3020000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000002.00000002.1399255207.0000000003020000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3020000
|
Size: |
106496
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected RedLine Stealer |
Stealing of Sensitive Information, Remote Access Functionality |
|
|
402000
|
remote allocation
|
page execute and read and write
|
 |
|
|
Name: |
00000002.00000002.1397485445.0000000000402000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
402000
|
Size: |
102400
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected RedLine Stealer |
Stealing of Sensitive Information, Remote Access Functionality |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
Yara detected Credential Stealer |
Stealing of Sensitive Information |
|
Yara signature match |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
34E9000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000000.00000002.1236474263.00000000034E9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
34E9000
|
Size: |
2334720
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected RedLine Stealer |
Stealing of Sensitive Information, Remote Access Functionality |
|
Found many strings related to Crypto-Wallets (likely being stolen) |
Stealing of Sensitive Information |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
Yara detected Credential Stealer |
Stealing of Sensitive Information |
|
Yara signature match |
System Summary |
|
|
1520000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1398776742.0000000001520000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1520000
|
Size: |
16384
|
|
59B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1407817389.00000000059B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
59B0000
|
Size: |
65536
|
|
6A5A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1409972622.0000000006A5A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6A5A000
|
Size: |
8192
|
|
6885000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1409485963.0000000006885000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6885000
|
Size: |
8192
|
|
33CC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1399255207.00000000033CC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33CC000
|
Size: |
12288
|
|
510000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1234553386.0000000000510000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
510000
|
Size: |
4096
|
|
415F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1402286988.000000000415F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
415F000
|
Size: |
4096
|
|
3FE2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1402286988.0000000003FE2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3FE2000
|
Size: |
8192
|
|
4451000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1402286988.0000000004451000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4451000
|
Size: |
954368
|
|
C30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1235859102.0000000000C30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C30000
|
Size: |
24576
|
|
576B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1238744632.000000000576B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
576B000
|
Size: |
24576
|
|
6B50000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1410578125.0000000006B50000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
6B50000
|
Size: |
65536
|
|
4FD8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1406459845.0000000004FD8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4FD8000
|
Size: |
8192
|
|
4980000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1237307259.0000000004980000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4980000
|
Size: |
4096
|
|
2E84000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1399025072.0000000002E84000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E84000
|
Size: |
20480
|
|
82B000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1235451040.000000000082B000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
82B000
|
Size: |
4096
|
|
4C10000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1238241501.0000000004C10000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
4C10000
|
Size: |
4096
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1407429567.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
65536
|
|
49D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1237662278.00000000049D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
49D0000
|
Size: |
65536
|
|
632000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1234677955.0000000000632000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
632000
|
Size: |
28672
|
|
7AF0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1413791535.0000000007AF0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7AF0000
|
Size: |
65536
|
|
71C0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1239701138.00000000071C0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
71C0000
|
Size: |
49152
|
|
72F0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1412863923.00000000072F0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
72F0000
|
Size: |
65536
|
|
6882000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1409460251.0000000006882000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6882000
|
Size: |
8192
|
|
59CA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1407903570.00000000059CA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
59CA000
|
Size: |
8192
|
|
5E2D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1408586992.0000000005E2D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5E2D000
|
Size: |
12288
|
|
6A85000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1410277918.0000000006A85000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6A85000
|
Size: |
45056
|
|
6816000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1408982844.0000000006816000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6816000
|
Size: |
4096
|
|
305D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1399255207.000000000305D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
305D000
|
Size: |
4096
|
|
2E80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1399025072.0000000002E80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E80000
|
Size: |
12288
|
|
C38000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1235859102.0000000000C38000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C38000
|
Size: |
28672
|
|
4A00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1237853150.0000000004A00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4A00000
|
Size: |
65536
|
|
6F90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1411833273.0000000006F90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6F90000
|
Size: |
65536
|
|
6868000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1409328424.0000000006868000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6868000
|
Size: |
8192
|
|
5772000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1238744632.0000000005772000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5772000
|
Size: |
77824
|
|
6F3C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1411019930.0000000006F3C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6F3C000
|
Size: |
4096
|
|
5F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1234677955.00000000005F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5F0000
|
Size: |
28672
|
|
414D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1402286988.000000000414D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
414D000
|
Size: |
4096
|
|
5C5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1234628633.00000000005C5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5C5000
|
Size: |
12288
|
|
6A45000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1409972622.0000000006A45000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6A45000
|
Size: |
12288
|
|
121E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1397770285.000000000121E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
