482000
|
unkown
|
page readonly
|
 |
|
|
Name: |
00000000.00000000.1180996745.0000000000482000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
482000
|
Size: |
36864
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Found malware configuration |
AV Detection |
|
Yara detected Njrat |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
May infect USB drives |
Spreading |
Replication Through Removable Media
|
Yara signature match |
System Summary |
|
|
4DAC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3636252014.0000000004DAC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4DAC000
|
Size: |
16384
|
|
48C000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1181014463.000000000048C000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
48C000
|
Size: |
4096
|
|
9D9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1245268186.00000000009D9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D9000
|
Size: |
45056
|
|
BFE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3634681172.0000000000BFE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BFE000
|
Size: |
188416
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
A60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3634153673.0000000000A60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
A60000
|
Size: |
8192
|
|
4F8E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3636326079.0000000004F8E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4F8E000
|
Size: |
8192
|
|
4950000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1245502461.0000000004950000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4950000
|
Size: |
4096
|
|
52A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3636369750.00000000052A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
52A0000
|
Size: |
4096
|
|
4D00000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3636165524.0000000004D00000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
4D00000
|
Size: |
4096
|
|
BEE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3634642812.0000000000BEE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BEE000
|
Size: |
8192
|
|
E2E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3634983668.0000000000E2E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
E2E000
|
Size: |
8192
|
|
A97000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3634493707.0000000000A97000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
A97000
|
Size: |
4096
|
|
580000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3633745598.0000000000580000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
580000
|
Size: |
4096
|
|
2AFC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3635175885.0000000002AFC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AFC000
|
Size: |
5541888
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
9D8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1245094495.00000000009D8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D8000
|
Size: |
49152
|
|
A82000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3634365215.0000000000A82000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
A82000
|
Size: |
4096
|
|
4E8E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3636304788.0000000004E8E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4E8E000
|
Size: |
8192
|
|
9B5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1245216955.00000000009B5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9B5000
|
Size: |
40960
|
|
93B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1245152535.000000000093B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
93B000
|
Size: |
4096
|
|
C8C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3634681172.0000000000C8C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C8C000
|
Size: |
45056
|
|
F80000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3635124120.0000000000F80000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
F80000
|
Size: |
12288
|
|
C2E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3634681172.0000000000C2E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C2E000
|
Size: |
204800
|
|
A50000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3634111578.0000000000A50000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
A50000
|
Size: |
8192
|
|
92E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1245152535.000000000092E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
92E000
|
Size: |
12288
|
|
CF6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1245392122.0000000000CF6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CF6000
|
Size: |
36864
|
|
9E4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1245029152.00000000009E4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9E4000
|
Size: |
8192
|
|
52C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3636426873.00000000052C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
52C0000
|
Size: |
8192
|
|
A7A000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3634320821.0000000000A7A000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
A7A000
|
Size: |
8192
|
|
C98000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3634681172.0000000000C98000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C98000
|
Size: |
12288
|
|
480000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1180972149.0000000000480000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
480000
|
Size: |
4096
|
|
C61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3634681172.0000000000C61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C61000
|
Size: |
172032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
CAC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3634681172.0000000000CAC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CAC000
|
Size: |
81920
|
|
480E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1245488689.000000000480E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
480E000
|
Size: |
8192
|
|
4D23000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3636188796.0000000004D23000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D23000
|
Size: |
8192
|
|
9C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1245042416.00000000009C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9C0000
|
Size: |
147456
|
|
F50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3635085185.0000000000F50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F50000
|
Size: |
16384
|
|
F60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3635105046.0000000000F60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
F60000
|
Size: |
12288
|
|
50DF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1245570166.00000000050DF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
50DF000
|
Size: |
4096
|
|
F2E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3635026801.0000000000F2E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
F2E000
|
Size: |
8192
|
|
CCE000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1245353618.0000000000CCE000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CCE000
|
Size: |
8192
|
|
AE0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3634604916.0000000000AE0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AE0000
|
Size: |
20480
|
|
46EE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1245458653.00000000046EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
46EE000
|
Size: |
8192
|
|
4B5C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3636047368.0000000004B5C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4B5C000
|
Size: |
16384
|
|
3A81000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3635986153.0000000003A81000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3A81000
|
Size: |
28672
|
|
A92000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3634449886.0000000000A92000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
A92000
|
Size: |
4096
|
|
4E9F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1245513533.0000000004E9F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4E9F000
|
Size: |
4096
|
|
A37000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3633949797.0000000000A37000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
A37000
|
Size: |
4096
|
|
52B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3636396696.00000000052B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
52B0000
|
Size: |
4096
|
|
4C5E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3636094134.0000000004C5E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4C5E000
