40E0000
|
direct allocation
|
page read and write
|
 |
|
|
Name: |
00000000.00000002.1381876704.00000000040E0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
40E0000
|
Size: |
98304
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected RedLine Stealer |
Stealing of Sensitive Information, Remote Access Functionality |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
Yara detected Credential Stealer |
Stealing of Sensitive Information |
|
Yara signature match |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
772000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
00000001.00000002.1528505566.0000000000772000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
772000
|
Size: |
102400
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected RedLine Stealer |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected Credential Stealer |
Stealing of Sensitive Information |
|
Yara signature match |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
5DB0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1537029034.0000000005DB0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5DB0000
|
Size: |
16384
|
|
6760000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1538919571.0000000006760000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
6760000
|
Size: |
4096
|
|
63F1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1538211855.00000000063F1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63F1000
|
Size: |
8192
|
|
4223000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1377689433.0000000004223000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4223000
|
Size: |
507904
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
1943000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1368187352.0000000001943000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1943000
|
Size: |
131072
|
|
1942000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1368040412.0000000001942000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1942000
|
Size: |
335872
|
|
70B3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1539612279.00000000070B3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
70B3000
|
Size: |
32768
|
|
5D6B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1536672063.0000000005D6B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5D6B000
|
Size: |
69632
|
|
15CF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1381123070.00000000015CF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
15CF000
|
Size: |
4096
|
|
2878000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529681672.0000000002878000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2878000
|
Size: |
4096
|
|
2760000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529681672.0000000002760000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2760000
|
Size: |
98304
|
|
6770000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1538942775.0000000006770000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6770000
|
Size: |
65536
|
|
26FC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529638406.00000000026FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
26FC000
|
Size: |
16384
|
|
4100000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1378118678.0000000004100000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4100000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
50CA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1534595771.00000000050CA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
50CA000
|
Size: |
8192
|
|
5D5E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1536611187.0000000005D5E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5D5E000
|
Size: |
12288
|
|
2781000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529681672.0000000002781000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2781000
|
Size: |
20480
|
|
1994000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1367947133.0000000001994000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1994000
|
Size: |
131072
|
|
5F18000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1537338369.0000000005F18000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F18000
|
Size: |
4096
|
|
92E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1528651367.000000000092E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
92E000
|
Size: |
8192
|
|
AAD000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1529062591.0000000000AAD000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
AAD000
|
Size: |
4096
|
|
63B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1538101251.00000000063B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63B0000
|
Size: |
36864
|
|
1918000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1381474548.0000000001918000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1918000
|
Size: |
176128
|
|
A51000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000002.1380741367.0000000000A51000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
A51000
|
Size: |
581632
|
|
43ED000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1380329190.00000000043ED000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
43ED000
|
Size: |
458752
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
604E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1537955115.000000000604E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
604E000
|
Size: |
8192
|
|
ADF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1380879103.0000000000ADF000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
ADF000
|
Size: |
147456
|
|
5DA0000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1537003746.0000000005DA0000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
5DA0000
|
Size: |
4096
|
|
5F8E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1537744328.0000000005F8E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5F8E000
|
Size: |
8192
|
|
6E80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1539276891.0000000006E80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6E80000
|
Size: |
4096
|
|
4FF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1534070130.0000000004FF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4FF0000
|
Size: |
65536
|
|
708B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1539455237.000000000708B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
708B000
|
Size: |
36864
|
|
2BE7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529681672.0000000002BE7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BE7000
|
Size: |
32768
|
|
4BC0000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1533002488.0000000004BC0000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
4BC0000
|
Size: |
4096
|
|
1840000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1381375663.0000000001840000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1840000
|
Size: |
4096
|
|
70A1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1539567786.00000000070A1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
70A1000
|
Size: |
65536
|
|
50B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1534527930.00000000050B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
50B0000
|
Size: |
65536
|
|