121E000
|
Size: |
8192
|
|
14A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1398322212.00000000014A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
14A0000
|
Size: |
12288
|
|
4D20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1238352164.0000000004D20000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4D20000
|
Size: |
65536
|
|
70E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1412311956.00000000070E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
70E0000
|
Size: |
32768
|
|
7300000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1412961100.0000000007300000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7300000
|
Size: |
4096
|
|
72B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1412656984.00000000072B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
72B0000
|
Size: |
65536
|
|
5B90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1408497201.0000000005B90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5B90000
|
Size: |
36864
|
|
6F65000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1411019930.0000000006F65000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6F65000
|
Size: |
36864
|
|
4F8E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1238664941.0000000004F8E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4F8E000
|
Size: |
8192
|
|
72A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1412549906.00000000072A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
72A0000
|
Size: |
65536
|
|
14D7000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1398628697.00000000014D7000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
14D7000
|
Size: |
4096
|
|
6F80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1411764992.0000000006F80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6F80000
|
Size: |
65536
|
|
2EB0000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1399185117.0000000002EB0000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
2EB0000
|
Size: |
4096
|
|
576E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1406773604.000000000576E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
576E000
|
Size: |
8192
|
|
6F34000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1411019930.0000000006F34000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6F34000
|
Size: |
4096
|
|
6A6F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1409972622.0000000006A6F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6A6F000
|
Size: |
4096
|
|
2E90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1399108121.0000000002E90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E90000
|
Size: |
36864
|
|
68A2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1409618932.00000000068A2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
68A2000
|
Size: |
16384
|
|
1460000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1398277641.0000000001460000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1460000
|
Size: |
4096
|
|
71B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1239655788.00000000071B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
71B0000
|
Size: |
65536
|
|
784A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1413067474.000000000784A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
784A000
|
Size: |
49152
|
|
4175000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1402286988.0000000004175000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4175000
|
Size: |
8192
|
|
6A42000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1409972622.0000000006A42000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6A42000
|
Size: |
8192
|
|
7F3000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1235032042.00000000007F3000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7F3000
|
Size: |
4096
|
|
5886000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1406847468.0000000005886000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5886000
|
Size: |
45056
|
|
1289000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1397819004.0000000001289000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1289000
|
Size: |
53248
|
|
3FFB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1402286988.0000000003FFB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3FFB000
|
Size: |
8192
|
|
4152000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1402286988.0000000004152000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4152000
|
Size: |
20480
|
|
6F48000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1411019930.0000000006F48000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6F48000
|
Size: |
4096
|
|
59A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1407733203.00000000059A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
59A0000
|
Size: |
65536
|
|
870000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1235579048.0000000000870000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
870000
|
Size: |
4096
|
|
5881000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1406847468.0000000005881000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5881000
|
Size: |
16384
|
|
6D30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1239331429.0000000006D30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6D30000
|
Size: |
53248
|
|
413D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1402286988.000000000413D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
413D000
|
Size: |
8192
|
|
58F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1407307414.00000000058F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
58F0000
|
Size: |
65536
|
|
AFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1235733227.0000000000AFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
AFE000
|
Size: |
8192
|
|
3FF4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1402286988.0000000003FF4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3FF4000
|
Size: |
8192
|
|
58D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1407175426.00000000058D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
58D0000
|
Size: |
65536
|
|
49A6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1237429904.00000000049A6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
49A6000
|
Size: |
40960
|
|
6F40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1239468221.0000000006F40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6F40000
|
Size: |
8192
|
|
27B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1235911398.00000000027B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
27B0000
|
Size: |
16384
|
|
4159000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1402286988.0000000004159000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4159000
|
Size: |
8192
|
|
72C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1412762487.00000000072C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
72C0000
|
Size: |
65536
|
|
6A82000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1410277918.0000000006A82000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6A82000
|
Size: |
8192
|
|
493E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1237174014.000000000493E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
493E000
|
Size: |
8192
|
|
86C6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1239873041.00000000086C6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
86C6000
|
Size: |
49152
|
|
3FE8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1402286988.0000000003FE8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3FE8000
|
Size: |
16384
|
|
68B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1409690878.00000000068B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
68B0000
|
Size: |
57344
|
|
125E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1397793786.000000000125E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
125E000
|
Size: |
8192
|
|
59CD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1407903570.00000000059CD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
59CD000
|
Size: |
12288
|
|
