59E0000
|
direct allocation
|
page read and write
|
 |
|
|
Name: |
00000001.00000002.1356058606.00000000059E0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
59E0000
|
Size: |
446464
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Found malware configuration |
AV Detection |
|
Yara detected Amadeys Clipper DLL |
Stealing of Sensitive Information |
|
Contains functionality to start a terminal service |
Remote Access Functionality |
|
Sample uses string decryption to hide its real strings |
AV Detection |
|
|
36D2000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.2617475641.00000000036D2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
36D2000
|
Size: |
8192
|
|
E1A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1369277677.0000000000E1A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E1A000
|
Size: |
4096
|
|
E22000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1350798840.0000000000E22000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E22000
|
Size: |
122880
|
|
29FD000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1329524678.00000000029FD000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
29FD000
|
Size: |
4096
|
|
9B5000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1253429509.00000000009B5000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
9B5000
|
Size: |
4096
|
|
98B000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1370008418.000000000098B000.00000004.00000001.01000000.00000008.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
98B000
|
Size: |
8192
|
|
57F9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3723408584.00000000057F9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
57F9000
|
Size: |
4096
|
|
56D0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3723408584.00000000056D0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
56D0000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
36EF000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3722161485.00000000036EF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
36EF000
|
Size: |
40960
|
|
3600000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3722116943.0000000003600000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3600000
|
Size: |
8192
|
|
29B1000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1264873247.00000000029B1000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
29B1000
|
Size: |
12288
|
|
3785000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3722640351.0000000003785000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3785000
|
Size: |
12288
|
|
E15000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1350906559.0000000000E15000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E15000
|
Size: |
12288
|
|
B81000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000A.00000002.3721696998.0000000000B81000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B81000
|
Size: |
86016
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Contains functionality to start a terminal service |
Remote Access Functionality |
|
|
BC2000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1253492449.0000000000BC2000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BC2000
|
Size: |
155648
|
|
2A01000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1264873247.0000000002A01000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2A01000
|
Size: |
4096
|
|
323F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1355241573.000000000323F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
323F000
|
Size: |
4096
|
|
58EE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1355965536.00000000058EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
58EE000
|
Size: |
8192
|
|
2FF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1277682924.0000000002FF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FF4000
|
Size: |
4096
|
|
95B000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1264224412.000000000095B000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
95B000
|
Size: |
4096
|
|
E26000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1351054033.0000000000E26000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E26000
|
Size: |
8192
|
|
402B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1268251944.000000000402B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
402B000
|
Size: |
24576
|
|
3037000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1355168830.0000000003037000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3037000
|
Size: |
8192
|
|
4FC0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1355722758.0000000004FC0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4FC0000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
5254000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3722752413.0000000005254000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5254000
|
Size: |
880640
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
10F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1264808856.00000000010F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10F0000
|
Size: |
4096
|
|
4C53000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1355454272.0000000004C53000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4C53000
|
Size: |
512000
|
|
1126000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1264826360.0000000001126000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1126000
|
Size: |
36864
|
|
338E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1355389010.000000000338E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
338E000
|
Size: |
4096
|
|
29FA000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1264873247.00000000029FA000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
29FA000
|
Size: |
4096
|
|
C30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1264409035.0000000000C30000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C30000
|
Size: |
4096
|
|
E26000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1351094916.0000000000E26000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E26000
|
Size: |
12288
|
|
95B000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1369957670.000000000095B000.00000004.00000001.01000000.00000008.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
95B000
|
Size: |
4096
|
|
2D4E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1370983161.0000000002D4E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2D4E000
|
Size: |
8192
|
|
2FF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1328549069.0000000002FF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FF4000
|
Size: |
4096
|
|
333E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1355258250.000000000333E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
333E000
|
Size: |
8192
|
|
46B3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1256167335.00000000046B3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
46B3000
|
Size: |
1167360
|
|
BFB000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1253492449.0000000000BFB000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BFB000
|
Size: |
40960
|
|
3780000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3722640351.0000000003780000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3780000
|
Size: |
16384
|
|
520C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3722752413.000000000520C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
520C000
|
Size: |
290816
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
5EFD000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3723690381.0000000005EFD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5EFD000
|
Size: |
12288
|
|
5330000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1371502284.0000000005330000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5330000
|
Size: |
4096
|
|
2F9F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1355083230.0000000002F9F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2F9F000
|
Size: |
4096
|
|
334D000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3722008674.000000000334D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
334D000
|
Size: |
12288
|
|
19A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1369860866.000000000019A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
19A000
|
Size: |
24576
|
|
E3F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1351018632.0000000000E3F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E3F000
|
Size: |
4096
|
|
2A7A000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1329524678.0000000002A7A000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2A7A000
|
Size: |
4096
|
|
9B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1264052612.000000000009B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9B000
|
Size: |
20480
|
|
55CA000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1285840775.00000000055CA000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
55CA000
|
Size: |
4096
|
|
5AFB000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3723666016.0000000005AFB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5AFB000
|
Size: |