1A53000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1371466851.0000000001A53000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A53000
|
Size: |
98304
|
|
5F00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1537338369.0000000005F00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F00000
|
Size: |
4096
|
|
4BC3000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1533002488.0000000004BC3000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
4BC3000
|
Size: |
8192
|
|
43C9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1378240324.00000000043C9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
43C9000
|
Size: |
4096
|
|
5D90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1536954671.0000000005D90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5D90000
|
Size: |
65536
|
|
5F09000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1537338369.0000000005F09000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F09000
|
Size: |
8192
|
|
4E0E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1533081757.0000000004E0E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4E0E000
|
Size: |
8192
|
|
2C84000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529681672.0000000002C84000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C84000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
1993000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1381615694.0000000001993000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1993000
|
Size: |
507904
|
|
2787000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529681672.0000000002787000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2787000
|
Size: |
4096
|
|
1854000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1381394899.0000000001854000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1854000
|
Size: |
8192
|
|
5050000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1534397497.0000000005050000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5050000
|
Size: |
65536
|
|
517E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1534818755.000000000517E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
517E000
|
Size: |
8192
|
|
4CCE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1533042481.0000000004CCE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4CCE000
|
Size: |
8192
|
|
B17000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1380964236.0000000000B17000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B17000
|
Size: |
344064
|
|
2CAC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529681672.0000000002CAC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CAC000
|
Size: |
290816
|
|
A50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1528906903.0000000000A50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A50000
|
Size: |
4096
|
|
D70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529456759.0000000000D70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
D70000
|
Size: |
4096
|
|
5510000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1535016242.0000000005510000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5510000
|
Size: |
57344
|
|
60CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1538011775.00000000060CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
60CE000
|
Size: |
8192
|
|
50F0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1534752304.00000000050F0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
50F0000
|
Size: |
65536
|
|
6E30000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1539119550.0000000006E30000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
6E30000
|
Size: |
61440
|
|
5030000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1534302243.0000000005030000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5030000
|
Size: |
65536
|
|
43E9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1380329190.00000000043E9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
43E9000
|
Size: |
4096
|
|
1910000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1381474548.0000000001910000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1910000
|
Size: |
24576
|
|
639E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1538039796.000000000639E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
639E000
|
Size: |
8192
|
|
5D82000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1536802541.0000000005D82000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5D82000
|
Size: |
24576
|
|
4223000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1378118678.0000000004223000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4223000
|
Size: |
507904
|
|
1A92000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1371712560.0000000001A92000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A92000
|
Size: |
8192
|
|
A51000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000000.1367356540.0000000000A51000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
A51000
|
Size: |
581632
|
|
2B68000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529681672.0000000002B68000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B68000
|
Size: |
40960
|
|
39DB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1531735407.00000000039DB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
39DB000
|
Size: |
1662976
|
|
3784000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1531735407.0000000003784000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3784000
|
Size: |
835584
|
|
8EE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1528595542.00000000008EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8EE000
|
Size: |
8192
|
|
5F05000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1537338369.0000000005F05000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F05000
|
Size: |
12288
|
|
770000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1528505566.0000000000770000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
770000
|
Size: |
4096
|
|
6E50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1539186025.0000000006E50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6E50000
|
Size: |
65536
|
|
1933000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1368040412.0000000001933000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1933000
|
Size: |
49152
|
|
5020000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1534193561.0000000005020000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5020000
|
Size: |
65536
|
|
4100000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1377311226.0000000004100000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4100000
|
Size: |
1187840
|
|
AB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529077308.0000000000AB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
AB0000
|
Size: |
28672
|
|
5562000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1535387298.0000000005562000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5562000
|
Size: |
8192
|
|
43CD000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1378240324.00000000043CD000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
43CD000
|
Size: |
458752
|
|
529E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1534931621.000000000529E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
529E000
|
Size: |
8192
|
|