|
Size: |
8192
|
|
CAA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3634681172.0000000000CAA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CAA000
|
Size: |
4096
|
|
A8A000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3634408286.0000000000A8A000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
A8A000
|
Size: |
4096
|
|
5DE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3633836896.00000000005DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5DE000
|
Size: |
8192
|
|
A9B000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3634533577.0000000000A9B000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
A9B000
|
Size: |
4096
|
|
A77000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3634282113.0000000000A77000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
A77000
|
Size: |
4096
|
|
CD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1245377767.0000000000CD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CD0000
|
Size: |
4096
|
|
83B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1245138426.000000000083B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
83B000
|
Size: |
20480
|
|
5220000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3636349037.0000000005220000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5220000
|
Size: |
12288
|
|
935000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1245152535.0000000000935000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
935000
|
Size: |
12288
|
|
9A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1245216955.00000000009A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9A0000
|
Size: |
36864
|
|
A30000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3633949797.0000000000A30000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
A30000
|
Size: |
8192
|
|
4EA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1245538136.0000000004EA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4EA0000
|
Size: |
36864
|
|
4DE9000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3636279417.0000000004DE9000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4DE9000
|
Size: |
28672
|
|
9AA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1245216955.00000000009AA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9AA000
|
Size: |
32768
|
|
D00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1245421469.0000000000D00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D00000
|
Size: |
4096
|
|
BFA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3634681172.0000000000BFA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BFA000
|
Size: |
8192
|
|
9B2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1245042416.00000000009B2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9B2000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
A42000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3634030673.0000000000A42000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
A42000
|
Size: |
8192
|
|
93F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1245152535.000000000093F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
93F000
|
Size: |
4096
|
|
CF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1245392122.0000000000CF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CF0000
|
Size: |
16384
|
|
AB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1245328120.0000000000AB0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AB0000
|
Size: |
4096
|
|
BF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3634681172.0000000000BF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BF0000
|
Size: |
36864
|
|
4830000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1244994050.0000000004830000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4830000
|
Size: |
4096
|
|
AA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1245302283.0000000000AA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AA0000
|
Size: |
16384
|
|
2AD8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3635175885.0000000002AD8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AD8000
|
Size: |
24576
|
|
4FDE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1245552915.0000000004FDE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4FDE000
|
Size: |
8192
|
|
A4A000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3634071680.0000000000A4A000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
A4A000
|
Size: |
8192
|
|
AA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3634567537.0000000000AA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AA0000
|
Size: |
12288
|
|
A6A000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3634237584.0000000000A6A000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
A6A000
|
Size: |
12288
|
|
F90000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3635141336.0000000000F90000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F90000
|
Size: |
16384
|
|
4CEC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3636114102.0000000004CEC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4CEC000
|
Size: |
16384
|
|
51A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3633660563.000000000051A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
51A000
|
Size: |
24576
|
|
F96000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3635141336.0000000000F96000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F96000
|
Size: |
8192
|
|
4D6B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3636231802.0000000004D6B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4D6B000
|
Size: |
20480
|
|
4CF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3636135229.0000000004CF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4CF0000
|
Size: |
65536
|
|
8F6000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3633910345.00000000008F6000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8F6000
|
Size: |
40960
|
|
F40000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3635067209.0000000000F40000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
F40000
|
Size: |
12288
|
|
4A88000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3636011122.0000000004A88000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4A88000
|
Size: |
8192
|
|
7F410000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3636481822.000000007F410000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7F410000
|
Size: |
4096
|
|
AA5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1245302283.0000000000AA5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AA5000
|
Size: |
20480
|
|
590000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3633795113.0000000000590000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
590000
|
Size: |
8192
|
|
C9D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3634681172.0000000000C9D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C9D000
|
Size: |
49152
|
|
4D20000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3636188796.0000000004D20000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D20000
|
Size: |
4096
|
|
9C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1245268186.00000000009C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9C1000
|
Size: |
94208
|
|
F30000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3635042509.0000000000F30000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
F30000
|
Size: |
65536
|
|
9C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1245075548.00000000009C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9C0000
|
Size: |
147456
|
|
BCD000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1245341614.0000000000BCD000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
BCD000
|
Size: |
12288
|
|
2A81000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3635175885.0000000002A81000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A81000
|
Size: |
233472
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May infect USB drives |
Spreading |
Replication Through Removable Media
|
|
DFD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1245433730.0000000000DFD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
DFD000
|
Size: |
12288
|
|
A62000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3634188730.0000000000A62000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
A62000
|
Size: |
24576
|
|
E10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1245446130.0000000000E10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E10000
|
Size: |
4096
|
|