20480
|
|
95D000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1369978024.000000000095D000.00000004.00000001.01000000.00000008.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
95D000
|
Size: |
12288
|
|
2FF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1277388544.0000000002FF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FF4000
|
Size: |
4096
|
|
5119000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1284449910.0000000005119000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5119000
|
Size: |
4096
|
|
769000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000002.1264108434.0000000000769000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
769000
|
Size: |
16384
|
|
2A73000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1329524678.0000000002A73000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2A73000
|
Size: |
4096
|
|
D35000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1264455085.0000000000D35000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D35000
|
Size: |
12288
|
|
3700000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.2617475641.0000000003700000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3700000
|
Size: |
12288
|
|
E28000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1369277677.0000000000E28000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E28000
|
Size: |
69632
|
|
5330000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3723067075.0000000005330000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5330000
|
Size: |
4096
|
|
3750000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1268065272.0000000003750000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3750000
|
Size: |
237568
|
|
5ABC000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3723639244.0000000005ABC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5ABC000
|
Size: |
16384
|
|
3FE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1268251944.0000000003FE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3FE4000
|
Size: |
155648
|
|
4480000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1281779981.0000000004480000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4480000
|
Size: |
12288
|
|
E25000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1370546481.0000000000E25000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E25000
|
Size: |
4096
|
|
61BE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3723791505.00000000061BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
61BE000
|
Size: |
8192
|
|
4420000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1281750904.0000000004420000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4420000
|
Size: |
4096
|
|
F3D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1264557251.0000000000F3D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F3D000
|
Size: |
32768
|
|
2A38000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1329524678.0000000002A38000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2A38000
|
Size: |
4096
|
|
2A22000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1329524678.0000000002A22000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2A22000
|
Size: |
4096
|
|
2FF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1277451002.0000000002FF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FF4000
|
Size: |
4096
|
|
29C8000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1264873247.00000000029C8000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
29C8000
|
Size: |
4096
|
|
33B0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3722067810.00000000033B0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33B0000
|
Size: |
4096
|
|
401C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1268251944.000000000401C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
401C000
|
Size: |
40960
|
|
E19000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1350906559.0000000000E19000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E19000
|
Size: |
4096
|
|
29EC000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1264873247.00000000029EC000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
29EC000
|
Size: |
4096
|
|
36E6000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.2617475641.00000000036E6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
36E6000
|
Size: |
32768
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
E0F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1350906559.0000000000E0F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E0F000
|
Size: |
20480
|
|
29AA000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1264873247.00000000029AA000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
29AA000
|
Size: |
4096
|
|
F4E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1355002093.0000000000F4E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
F4E000
|
Size: |
8192
|
|
2FF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1277653548.0000000002FF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FF4000
|
Size: |
4096
|
|
47E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1259152436.00000000047E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
47E0000
|
Size: |
4096
|
|
2A6C000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1329524678.0000000002A6C000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2A6C000
|
Size: |
4096
|
|
D7E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1264525605.0000000000D7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
D7E000
|
Size: |
8192
|
|
E40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1350754348.0000000000E40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E40000
|
Size: |
36864
|
|
F00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1354984551.0000000000F00000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F00000
|
Size: |
4096
|
|
FEF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1370684115.0000000000FEF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FEF000
|
Size: |
4096
|
|
2FF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1277542801.0000000002FF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FF4000
|
Size: |
4096
|
|
2FF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1277567613.0000000002FF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FF4000
|
Size: |
4096
|
|
95B000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.1253276821.000000000095B000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
95B000
|
Size: |
98304
|
|
F06000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1264557251.0000000000F06000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F06000
|
Size: |
98304
|
|
2A56000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1329524678.0000000002A56000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2A56000
|
Size: |
4096
|
|
2FF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1355136193.0000000002FF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FF0000
|
Size: |
16384
|
|
2FF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1277592693.0000000002FF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FF4000
|
Size: |
4096
|
|
D10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1264431004.0000000000D10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D10000
|
Size: |
4096
|
|
2C30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1267563363.0000000002C30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C30000
|
Size: |
4096
|
|
11A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1370776391.00000000011A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11A0000
|
Size: |
12288
|
|
592F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1355996602.000000000592F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
592F000
|
Size: |
4096
|
|
E2D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1370546481.0000000000E2D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E2D000
|
Size: |
16384
|
|
4E9E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1355597563.0000000004E9E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4E9E000
|
Size: |
290816
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
596E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1356010415.000000000596E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
596E000
|
Size: |
8192
|
|
4484000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1256706641.0000000004484000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4484000
|
Size: |
4096
|
|
47BF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1281935798.00000000047BF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
47BF000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
962000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1264255882.0000000000962000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
962000
|
Size: |
8192
|
|
2A4F000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1329524678.0000000002A4F000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2A4F000
|
Size: |
4096
|
|
2FF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1277333963.0000000002FF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FF4000