2C03000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529681672.0000000002C03000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C03000
|
Size: |
131072
|
|
70C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1539667292.00000000070C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
70C1000
|
Size: |
40960
|
|
4F5B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1533152172.0000000004F5B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4F5B000
|
Size: |
20480
|
|
443E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1378615585.000000000443E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
443E000
|
Size: |
24576
|
|
AA3000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1528996275.0000000000AA3000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
AA3000
|
Size: |
4096
|
|
1993000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1368187352.0000000001993000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1993000
|
Size: |
507904
|
|
50D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1534670218.00000000050D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
50D0000
|
Size: |
65536
|
|
287A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529681672.000000000287A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
287A000
|
Size: |
925696
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
ADF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1367443123.0000000000ADF000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
ADF000
|
Size: |
147456
|
|
B12000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.1367502838.0000000000B12000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
B12000
|
Size: |
8192
|
|
6530000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1538784617.0000000006530000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6530000
|
Size: |
65536
|
|
6740000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1538856068.0000000006740000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
6740000
|
Size: |
65536
|
|
67C6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1539034037.00000000067C6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
67C6000
|
Size: |
40960
|
|
4BB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1532932875.0000000004BB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4BB0000
|
Size: |
12288
|
|
72A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1539969409.00000000072A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
72A0000
|
Size: |
8192
|
|
E10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529490086.0000000000E10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E10000
|
Size: |
20480
|
|
6000000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1537914272.0000000006000000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
6000000
|
Size: |
65536
|
|
371E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1531735407.000000000371E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
371E000
|
Size: |
4096
|
|
4F61000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1533152172.0000000004F61000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4F61000
|
Size: |
16384
|
|
15DB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1381123070.00000000015DB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
15DB000
|
Size: |
20480
|
|
63F6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1538211855.00000000063F6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63F6000
|
Size: |
4096
|
|
6F80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1539322091.0000000006F80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6F80000
|
Size: |
12288
|
|
194A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1381474548.000000000194A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
194A000
|
Size: |
16384
|
|
6750000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1538900091.0000000006750000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6750000
|
Size: |
4096
|
|
17B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1381328689.00000000017B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17B0000
|
Size: |
20480
|
|
5CF2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1536095769.0000000005CF2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5CF2000
|
Size: |
4096
|
|
2965000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529681672.0000000002965000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2965000
|
Size: |
32768
|
|
194F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1371175229.000000000194F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
194F000
|
Size: |
28672
|
|
63C0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1538167348.00000000063C0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
63C0000
|
Size: |
65536
|
|
63F8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1538211855.00000000063F8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63F8000
|
Size: |
4096
|
|
18F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1381452556.00000000018F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
18F0000
|
Size: |
8192
|
|
1956000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1371738369.0000000001956000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1956000
|
Size: |
196608
|
|
5F2F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1537338369.0000000005F2F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F2F000
|
Size: |
4096
|
|
A50000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1380685526.0000000000A50000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
A50000
|
Size: |
4096
|
|
70BE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1539612279.00000000070BE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
70BE000
|
Size: |
8192
|
|
6E96000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1539296034.0000000006E96000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6E96000
|
Size: |
12288
|
|
5D8E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1536802541.0000000005D8E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5D8E000
|
Size: |
4096
|
|
295D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529681672.000000000295D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
295D000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
7FA80000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1540069795.000000007FA80000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7FA80000
|
Size: |
4096
|
|
4223000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1377311226.0000000004223000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4223000
|
Size: |
507904
|
|
4E4D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1533100903.0000000004E4D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4E4D000
|
Size: |
12288
|
|
5D10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1536095769.0000000005D10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5D10000
|
Size: |
135168
|
|
278F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529681672.000000000278F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
278F000
|
Size: |
925696
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
70D8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1539771783.00000000070D8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
70D8000
|
Size: |
36864