59F0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1408181865.00000000059F0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
59F0000
|
Size: |
65536
|
|
59E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1408092777.00000000059E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
59E0000
|
Size: |
65536
|
|
B3C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1235748045.0000000000B3C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B3C000
|
Size: |
16384
|
|
682E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1408982844.000000000682E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
682E000
|
Size: |
233472
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
AV process strings found (often used to terminate AV products) |
Lowering of HIPS / PFW / Operating System Security Settings |
Security Software Discovery
|
|
6F20000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1410999288.0000000006F20000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6F20000
|
Size: |
4096
|
|
67C4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1408796220.00000000067C4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
67C4000
|
Size: |
4096
|
|
6F36000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1411019930.0000000006F36000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6F36000
|
Size: |
4096
|
|
14BD000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1398449783.00000000014BD000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
14BD000
|
Size: |
4096
|
|
67B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1408796220.00000000067B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
67B0000
|
Size: |
4096
|
|
5C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1234628633.00000000005C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5C0000
|
Size: |
16384
|
|
81A000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1235394662.000000000081A000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
81A000
|
Size: |
4096
|
|
AE3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1240393952.000000000AE3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
AE3E000
|
Size: |
8192
|
|
810000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1235308272.0000000000810000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
810000
|
Size: |
4096
|
|
692E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1409890993.000000000692E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
692E000
|
Size: |
8192
|
|
33A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1399255207.00000000033A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33A0000
|
Size: |
4096
|
|
6A3F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1409949212.0000000006A3F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6A3F000
|
Size: |
4096
|
|
827000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1235431969.0000000000827000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
827000
|
Size: |
4096
|
|
6A74000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1410210393.0000000006A74000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6A74000
|
Size: |
36864
|
|
7028000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1412202119.0000000007028000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7028000
|
Size: |
32768
|
|
4A80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1238069657.0000000004A80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4A80000
|
Size: |
8192
|
|
4F7000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1234522229.00000000004F7000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4F7000
|
Size: |
36864
|
|
67F2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1408982844.00000000067F2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
67F2000
|
Size: |
118784
|
|
5950000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1407570224.0000000005950000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5950000
|
Size: |
65536
|
|
689D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1409592217.000000000689D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
689D000
|
Size: |
8192
|
|
822000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1235412972.0000000000822000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
822000
|
Size: |
4096
|
|
7C1D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1413908139.0000000007C1D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7C1D000
|
Size: |
12288
|
|
4351000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1402286988.0000000004351000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4351000
|
Size: |
954368
|
|
1500000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1398701939.0000000001500000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1500000
|
Size: |
65536
|
|
68D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1409776535.00000000068D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
68D0000
|
Size: |
4096
|
|
6A5F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1409972622.0000000006A5F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6A5F000
|
Size: |
8192
|
|
92BA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1414199752.00000000092BA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
92BA000
|
Size: |
4096
|
|
DC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1397611195.0000000000DC0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DC0000
|
Size: |
4096
|
|
68D2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1409776535.00000000068D2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
68D2000
|
Size: |
12288
|
|
7010000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1412087229.0000000007010000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7010000
|
Size: |
65536
|
|
3370000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1399255207.0000000003370000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3370000
|
Size: |
12288
|
|
49A2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1237429904.00000000049A2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
49A2000
|
Size: |
12288
|
|
4166000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1402286988.0000000004166000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4166000
|
Size: |
4096
|
|
68A8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1409650045.00000000068A8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
68A8000
|
Size: |
28672
|
|
6A65000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1409972622.0000000006A65000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6A65000
|
Size: |
4096
|
|
1510000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1398751340.0000000001510000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1510000
|
Size: |
8192
|
|
6920000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1238899476.0000000006920000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
6920000
|
Size: |
4096
|
|
1810000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1398889174.0000000001810000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
1810000
|
Size: |
4096
|
|
6870000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1409390908.0000000006870000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6870000
|
Size: |
61440
|
|
24F5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1235911398.00000000024F5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24F5000
|
Size: |
966656
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
516D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1406563599.000000000516D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
516D000
|
Size: |
12288
|
|
7290000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1412456820.0000000007290000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7290000
|
Size: |
65536
|
|
14C2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1398499695.00000000014C2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
14C2000
|
Size: |
4096
|
|
63A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1234677955.000000000063A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
63A000
|
Size: |
139264
|
|
