|
Size: |
16384
|
|
BDE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1269146849.0000000000BDE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BDE000
|
Size: |
8192
|
|
D55000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1266681437.0000000000D55000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D55000
|
Size: |
16384
|
|
CFC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1260298162.0000000000CFC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CFC000
|
Size: |
139264
|
|
DA7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1265490879.0000000000DA7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DA7000
|
Size: |
32768
|
|
D49000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1260797662.0000000000D49000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D49000
|
Size: |
16384
|
|
CF9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1260484586.0000000000CF9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CF9000
|
Size: |
12288
|
|
4EEB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1274044193.0000000004EEB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4EEB000
|
Size: |
4096
|
|
D9F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1264545900.0000000000D9F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D9F000
|
Size: |
65536
|
|
1210000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1267599998.0000000001210000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1210000
|
Size: |
4096
|
|
570000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1268476068.0000000000570000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
570000
|
Size: |
4096
|
|
D5D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1260619936.0000000000D5D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D5D000
|
Size: |
12288
|
|
D08000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1260381066.0000000000D08000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D08000
|
Size: |
90112
|
|
E12000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3661213833.0000000000E12000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
E12000
|
Size: |
20480
|
|
E8E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3661569260.0000000000E8E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
E8E000
|
Size: |
8192
|
|
11F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1273883513.00000000011F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11F0000
|
Size: |
4096
|
|
D25000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1260381066.0000000000D25000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D25000
|
Size: |
8192
|
|
2C86000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3661774491.0000000002C86000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C86000
|
Size: |
24576
|
|
D46000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1261577355.0000000000D46000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D46000
|
Size: |
106496
|
|
DA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1263628990.0000000000DA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DA0000
|
Size: |
16384
|
|
DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1262880386.0000000000DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DA4000
|
Size: |
20480
|
|
8FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1268611279.00000000008FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8FE000
|
Size: |
8192
|
|
5000000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3663070034.0000000005000000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5000000
|
Size: |
8192
|
|
D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1267227773.0000000000D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D01000
|
Size: |
20480
|
|
C60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1271602586.0000000000C60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C60000
|
Size: |
4096
|
|
910000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3660412464.0000000000910000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
910000
|
Size: |
4096
|
|
D05000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1260484586.0000000000D05000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D05000
|
Size: |
12288
|
|
4F99000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3663043324.0000000004F99000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4F99000
|
Size: |
28672
|
|
D4E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1261883545.0000000000D4E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D4E000
|
Size: |
8192
|
|
D4A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1261621019.0000000000D4A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D4A000
|
Size: |
90112
|
|
D4D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1260619936.0000000000D4D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D4D000
|
Size: |
20480
|
|
D3E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1261085886.0000000000D3E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D3E000
|
Size: |
69632
|
|
DA9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1262708471.0000000000DA9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DA9000
|
Size: |
24576
|
|
4EEC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1262067765.0000000004EEC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4EEC000
|
Size: |
45056
|
|
CF5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1260366717.0000000000CF5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CF5000
|
Size: |
28672
|
|
5D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3660188727.00000000005D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5D0000
|
Size: |
16384
|
|
CFB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1263047881.0000000000CFB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CFB000
|
Size: |
28672
|
|
AD5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1268940484.0000000000AD5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AD5000
|
Size: |
12288
|
|
CF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1273320333.0000000000CF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CF0000
|
Size: |
45056
|
|
D3E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1260811503.0000000000D3E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D3E000
|
Size: |
45056
|
|
AD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1268940484.0000000000AD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AD0000
|
Size: |
16384
|
|
4E90000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3662935011.0000000004E90000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4E90000
|
Size: |
4096
|
|
D5C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1260445043.0000000000D5C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D5C000
|
Size: |
16384
|
|
E47000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3661530711.0000000000E47000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
E47000
|
Size: |
4096
|
|
5BE000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1268519299.00000000005BE000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5BE000
|
Size: |
8192
|
|
4E80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3662899019.0000000004E80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4E80000
|
Size: |
65536
|
|
D50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1261783066.0000000000D50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D50000
|
Size: |
65536
|
|
D07000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1273521588.0000000000D07000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D07000
|
Size: |
81920
|
|
D07000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1267227773.0000000000D07000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D07000
|
Size: |
81920
|
|
D59000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1265969001.0000000000D59000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D59000
|
Size: |
159744
|
|