|
|
4243000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1378892654.0000000004243000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4243000
|
Size: |
507904
|
|
2BFD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529681672.0000000002BFD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BFD000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
5FE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1537802600.0000000005FE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5FE0000
|
Size: |
65536
|
|
42C0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1379038440.00000000042C0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
42C0000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
43E9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1379464159.00000000043E9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
43E9000
|
Size: |
4096
|
|
63E4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1538211855.00000000063E4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63E4000
|
Size: |
8192
|
|
42C0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1380329190.00000000042C0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
42C0000
|
Size: |
1196032
|
|
50A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1534442784.00000000050A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
50A0000
|
Size: |
65536
|
|
5040000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1534362257.0000000005040000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5040000
|
Size: |
53248
|
|
2B9E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529681672.0000000002B9E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B9E000
|
Size: |
290816
|
|
7D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1528578135.00000000007D0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7D0000
|
Size: |
4096
|
|
64B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1538671056.00000000064B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
64B0000
|
Size: |
65536
|
|
63A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1538060032.00000000063A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63A0000
|
Size: |
49152
|
|
5FCF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1537776675.0000000005FCF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5FCF000
|
Size: |
4096
|
|
B0E000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.1367502838.0000000000B0E000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
B0E000
|
Size: |
8192
|
|
BDF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529232768.0000000000BDF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BDF000
|
Size: |
4096
|
|
B04000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1367443123.0000000000B04000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B04000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary is likely a compiled AutoIt script file |
System Summary |
|
|
43ED000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1379038440.00000000043ED000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
43ED000
|
Size: |
458752
|
|
296E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529681672.000000000296E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
296E000
|
Size: |
1392640
|
|
1993000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1371175229.0000000001993000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1993000
|
Size: |
507904
|
|
7096000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1539455237.0000000007096000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7096000
|
Size: |
16384
|
|
7290000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1539949751.0000000007290000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7290000
|
Size: |
4096
|
|
2876000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529681672.0000000002876000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2876000
|
Size: |
4096
|
|
6520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1538741945.0000000006520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6520000
|
Size: |
65536
|
|
FF9000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1381035086.0000000000FF9000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FF9000
|
Size: |
28672
|
|
1A10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1381695499.0000000001A10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A10000
|
Size: |
241664
|
|
70CF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1539708945.00000000070CF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
70CF000
|
Size: |
4096
|
|
D78000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529456759.0000000000D78000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
D78000
|
Size: |
4096
|
|
3711000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1531735407.0000000003711000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3711000
|
Size: |
49152
|
|
5F25000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1537338369.0000000005F25000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F25000
|
Size: |
4096
|
|
2872000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529681672.0000000002872000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2872000
|
Size: |
12288
|
|
2C77000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529681672.0000000002C77000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C77000
|
Size: |
36864
|
|
5565000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1535387298.0000000005565000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5565000
|
Size: |
45056
|
|
64A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1538632458.00000000064A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
64A0000
|
Size: |
65536
|
|
194E000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1381543710.000000000194E000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
194E000
|
Size: |
16384
|
|
AC0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529108563.0000000000AC0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
AC0000
|
Size: |
4096
|
|
5532000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1535088717.0000000005532000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5532000
|
Size: |
12288
|
|
AD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529185025.0000000000AD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AD0000
|
Size: |
16384
|
|
210F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1381842322.000000000210F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
210F000
|
Size: |
4096
|
|
63D2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1538211855.00000000063D2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63D2000
|
Size: |
4096
|
|
177E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1381296882.000000000177E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
177E000
|
Size: |
8192
|
|
B0E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1380937589.0000000000B0E000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
B0E000
|
Size: |
36864
|
|
513D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1534789798.000000000513D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
513D000
|
Size: |
12288
|
|
250E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1381860912.000000000250E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