4002000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1402286988.0000000004002000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4002000
|
Size: |
192512
|
|
1268000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1397819004.0000000001268000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1268000
|
Size: |
86016
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
4E4E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1238580954.0000000004E4E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4E4E000
|
Size: |
8192
|
|
DD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1397641472.0000000000DD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DD0000
|
Size: |
12288
|
|
7E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1234992462.00000000007E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7E0000
|
Size: |
8192
|
|
25E5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1235911398.00000000025E5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
25E5000
|
Size: |
1871872
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
56D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1234593164.000000000056D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
56D000
|
Size: |
12288
|
|
58A1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1406847468.00000000058A1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
58A1000
|
Size: |
49152
|
|
4941000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1237174014.0000000004941000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4941000
|
Size: |
16384
|
|
ABE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1235717407.0000000000ABE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
ABE000
|
Size: |
8192
|
|
5F8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1234677955.00000000005F8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5F8000
|
Size: |
16384
|
|
562E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1406732537.000000000562E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
562E000
|
Size: |
8192
|
|
D5B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1397575328.0000000000D5B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
D5B000
|
Size: |
20480
|
|
6F1E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1410979261.0000000006F1E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6F1E000
|
Size: |
8192
|
|
7310000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1239793244.0000000007310000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7310000
|
Size: |
12288
|
|
618000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1234677955.0000000000618000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
618000
|
Size: |
65536
|
|
66AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1408747329.00000000066AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
66AE000
|
Size: |
8192
|
|
5B8F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1408465308.0000000005B8F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5B8F000
|
Size: |
4096
|
|
1260000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1397819004.0000000001260000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1260000
|
Size: |
28672
|
|
1298000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1397819004.0000000001298000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1298000
|
Size: |
397312
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
6F32000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1411019930.0000000006F32000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6F32000
|
Size: |
4096
|
|
55EF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1406681847.00000000055EF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
55EF000
|
Size: |
4096
|
|
662000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1234677955.0000000000662000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
662000
|
Size: |
4096
|
|
7840000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1413005087.0000000007840000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7840000
|
Size: |
28672
|
|
70D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1412311956.00000000070D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
70D0000
|
Size: |
36864
|
|
58E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1407234276.00000000058E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
58E0000
|
Size: |
65536
|
|
3061000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1399255207.0000000003061000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3061000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
414A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1402286988.000000000414A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
414A000
|
Size: |
4096
|
|
2EA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1399143344.0000000002EA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EA0000
|
Size: |
65536
|
|
6F3F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1411019930.0000000006F3F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6F3F000
|
Size: |
8192
|
|
6A6A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1409972622.0000000006A6A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6A6A000
|
Size: |
8192
|
|
41A8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1402286988.00000000041A8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
41A8000
|
Size: |
4096
|
|
787C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1413128661.000000000787C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
787C000
|
Size: |
20480
|
|
8A5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1235638233.00000000008A5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8A5000
|
Size: |
45056
|
|
4185000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1402286988.0000000004185000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4185000
|
Size: |
4096
|
|
14C6000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1398522555.00000000014C6000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
14C6000
|
Size: |
40960
|
|
65E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1234677955.000000000065E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
65E000
|
Size: |
8192
|
|
6F44000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1411019930.0000000006F44000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6F44000
|
Size: |
8192
|
|
3207000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1399255207.0000000003207000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3207000
|
Size: |
413696
|
|
6930000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1409915679.0000000006930000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
6930000
|
Size: |
16384
|
|
5E6E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1408633320.0000000005E6E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5E6E000
|
Size: |
8192
|
|
35DA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1399255207.00000000035DA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
35DA000
|
Size: |
139264
|
|
1820000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1398909918.0000000001820000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1820000
|
Size: |
20480
|
|
859E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1414058077.000000000859E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
859E000
|
Size: |
8192
|
|
7FD000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1235075178.00000000007FD000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7FD000
|
Size: |
4096
|
|
880000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1235593315.0000000000880000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
880000
|
Size: |
65536
|
|
890000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1235615404.0000000000890000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
890000
|
Size: |
65536
|
|
80D000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1235288100.000000000080D000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
80D000
|
Size: |
4096
|
|
67CC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1408796220.00000000067CC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