ED0000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3661589170.0000000000ED0000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
ED0000
|
Size: |
4096
|
|
D52000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1261244602.0000000000D52000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D52000
|
Size: |
57344
|
|
101E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3661657264.000000000101E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
101E000
|
Size: |
8192
|
|
DA1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1267003416.0000000000DA1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DA1000
|
Size: |
8192
|
|
D3E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1260930840.0000000000D3E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D3E000
|
Size: |
4096
|
|
D53000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1260619936.0000000000D53000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D53000
|
Size: |
36864
|
|
4EE7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1262397759.0000000004EE7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4EE7000
|
Size: |
8192
|
|
94E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3660508908.000000000094E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
94E000
|
Size: |
192512
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
BB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3660842500.0000000000BB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BB0000
|
Size: |
12288
|
|
8F9000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3660317588.00000000008F9000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8F9000
|
Size: |
28672
|
|
D40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1262959843.0000000000D40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D40000
|
Size: |
57344
|
|
1050000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3661751256.0000000001050000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1050000
|
Size: |
16384
|
|
D53000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1260484586.0000000000D53000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D53000
|
Size: |
36864
|
|
DA5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1267003416.0000000000DA5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DA5000
|
Size: |
8192
|
|
D1C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1266316231.0000000000D1C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D1C000
|
Size: |
8192
|
|
1030000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3661710757.0000000001030000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1030000
|
Size: |
12288
|
|
4D70000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1273981411.0000000004D70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D70000
|
Size: |
40960
|
|
CD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1273320333.0000000000CD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CD0000
|
Size: |
81920
|
|
CE5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1267373577.0000000000CE5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE5000
|
Size: |
90112
|
|
CC1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1268033494.0000000000CC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CC1000
|
Size: |
57344
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
DA8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1266276951.0000000000DA8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DA8000
|
Size: |
12288
|
|
4EC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1274009550.0000000004EC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4EC0000
|
Size: |
135168
|
|
2D00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3661774491.0000000002D00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D00000
|
Size: |
5246976
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
4F5C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3663010301.0000000004F5C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4F5C000
|
Size: |
16384
|
|
D05000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1261004962.0000000000D05000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D05000
|
Size: |
229376
|
|
D41000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1261714215.0000000000D41000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D41000
|
Size: |
20480
|
|
D44000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1263071151.0000000000D44000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D44000
|
Size: |
40960
|
|
D4A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1260919258.0000000000D4A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D4A000
|
Size: |
12288
|
|
BF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1270563993.0000000000BF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BF0000
|
Size: |
4096
|
|
D4F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1261068279.0000000000D4F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D4F000
|
Size: |
69632
|
|
E27000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3661365787.0000000000E27000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
E27000
|
Size: |
4096
|
|
59A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3660088518.000000000059A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
59A000
|
Size: |
24576
|
|
D09000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1261437365.0000000000D09000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D09000
|
Size: |
356352
|
|
D59000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1261275033.0000000000D59000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D59000
|
Size: |
28672
|
|
97F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3660508908.000000000097F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
97F000
|
Size: |
380928
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
4EEA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1262397759.0000000004EEA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4EEA000
|
Size: |
8192
|
|
D51000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1263250107.0000000000D51000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D51000
|
Size: |
32768
|
|
4EF6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1267156825.0000000004EF6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4EF6000
|
Size: |
8192
|
|
D3F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1260889663.0000000000D3F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D3F000
|
Size: |
40960
|
|
E10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3661143424.0000000000E10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
E10000
|
Size: |
8192
|
|
D09000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1260484586.0000000000D09000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D09000
|
Size: |
86016
|
|
50B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1268437236.000000000050B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
50B000
|
Size: |
20480
|
|
D5A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1263071151.0000000000D5A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D5A000
|
Size: |
303104
|
|
D5D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1260733598.0000000000D5D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D5D000
|
Size: |
12288
|
|
5D5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3660188727.00000000005D5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5D5000
|
Size: |
12288
|
|
E02000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3661059429.0000000000E02000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
E02000
|
Size: |
8192
|
|
D25000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1260484586.0000000000D25000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D25000
|
Size: |
8192
|
|
D25000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1260298162.0000000000D25000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D25000
|
Size: |
8192
|
|