250E000
|
Size: |
8192
|
|
5C9C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1535599806.0000000005C9C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5C9C000
|
Size: |
4096
|
|
4FA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1533559456.0000000004FA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4FA0000
|
Size: |
65536
|
|
4BAE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1532914556.0000000004BAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4BAE000
|
Size: |
8192
|
|
2B16000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529681672.0000000002B16000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B16000
|
Size: |
290816
|
|
938000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1528669581.0000000000938000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
938000
|
Size: |
86016
|
|
63E8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1538211855.00000000063E8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63E8000
|
Size: |
4096
|
|
D00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529375083.0000000000D00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
D00000
|
Size: |
4096
|
|
15BF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1381123070.00000000015BF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
15BF000
|
Size: |
4096
|
|
5550000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1535267985.0000000005550000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5550000
|
Size: |
4096
|
|
6F84000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1539322091.0000000006F84000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6F84000
|
Size: |
20480
|
|
5D63000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1536672063.0000000005D63000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5D63000
|
Size: |
8192
|
|
4B50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1532857802.0000000004B50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4B50000
|
Size: |
8192
|
|
4F90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1533498304.0000000004F90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4F90000
|
Size: |
36864
|
|
D50000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1529404444.0000000000D50000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
D50000
|
Size: |
65536
|
|
5C8E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1535535894.0000000005C8E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5C8E000
|
Size: |
8192
|
|
6419000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1538572397.0000000006419000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6419000
|
Size: |
28672
|
|
445E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1379038440.000000000445E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
445E000
|
Size: |
24576
|
|
4243000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1380133115.0000000004243000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4243000
|
Size: |
507904
|
|
CE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529264210.0000000000CE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
CE0000
|
Size: |
4096
|
|
3864000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1531735407.0000000003864000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3864000
|
Size: |
966656
|
|
63D6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1538211855.00000000063D6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63D6000
|
Size: |
4096
|
|
E1B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529490086.0000000000E1B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E1B000
|
Size: |
16384
|
|
70D2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1539708945.00000000070D2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
70D2000
|
Size: |
8192
|
|
19B3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1368015239.00000000019B3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
19B3000
|
Size: |
4096
|
|
43CD000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1378615585.00000000043CD000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
43CD000
|
Size: |
458752
|
|
4223000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1378495546.0000000004223000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4223000
|
Size: |
507904
|
|
63DC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1538211855.00000000063DC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63DC000
|
Size: |
4096
|
|
5FF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1537865895.0000000005FF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5FF0000
|
Size: |
65536
|
|
50CD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1534595771.00000000050CD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
50CD000
|
Size: |
12288
|
|
1993000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1371738369.0000000001993000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1993000
|
Size: |
507904
|
|
196B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1368463892.000000000196B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
196B000
|
Size: |
98304
|
|
5290000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1534931621.0000000005290000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5290000
|
Size: |
36864
|
|
4120000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1380133115.0000000004120000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4120000
|
Size: |
1187840
|
|
2B7C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529681672.0000000002B7C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B7C000
|
Size: |
131072
|
|
67C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1539034037.00000000067C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
67C0000
|
Size: |
20480
|
|
1850000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1381394899.0000000001850000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1850000
|
Size: |
8192
|
|
63B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1528446530.000000000063B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
63B000
|
Size: |
20480
|
|
43CD000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1377813004.00000000043CD000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
43CD000
|
Size: |
458752
|
|
4BB4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1532932875.0000000004BB4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4BB4000
|
Size: |
20480
|
|
930000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1528669581.0000000000930000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
930000
|
Size: |
28672
|
|
608E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1537982553.000000000608E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
608E000
|
Size: |
8192
|
|
6410000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1538572397.0000000006410000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6410000
|
Size: |
32768
|
|
63DF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1538211855.00000000063DF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63DF000
|
Size: |
8192
|
|
799F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1540013543.000000000799F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
799F000