67CC000
|
Size: |
4096
|
|
17FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1398824721.00000000017FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
17FE000
|
Size: |
8192
|
|
6A70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1410210393.0000000006A70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6A70000
|
Size: |
4096
|
|
14A4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1398366739.00000000014A4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
14A4000
|
Size: |
16384
|
|
2E8A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1399025072.0000000002E8A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E8A000
|
Size: |
24576
|
|
5A3D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1408256661.0000000005A3D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5A3D000
|
Size: |
12288
|
|
7883000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1413128661.0000000007883000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7883000
|
Size: |
4096
|
|
4F90000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1238684259.0000000004F90000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
4F90000
|
Size: |
45056
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
574F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1238725357.000000000574F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
574F000
|
Size: |
4096
|
|
730E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1239767262.000000000730E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
730E000
|
Size: |
8192
|
|
6A40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1409972622.0000000006A40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6A40000
|
Size: |
4096
|
|
6F5D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1411019930.0000000006F5D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6F5D000
|
Size: |
4096
|
|
7A50000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1413486136.0000000007A50000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7A50000
|
Size: |
4096
|
|
700C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1412016692.000000000700C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
700C000
|
Size: |
16384
|
|
5D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1234662615.00000000005D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5D0000
|
Size: |
4096
|
|
4C00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1238207607.0000000004C00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4C00000
|
Size: |
65536
|
|
7AC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1413702094.0000000007AC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7AC0000
|
Size: |
4096
|
|
7F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1235014625.00000000007F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7F0000
|
Size: |
8192
|
|
6910000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1238866238.0000000006910000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
6910000
|
Size: |
65536
|
|
5870000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1406847468.0000000005870000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5870000
|
Size: |
36864
|
|
7314000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1239793244.0000000007314000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7314000
|
Size: |
16384
|
|
564E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1238710172.000000000564E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
564E000
|
Size: |
8192
|
|
5760000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1238744632.0000000005760000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5760000
|
Size: |
40960
|
|
849E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1414035326.000000000849E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
849E000
|
Size: |
8192
|
|
6CF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1234952716.00000000006CF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6CF000
|
Size: |
131072
|
|
7EF90000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1240492080.000000007EF90000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7EF90000
|
Size: |
4096
|
|
24DE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1235896590.00000000024DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
24DE000
|
Size: |
8192
|
|
5892000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1406847468.0000000005892000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5892000
|
Size: |
36864
|
|
80000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1169715309.0000000000080000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
80000
|
Size: |
4096
|
|
6BEE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1410830850.0000000006BEE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6BEE000
|
Size: |
8192
|
|
7A80000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1413618234.0000000007A80000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7A80000
|
Size: |
65536
|
|
6BAE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1410807959.0000000006BAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6BAE000
|
Size: |
8192
|
|
6A49000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1409972622.0000000006A49000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6A49000
|
Size: |
8192
|
|
54EE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1406620930.00000000054EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
54EE000
|
Size: |
8192
|
|
5940000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1407489984.0000000005940000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5940000
|
Size: |
53248
|
|
3376000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1399255207.0000000003376000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3376000
|
Size: |
147456
|
|
7F4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1235051267.00000000007F4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7F4000
|
Size: |
4096
|
|
812000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1235324904.0000000000812000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
812000
|
Size: |
4096
|
|
6930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1238919215.0000000006930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6930000
|
Size: |
24576
|
|
699000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1234677955.0000000000699000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
699000
|
Size: |
8192
|
|
850000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1235519216.0000000000850000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
850000
|
Size: |
65536
|
|
58B1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1407122408.00000000058B1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
58B1000
|
Size: |
61440
|
|
7020000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1412202119.0000000007020000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7020000
|
Size: |
28672
|
|
86DD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1239960857.00000000086DD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
86DD000
|
Size: |
4096
|
|
2FD1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1399255207.0000000002FD1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2FD1000
|
Size: |
319488
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
7875000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1413128661.0000000007875000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7875000
|
Size: |
20480
|
|
34E1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1236474263.00000000034E1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
34E1000
|
Size: |
28672
|
|
24ED000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1235911398.00000000024ED000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24ED000
|
Size: |
28672
|
|
162F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1398800774.000000000162F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
162F000
|
Size: |
4096
|
|