DF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3660943147.0000000000DF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
DF0000
|
Size: |
8192
|
|
4EDD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3662955920.0000000004EDD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4EDD000
|
Size: |
12288
|
|
CEF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1268314402.0000000000CEF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CEF000
|
Size: |
49152
|
|
DA3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1266113305.0000000000DA3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DA3000
|
Size: |
4096
|
|
DF3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3660943147.0000000000DF3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
DF3000
|
Size: |
4096
|
|
1040000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3661731970.0000000001040000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1040000
|
Size: |
8192
|
|
D05000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1260870637.0000000000D05000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D05000
|
Size: |
12288
|
|
DA5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1266113305.0000000000DA5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DA5000
|
Size: |
8192
|
|
D5A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1263366318.0000000000D5A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D5A000
|
Size: |
303104
|
|
4EF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1265285779.0000000004EF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4EF0000
|
Size: |
32768
|
|
4EEB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1263200030.0000000004EEB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4EEB000
|
Size: |
4096
|
|
D5D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1273762328.0000000000D5D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D5D000
|
Size: |
143360
|
|
D09000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1260811503.0000000000D09000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D09000
|
Size: |
86016
|
|
D4A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1264545900.0000000000D4A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D4A000
|
Size: |
221184
|
|
D3E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1260298162.0000000000D3E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D3E000
|
Size: |
139264
|
|
D3E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1261004962.0000000000D3E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D3E000
|
Size: |
139264
|
|
D4A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1265559227.0000000000D4A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D4A000
|
Size: |
221184
|
|
DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1265383832.0000000000DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DA4000
|
Size: |
45056
|
|
DAB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1265821461.0000000000DAB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DAB000
|
Size: |
16384
|
|
4D6F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1273941823.0000000004D6F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4D6F000
|
Size: |
4096
|
|
4EF7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1274096292.0000000004EF7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4EF7000
|
Size: |
4096
|
|
D1B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1263489001.0000000000D1B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D1B000
|
Size: |
147456
|
|
D5A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1263250107.0000000000D5A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D5A000
|
Size: |
303104
|
|
8F6000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3660317588.00000000008F6000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8F6000
|
Size: |
8192
|
|
D09000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1261621019.0000000000D09000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D09000
|
Size: |
249856
|
|
4EEC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1265677899.0000000004EEC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4EEC000
|
Size: |
16384
|
|
DC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3660893283.0000000000DC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DC0000
|
Size: |
4096
|
|
4C6E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1273917953.0000000004C6E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4C6E000
|
Size: |
8192
|
|
D4A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1261714215.0000000000D4A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D4A000
|
Size: |
90112
|
|
E0A000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3661104062.0000000000E0A000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
E0A000
|
Size: |
8192
|
|
4EEB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1265073173.0000000004EEB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4EEB000
|
Size: |
53248
|
|
DA9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1273798781.0000000000DA9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DA9000
|
Size: |
8192
|
|
CFF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1263344678.0000000000CFF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CFF000
|
Size: |
12288
|
|
E3A000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3661480263.0000000000E3A000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
E3A000
|
Size: |
4096
|
|
D3E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1260381066.0000000000D3E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D3E000
|
Size: |
139264
|
|
CBB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1271752311.0000000000CBB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CBB000
|
Size: |
24576
|
|
D4D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1267442172.0000000000D4D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D4D000
|
Size: |
32768
|
|
D59000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1262310330.0000000000D59000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D59000
|
Size: |
352256
|
|
920000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3660465629.0000000000920000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
920000
|
Size: |
8192
|
|
4EE1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1265073173.0000000004EE1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4EE1000
|
Size: |
24576
|
|
2C41000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3661774491.0000000002C41000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C41000
|
Size: |
4096
|
|
D59000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1260733598.0000000000D59000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D59000
|
Size: |
12288
|
|
4C48000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3662775480.0000000004C48000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4C48000
|
Size: |
8192
|
|
D4E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1262838421.0000000000D4E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D4E000
|
Size: |
45056
|
|
D3E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1264545900.0000000000D3E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D3E000
|
Size: |
28672
|
|
E2A000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3661405573.0000000000E2A000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
E2A000
|
Size: |
4096
|
|
50C000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1196284337.000000000050C000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
50C000
|
Size: |
4096
|
|
4EF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1266425013.0000000004EF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4EF4000
|
Size: |
16384
|
|
4EE1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1263200030.0000000004EE1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4EE1000
|
Size: |
4096
|
|
3C41000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3662749486.0000000003C41000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3C41000