|
Size: |
4096
|
|
43CD000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1377436468.00000000043CD000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
43CD000
|
Size: |
458752
|
|
1A52000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1381695499.0000000001A52000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A52000
|
Size: |
4096
|
|
5D59000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1536095769.0000000005D59000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5D59000
|
Size: |
16384
|
|
1963000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1368120811.0000000001963000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1963000
|
Size: |
704512
|
|
480D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1532835534.000000000480D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
480D000
|
Size: |
12288
|
|
529B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1534931621.000000000529B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
529B000
|
Size: |
8192
|
|
63D4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1538211855.00000000063D4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63D4000
|
Size: |
4096
|
|
B04000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1380879103.0000000000B04000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B04000
|
Size: |
40960
|
|
43C9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1377813004.00000000043C9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
43C9000
|
Size: |
4096
|
|
5F1F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1537338369.0000000005F1F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F1F000
|
Size: |
12288
|
|
5560000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1535387298.0000000005560000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5560000
|
Size: |
4096
|
|
63BA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1538101251.00000000063BA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63BA000
|
Size: |
20480
|
|
7C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1528544685.00000000007C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7C0000
|
Size: |
16384
|
|
3743000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1531735407.0000000003743000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3743000
|
Size: |
180224
|
|
D60000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1529438800.0000000000D60000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
D60000
|
Size: |
4096
|
|
5CA4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1535599806.0000000005CA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5CA4000
|
Size: |
4096
|
|
6402000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1538211855.0000000006402000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6402000
|
Size: |
8192
|
|
443E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1378240324.000000000443E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
443E000
|
Size: |
24576
|
|
4243000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1379318536.0000000004243000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4243000
|
Size: |
507904
|
|
2C8A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529681672.0000000002C8A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C8A000
|
Size: |
131072
|
|
1956000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1368538325.0000000001956000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1956000
|
Size: |
86016
|
|
7C5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1528544685.00000000007C5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7C5000
|
Size: |
16384
|
|
4F81000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1533152172.0000000004F81000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4F81000
|
Size: |
49152
|
|
4B60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1532878460.0000000004B60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4B60000
|
Size: |
65536
|
|
6E20000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1539097021.0000000006E20000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6E20000
|
Size: |
4096
|
|
6F96000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1539322091.0000000006F96000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6F96000
|
Size: |
4096
|
|
E17000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529490086.0000000000E17000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E17000
|
Size: |
8192
|
|
967000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1528669581.0000000000967000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
967000
|
Size: |
368640
|
|
A50000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1367315122.0000000000A50000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
A50000
|
Size: |
4096
|
|
6405000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1538211855.0000000006405000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6405000
|
Size: |
36864
|
|
66DD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1538830009.00000000066DD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
66DD000
|
Size: |
12288
|
|
4F4E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1533120267.0000000004F4E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4F4E000
|
Size: |
8192
|
|
5DFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1537115235.0000000005DFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5DFE000
|
Size: |
8192
|
|
70ED000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1539827447.00000000070ED000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
70ED000
|
Size: |
81920
|
|
42A0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1377436468.00000000042A0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
42A0000
|
Size: |
1196032
|
|
63EE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1538211855.00000000063EE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63EE000
|
Size: |
4096
|
|
26BF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529583572.00000000026BF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
26BF000
|
Size: |
4096
|
|
A90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1528963353.0000000000A90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
A90000
|
Size: |
8192
|
|
AA4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529046376.0000000000AA4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
AA4000
|
Size: |
16384
|
|
5554000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1535267985.0000000005554000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5554000
|
Size: |
36864
|
|
42A0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1378615585.00000000042A0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
42A0000
|
Size: |
1196032
|
|
5D8A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1536802541.0000000005D8A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5D8A000
|
Size: |
8192
|
|
3722000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1531735407.0000000003722000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3722000
|
Size: |
4096
|
|
5540000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1535192060.0000000005540000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5540000
|
Size: |
65536
|
|