14DB000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1398652445.00000000014DB000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
14DB000
|
Size: |
8192
|
|
182B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1398909918.000000000182B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
182B000
|
Size: |
16384
|
|
49A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1237429904.00000000049A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
49A0000
|
Size: |
4096
|
|
4946000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1237174014.0000000004946000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4946000
|
Size: |
16384
|
|
68D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1238836663.00000000068D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
68D0000
|
Size: |
65536
|
|
8670000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1239849185.0000000008670000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8670000
|
Size: |
36864
|
|
4F4E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1238628785.0000000004F4E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4F4E000
|
Size: |
8192
|
|
5B9B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1408497201.0000000005B9B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5B9B000
|
Size: |
8192
|
|
6952000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1238919215.0000000006952000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6952000
|
Size: |
1572864
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
67AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1408772807.00000000067AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
67AE000
|
Size: |
8192
|
|
4D10000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1238261827.0000000004D10000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
4D10000
|
Size: |
65536
|
|
6B6E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1410651475.0000000006B6E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6B6E000
|
Size: |
8192
|
|
4BAE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1238121030.0000000004BAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4BAE000
|
Size: |
8192
|
|
49B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1237632249.00000000049B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
49B0000
|
Size: |
65536
|
|
6AFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1410454826.0000000006AFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6AFE000
|
Size: |
8192
|
|
6A58000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1409972622.0000000006A58000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6A58000
|
Size: |
4096
|
|
24E1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1235911398.00000000024E1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24E1000
|
Size: |
45056
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
520000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1234576256.0000000000520000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
520000
|
Size: |
8192
|
|
589E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1406847468.000000000589E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
589E000
|
Size: |
8192
|
|
92B6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1414199752.00000000092B6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
92B6000
|
Size: |
12288
|
|
7B10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1413871303.0000000007B10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7B10000
|
Size: |
8192
|
|
66C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1234677955.000000000066C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
66C000
|
Size: |
143360
|
|
32D3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1399255207.00000000032D3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32D3000
|
Size: |
626688
|
|
65AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1408719352.00000000065AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
65AE000
|
Size: |
8192
|
|
4D40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1238457601.0000000004D40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D40000
|
Size: |
8192
|
|
9BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1235700261.00000000009BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9BE000
|
Size: |
8192
|
|
4BEE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1238167791.0000000004BEE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4BEE000
|
Size: |
8192
|
|
4B6E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1238096201.0000000004B6E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4B6E000
|
Size: |
8192
|
|
69E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1234677955.000000000069E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
69E000
|
Size: |
73728
|
|
6F70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1411655052.0000000006F70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6F70000
|
Size: |
65536
|
|
14D2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1398580269.00000000014D2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
14D2000
|
Size: |
4096
|
|
6F56000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1411019930.0000000006F56000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6F56000
|
Size: |
4096
|
|
860000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1235559574.0000000000860000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
860000
|
Size: |
65536
|
|
2FCE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1399229259.0000000002FCE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2FCE000
|
Size: |
8192
|
|
3FD1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1402286988.0000000003FD1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3FD1000
|
Size: |
45056
|
|
41B8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1402286988.00000000041B8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
41B8000
|
Size: |
397312
|
|
33D2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1399255207.00000000033D2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33D2000
|
Size: |
2125824
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Found many strings related to Crypto-Wallets (likely being stolen) |
Stealing of Sensitive Information |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
B60000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1235792669.0000000000B60000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
B60000
|
Size: |
4096
|
|
4920000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1237174014.0000000004920000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4920000
|
Size: |
114688
|
|
6F62000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1411019930.0000000006F62000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6F62000
|
Size: |
8192
|
|
816000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1235370483.0000000000816000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
816000
|
Size: |
8192
|
|
B78000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1235806922.0000000000B78000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
B78000
|
Size: |
4096
|
|
4197000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1402286988.0000000004197000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4197000
|
Size: |
4096
|
|
339E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1399255207.000000000339E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
339E000
|
Size: |
4096
|
|
7A40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1413387675.0000000007A40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7A40000
|
Size: |
65536
|
|
14AD000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1398398055.00000000014AD000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
14AD000
|
Size: |
4096
|
|
586F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1406826566.000000000586F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
586F000
|
Size: |
4096
|
|
4182000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1402286988.0000000004182000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4182000
|
Size: |
4096
|
|