|
Size: |
24576
|
|
2CDC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3661774491.0000000002CDC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CDC000
|
Size: |
4096
|
|
DAE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1273860079.0000000000DAE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DAE000
|
Size: |
4096
|
|
D1B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1261934711.0000000000D1B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D1B000
|
Size: |
147456
|
|
948000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3660508908.0000000000948000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
948000
|
Size: |
16384
|
|
4EE7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1264883766.0000000004EE7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4EE7000
|
Size: |
69632
|
|
DA8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1266113305.0000000000DA8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DA8000
|
Size: |
12288
|
|
CC4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1271752311.0000000000CC4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CC4000
|
Size: |
45056
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
C46000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1270732180.0000000000C46000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C46000
|
Size: |
36864
|
|
1020000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3661677369.0000000001020000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1020000
|
Size: |
65536
|
|
D05000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1261085886.0000000000D05000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D05000
|
Size: |
229376
|
|
4EEB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1262936732.0000000004EEB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4EEB000
|
Size: |
4096
|
|
5010000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3663091659.0000000005010000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
5010000
|
Size: |
4096
|
|
CFA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1261437365.0000000000CFA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CFA000
|
Size: |
8192
|
|
D3F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1262911323.0000000000D3F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D3F000
|
Size: |
61440
|
|
D5D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1260484586.0000000000D5D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D5D000
|
Size: |
12288
|
|
940000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3660508908.0000000000940000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
940000
|
Size: |
24576
|
|
E1A000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3661268026.0000000000E1A000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
E1A000
|
Size: |
4096
|
|
4EE2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1262397759.0000000004EE2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4EE2000
|
Size: |
4096
|
|
CD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1268236672.0000000000CD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CD0000
|
Size: |
81920
|
|
D1B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1265433819.0000000000D1B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D1B000
|
Size: |
12288
|
|
D4A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1264304129.0000000000D4A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D4A000
|
Size: |
413696
|
|
D3E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1261353829.0000000000D3E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D3E000
|
Size: |
12288
|
|
D1B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1261353829.0000000000D1B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D1B000
|
Size: |
139264
|
|
D4A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1266316231.0000000000D4A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D4A000
|
Size: |
61440
|
|
D4A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1273554870.0000000000D4A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D4A000
|
Size: |
12288
|
|
CE8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1267707592.0000000000CE8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE8000
|
Size: |
77824
|
|
D51000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1263071151.0000000000D51000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D51000
|
Size: |
32768
|
|
F10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3661608851.0000000000F10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F10000
|
Size: |
12288
|
|
D80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1264489297.0000000000D80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D80000
|
Size: |
192512
|
|
2CB8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3661774491.0000000002CB8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CB8000
|
Size: |
4096
|
|
D06000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1266636804.0000000000D06000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D06000
|
Size: |
86016
|
|
E42000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3661508995.0000000000E42000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
E42000
|
Size: |
4096
|
|
D4A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1264933384.0000000000D4A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D4A000
|
Size: |
221184
|
|
DA9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1267003416.0000000000DA9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DA9000
|
Size: |
8192
|
|
D9F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1264841273.0000000000D9F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D9F000
|
Size: |
65536
|
|
D25000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1260811503.0000000000D25000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D25000
|
Size: |
8192
|
|
D3E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1261308366.0000000000D3E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D3E000
|
Size: |
12288
|
|
D41000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1261292482.0000000000D41000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D41000
|
Size: |
49152
|
|
D52000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1260467870.0000000000D52000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D52000
|
Size: |
40960
|
|
CFB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1266483731.0000000000CFB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CFB000
|
Size: |
131072
|
|
4EF5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1262197916.0000000004EF5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4EF5000
|
Size: |
8192
|
|
CE8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1273320333.0000000000CE8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE8000
|
Size: |
28672
|
|
D3F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1261812856.0000000000D3F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D3F000
|
Size: |
8192
|
|
4EE3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1262097875.0000000004EE3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4EE3000
|
Size: |
36864
|
|
D02000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1262985061.0000000000D02000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D02000
|
Size: |
249856
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1267707592.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|
D25000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1260930840.0000000000D25000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D25000
|
Size: |
8192
|
|
CF5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1261004962.0000000000CF5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CF5000
|
Size: |
16384
|
|
E1C000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3661311590.0000000000E1C000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
E1C000
|
Size: |
4096
|
|