9D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1528669581.00000000009D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D0000
|
Size: |
389120
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
1993000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1368463892.0000000001993000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1993000
|
Size: |
507904
|
|
2700000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529658243.0000000002700000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2700000
|
Size: |
4096
|
|
445E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1380329190.000000000445E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
445E000
|
Size: |
24576
|
|
6F91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1539322091.0000000006F91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6F91000
|
Size: |
16384
|
|
2BF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529681672.0000000002BF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BF0000
|
Size: |
36864
|
|
443E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1377813004.000000000443E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
443E000
|
Size: |
24576
|
|
CDE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529249171.0000000000CDE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
CDE000
|
Size: |
8192
|
|
1660000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1381247696.0000000001660000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1660000
|
Size: |
4096
|
|
4D0E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1533061820.0000000004D0E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4D0E000
|
Size: |
8192
|
|
738000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1528489999.0000000000738000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
738000
|
Size: |
32768
|
|
6780000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1538991940.0000000006780000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6780000
|
Size: |
4096
|
|
651C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1538714937.000000000651C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
651C000
|
Size: |
16384
|
|
B17000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1367547226.0000000000B17000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B17000
|
Size: |
344064
|
|
AC6000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1529167373.0000000000AC6000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
AC6000
|
Size: |
40960
|
|
2AC3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529681672.0000000002AC3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AC3000
|
Size: |
327680
|
|
4F72000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1533152172.0000000004F72000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4F72000
|
Size: |
36864
|
|
2CF5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529681672.0000000002CF5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CF5000
|
Size: |
36864
|
|
1942000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1367980655.0000000001942000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1942000
|
Size: |
335872
|
|
5EFF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1537315256.0000000005EFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5EFF000
|
Size: |
4096
|
|
63FD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1538211855.00000000063FD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63FD000
|
Size: |
4096
|
|
445E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1379464159.000000000445E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
445E000
|
Size: |
24576
|
|
1993000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1371519548.0000000001993000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1993000
|
Size: |
507904
|
|
528E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1534893961.000000000528E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
528E000
|
Size: |
8192
|
|
6E70000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1539229741.0000000006E70000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
6E70000
|
Size: |
65536
|
|
2B76000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529681672.0000000002B76000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B76000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
50E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1534710515.00000000050E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
50E0000
|
Size: |
65536
|
|
295F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529681672.000000000295F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
295F000
|
Size: |
16384
|
|
5D7D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1536802541.0000000005D7D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5D7D000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
AV process strings found (often used to terminate AV products) |
Lowering of HIPS / PFW / Operating System Security Settings |
Security Software Discovery
|
|
42A0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1378240324.00000000042A0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
42A0000
|
Size: |
1196032
|
|
5180000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1534851791.0000000005180000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5180000
|
Size: |
65536
|
|
CEB000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1529359929.0000000000CEB000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
CEB000
|
Size: |
8192
|
|
CE7000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1529345734.0000000000CE7000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
CE7000
|
Size: |
4096
|
|
3964000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1531735407.0000000003964000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3964000
|
Size: |
139264
|
|
AC2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529151959.0000000000AC2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
AC2000
|
Size: |
4096
|
|
17FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1381353033.00000000017FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
17FE000
|
Size: |
8192
|
|
4FD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1533938867.0000000004FD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4FD0000
|
Size: |
65536
|
|
5F2A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1537338369.0000000005F2A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F2A000
|
Size: |
8192
|
|
D4E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529388910.0000000000D4E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
D4E000
|
Size: |
8192
|
|
AA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1528979283.0000000000AA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
AA0000
|
Size: |
12288
|
|
CE5000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1529292175.0000000000CE5000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
CE5000
|
Size: |
4096
|
|
2711000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529681672.0000000002711000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2711000
|
Size: |
319488
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4100000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1377689433.0000000004100000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4100000