800000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1235258563.0000000000800000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
800000
|
Size: |
40960
|
|
68E0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1409828751.00000000068E0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
68E0000
|
Size: |
65536
|
|
5A80000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1408365878.0000000005A80000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5A80000
|
Size: |
65536
|
|
5B9E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1408497201.0000000005B9E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5B9E000
|
Size: |
8192
|
|
10F7000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1397672183.00000000010F7000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
10F7000
|
Size: |
36864
|
|
7C40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1413956068.0000000007C40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7C40000
|
Size: |
4096
|
|
418A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1402286988.000000000418A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
418A000
|
Size: |
20480
|
|
49E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1237761182.00000000049E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
49E0000
|
Size: |
4096
|
|
4BF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1238189009.0000000004BF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4BF0000
|
Size: |
4096
|
|
1490000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1398299595.0000000001490000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1490000
|
Size: |
8192
|
|
6F2E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1239452652.0000000006F2E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6F2E000
|
Size: |
8192
|
|
14B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1398423150.00000000014B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
14B0000
|
Size: |
28672
|
|
B03E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1240437071.000000000B03E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B03E000
|
Size: |
8192
|
|
4A10000
|
trusted library section
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1237892456.0000000004A10000.00000002.08000000.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page readonly
|
Base address: |
4A10000
|
Size: |
65536
|
|
5750000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1238744632.0000000005750000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5750000
|
Size: |
4096
|
|
C10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1235836327.0000000000C10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
C10000
|
Size: |
65536
|
|
4A7B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1238040704.0000000004A7B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4A7B000
|
Size: |
20480
|
|
71AB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1239594687.00000000071AB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
71AB000
|
Size: |
20480
|
|
7857000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1413128661.0000000007857000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7857000
|
Size: |
106496
|
|
7D8E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1413984784.0000000007D8E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7D8E000
|
Size: |
8192
|
|
5AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1234613562.00000000005AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5AE000
|
Size: |
8192
|
|
4136000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1402286988.0000000004136000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4136000
|
Size: |
20480
|
|
6D53000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1239331429.0000000006D53000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6D53000
|
Size: |
8192
|
|
1AA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1234504680.00000000001AA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1AA000
|
Size: |
24576
|
|
326D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1399255207.000000000326D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
326D000
|
Size: |
413696
|
|
2EC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1399207542.0000000002EC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2EC0000
|
Size: |
4096
|
|
6812000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1408982844.0000000006812000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6812000
|
Size: |
4096
|
|
4169000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1402286988.0000000004169000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4169000
|
Size: |
4096
|
|
3FEF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1402286988.0000000003FEF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3FEF000
|
Size: |
4096
|
|
419E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1402286988.000000000419E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
419E000
|
Size: |
4096
|
|
6A80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1410277918.0000000006A80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6A80000
|
Size: |
4096
|
|
14D5000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1398606494.00000000014D5000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
14D5000
|
Size: |
4096
|
|
1800000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1398850848.0000000001800000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1800000
|
Size: |
65536
|
|
11D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1397711680.00000000011D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11D0000
|
Size: |
16384
|
|
3050000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1399255207.0000000003050000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3050000
|
Size: |
8192
|
|
587B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1406847468.000000000587B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
587B000
|
Size: |
20480
|
|
145E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1398251411.000000000145E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
145E000
|
Size: |
8192
|
|
71A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1239594687.00000000071A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
71A0000
|
Size: |
36864
|
|
4A35000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1237974088.0000000004A35000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4A35000
|
Size: |
40960
|
|
7A60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1413528084.0000000007A60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7A60000
|
Size: |
65536
|
|
3184000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1399255207.0000000003184000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3184000
|
Size: |
118784
|
|
2E7C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1398991623.0000000002E7C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2E7C000
|
Size: |
16384
|
|
494D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1237174014.000000000494D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
494D000
|
Size: |
69632
|
|
7AD0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1413744628.0000000007AD0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7AD0000
|
Size: |
4096
|
|
4A30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1237974088.0000000004A30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4A30000
|
Size: |
12288
|
|
6F51000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1411019930.0000000006F51000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6F51000
|
Size: |
8192
|
|
11D5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1397711680.00000000011D5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11D5000
|
Size: |
16384
|
|
49E3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1237761182.00000000049E3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
49E3000
|
Size: |
12288
|
|
5A7E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1408283543.0000000005A7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5A7E000
|
Size: |
8192
|
|
840000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1235479901.0000000000840000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
840000
|
Size: |
4096
|
|
4A20000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1237928760.0000000004A20000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
4A20000
|
Size: |
65536
|
|
6A90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1410380668.0000000006A90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6A90000
|
Size: |
65536
|
|
59D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1408013942.00000000059D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
59D0000
|
Size: |
65536
|
|
4191000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1402286988.0000000004191000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4191000
|
Size: |
8192
|
|
6FA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1411921769.0000000006FA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6FA0000
|
Size: |
65536
|
|
400000
|
remote allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1397485445.0000000000400000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
400000
|
Size: |
4096
|
|
4990000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1237326881.0000000004990000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
4990000
|
Size: |
65536
|
|
7F050000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1414430155.000000007F050000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7F050000
|
Size: |
4096
|
|
5FE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1234677955.00000000005FE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5FE000
|
Size: |
102400
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
33A4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1399255207.00000000033A4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33A4000
|
Size: |
151552
|
|
127E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1397819004.000000000127E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
127E000
|
Size: |
40960
|
|
7DCE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1414008944.0000000007DCE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7DCE000
|
Size: |
8192
|
|
6F58000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1411019930.0000000006F58000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6F58000
|
Size: |
4096
|
|
417B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1402286988.000000000417B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
417B000
|
Size: |
4096
|
|
4228000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1402286988.0000000004228000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4228000
|
Size: |
1122304
|
|
4047000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1402286988.0000000004047000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4047000
|
Size: |
962560
|
|
8B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1235682255.00000000008B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8B0000
|
Size: |
12288
|
|
45DC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1237147747.00000000045DC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
45DC000
|
Size: |
16384
|
|
6B60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1410651475.0000000006B60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6B60000
|
Size: |
53248
|
|
720E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1239740087.000000000720E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
720E000
|
Size: |
8192
|
|
92A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1414110080.00000000092A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
92A0000
|
Size: |
4096
|
|
3FDE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1402286988.0000000003FDE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3FDE000
|
Size: |
4096
|
|
B40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1235766208.0000000000B40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
B40000
|
Size: |
65536
|
|
7140000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1239483246.0000000007140000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
7140000
|
Size: |
376832
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
6F4E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1411019930.0000000006F4E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6F4E000
|
Size: |
4096
|
|
686B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1409355985.000000000686B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
686B000
|
Size: |
12288
|
|
6EDF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1410959226.0000000006EDF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6EDF000
|
Size: |
4096
|
|
8A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1235638233.00000000008A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8A0000
|
Size: |
16384
|
|
7AE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1413769706.0000000007AE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7AE0000
|
Size: |
4096
|
|
14F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1398676823.00000000014F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
14F0000
|
Size: |
4096
|
|
6D3E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1239331429.0000000006D3E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6D3E000
|
Size: |
24576
|
|
572F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1406754880.000000000572F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
572F000
|
Size: |
4096
|
|
14D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1398555199.00000000014D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
14D0000
|
Size: |
4096
|
|
1300000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1397819004.0000000001300000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1300000
|
Size: |
389120
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
AV process strings found (often used to terminate AV products) |
Lowering of HIPS / PFW / Operating System Security Settings |
Security Software Discovery
|
|
14C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1398472382.00000000014C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
14C0000
|
Size: |
4096
|
|
416E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1402286988.000000000416E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
416E000
|
Size: |
20480
|
|
5920000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1407370605.0000000005920000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5920000
|
Size: |
65536
|
|
3048000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1399255207.0000000003048000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3048000
|
Size: |
20480
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4143000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1402286988.0000000004143000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4143000
|
Size: |
4096
|
|
6B3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1410521221.0000000006B3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6B3E000
|
Size: |
8192
|
|
6888000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1409510917.0000000006888000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6888000
|
Size: |
81920
|
|
8698000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1239873041.0000000008698000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8698000
|
Size: |
163840
|
|
14A3000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1398347317.00000000014A3000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
14A3000
|
Size: |
4096
|
|
82000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1169734737.0000000000082000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
82000
|
Size: |
606208
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
31A2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1399255207.00000000031A2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31A2000
|
Size: |
409600
|
|
1827000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1398909918.0000000001827000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1827000
|
Size: |
12288
|
|