|
Size: |
1187840
|
|
5F02000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1537338369.0000000005F02000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F02000
|
Size: |
8192
|
|
5530000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1535088717.0000000005530000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5530000
|
Size: |
4096
|
|
1A72000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1371572276.0000000001A72000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A72000
|
Size: |
139264
|
|
709D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1539455237.000000000709D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
709D000
|
Size: |
12288
|
|
42C0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1379464159.00000000042C0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
42C0000
|
Size: |
1196032
|
|
789E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1539991869.000000000789E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
789E000
|
Size: |
8192
|
|
6E40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1539158041.0000000006E40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6E40000
|
Size: |
20480
|
|
1A72000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1371466851.0000000001A72000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A72000
|
Size: |
139264
|
|
67A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1539012080.00000000067A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
67A0000
|
Size: |
8192
|
|
CE2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529278081.0000000000CE2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
CE2000
|
Size: |
4096
|
|
94E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1528669581.000000000094E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
94E000
|
Size: |
98304
|
|
1780000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1381314014.0000000001780000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1780000
|
Size: |
4096
|
|
5F1A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1537338369.0000000005F1A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F1A000
|
Size: |
8192
|
|
4BBA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1532932875.0000000004BBA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4BBA000
|
Size: |
24576
|
|
4120000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1379318536.0000000004120000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4120000
|
Size: |
1187840
|
|
5D32000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1536095769.0000000005D32000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5D32000
|
Size: |
147456
|
|
43ED000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1379464159.00000000043ED000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
43ED000
|
Size: |
458752
|
|
4F7E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1533152172.0000000004F7E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4F7E000
|
Size: |
8192
|
|
195C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1371175229.000000000195C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
195C000
|
Size: |
151552
|
|
A30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1528890747.0000000000A30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A30000
|
Size: |
12288
|
|
7084000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1539455237.0000000007084000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7084000
|
Size: |
20480
|
|
43E9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1379038440.00000000043E9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
43E9000
|
Size: |
4096
|
|
15FD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1381123070.00000000015FD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
15FD000
|
Size: |
12288
|
|
4100000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1378495546.0000000004100000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4100000
|
Size: |
1187840
|
|
1955000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1381543710.0000000001955000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
1955000
|
Size: |
4096
|
|
2B5E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529681672.0000000002B5E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B5E000
|
Size: |
36864
|
|
70E2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1539827447.00000000070E2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
70E2000
|
Size: |
32768
|
|
4F66000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1533152172.0000000004F66000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4F66000
|
Size: |
45056
|
|
43C9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1378615585.00000000043C9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
43C9000
|
Size: |
4096
|
|
4120000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1378892654.0000000004120000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4120000
|
Size: |
1187840
|
|
43C9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1377436468.00000000043C9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
43C9000
|
Size: |
4096
|
|
2C6E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529681672.0000000002C6E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C6E000
|
Size: |
32768
|
|
7102000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1539905636.0000000007102000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7102000
|
Size: |
65536
|
|
4FB1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1533896927.0000000004FB1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4FB1000
|
Size: |
61440
|
|
5CD2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1536095769.0000000005CD2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5CD2000
|
Size: |
126976
|
|
7080000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1539432744.0000000007080000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7080000
|
Size: |
4096
|
|
70D5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1539771783.00000000070D5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
70D5000
|
Size: |
8192
|
|
443E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1377436468.000000000443E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
443E000
|
Size: |
24576
|
|
2CFF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529681672.0000000002CFF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CFF000
|
Size: |
188416
|
|
ABD000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1529094766.0000000000ABD000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
ABD000
|
Size: |
4096
|
|
2C25000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1529681672.0000000002C25000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C25000
|
Size: |
290816
|
|
42A0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1377813004.00000000042A0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
42A0000
|
Size: |
1196032
|
|
4FE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1533974889.0000000004FE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4FE0000
|
Size: |
65536
|
|
4F50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1533152172.0000000004F50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4F50000
|
Size: |
36864
|
|