|
Size: |
4096
|
|
2FF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1328588996.0000000002FF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FF4000
|
Size: |
4096
|
|
2A88000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1329524678.0000000002A88000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2A88000
|
Size: |
4096
|
|
2FDE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1355102282.0000000002FDE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2FDE000
|
Size: |
8192
|
|
298D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1264873247.000000000298D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
298D000
|
Size: |
4096
|
|
29F3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1264873247.00000000029F3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
29F3000
|
Size: |
4096
|
|
29D6000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1264873247.00000000029D6000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
29D6000
|
Size: |
4096
|
|
BA3000
|
unkown
|
page write copy
|
|
|
|
Name: |
0000000A.00000002.3721873594.0000000000BA3000.00000008.00000001.01000000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
BA3000
|
Size: |
4096
|
|
B9D000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000A.00000002.3721816119.0000000000B9D000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B9D000
|
Size: |
24576
|
|
2A7E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1370882705.0000000002A7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2A7E000
|
Size: |
8192
|
|
DF8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1370316636.0000000000DF8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DF8000
|
Size: |
114688
|
|
C80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1370248043.0000000000C80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C80000
|
Size: |
4096
|
|
2FF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1300994173.0000000002FF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FF4000
|
Size: |
4096
|
|
613D000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3723770480.000000000613D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
613D000
|
Size: |
12288
|
|
C07000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1253492449.0000000000C07000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
C07000
|
Size: |
8192
|
|
2FF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1277614469.0000000002FF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FF4000
|
Size: |
4096
|
|
330C000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3721961164.000000000330C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
330C000
|
Size: |
16384
|
|
2D80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1371022084.0000000002D80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D80000
|
Size: |
4096
|
|
E15000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1370316636.0000000000E15000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E15000
|
Size: |
12288
|
|
29B8000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1264873247.00000000029B8000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
29B8000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
2D83000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1371022084.0000000002D83000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D83000
|
Size: |
12288
|
|
2FF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1328570569.0000000002FF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FF4000
|
Size: |
4096
|
|
2FF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1354893098.0000000002FF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FF4000
|
Size: |
4096
|
|
E1E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1369277677.0000000000E1E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E1E000
|
Size: |
32768
|
|
2FF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1277523103.0000000002FF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FF4000
|
Size: |
4096
|
|
1110000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1370725322.0000000001110000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1110000
|
Size: |
4096
|
|
9B0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1264272814.00000000009B0000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9B0000
|
Size: |
8192
|
|
9B7000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1253492449.00000000009B7000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
9B7000
|
Size: |
2093056
|
|
4029000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1268251944.0000000004029000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4029000
|
Size: |
4096
|
|
10EF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1370701537.00000000010EF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
10EF000
|
Size: |
4096
|
|
2C20000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1267495506.0000000002C20000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
2C20000
|
Size: |
4096
|
|
CB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1370264467.0000000000CB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CB0000
|
Size: |
20480
|
|
518E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1284449910.000000000518E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
518E000
|
Size: |
24576
|
|
2C10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1267461581.0000000002C10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C10000
|
Size: |
4096
|
|
2FF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1328634881.0000000002FF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FF4000
|
Size: |
4096
|
|
36E6000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3722161485.00000000036E6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
36E6000
|
Size: |
32768
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
FDE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1264768105.0000000000FDE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FDE000
|
Size: |
8192
|
|
E48000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1351018632.0000000000E48000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E48000
|
Size: |
4096
|
|
B31000
|
unkown
|
page execute read
|
|
|
|
Name: |
0000000A.00000002.3721585599.0000000000B31000.00000020.00000001.01000000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
B31000
|
Size: |
327680
|
|
9B0000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.1253276821.00000000009B0000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
9B0000
|
Size: |
20480
|
|
515E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1355722758.000000000515E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
515E000
|
Size: |
24576
|
|
2D0F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1370925006.0000000002D0F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2D0F000
|
Size: |
4096
|
|
9B4000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1370104574.00000000009B4000.00000004.00000001.01000000.00000008.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9B4000
|
Size: |
4096
|
|
E21000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1369730193.0000000000E21000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E21000
|
Size: |
4096
|
|
EA8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1264557251.0000000000EA8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EA8000
|
Size: |
299008
|
|
2FF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1278066825.0000000002FF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FF4000
|
Size: |
4096
|
|
2FF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1277781933.0000000002FF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FF4000
|
Size: |
4096
|
|
3000000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1355151440.0000000003000000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3000000
|
Size: |
4096
|
|
3030000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1355168830.0000000003030000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3030000
|
Size: |
20480
|
|
D30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1264455085.0000000000D30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D30000
|
Size: |
16384
|
|
4034000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1268251944.0000000004034000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4034000
|
Size: |
3846144
|
|
29E4000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1264873247.00000000029E4000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
29E4000
|
Size: |
4096
|
|
5370000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1355890326.0000000005370000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5370000
|
Size: |
122880
|
|
2FF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1277496849.0000000002FF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FF4000
|
Size: |
4096
|
|
586E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3723408584.000000000586E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
586E000
|
Size: |
24576
|
|
2FF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1277833651.0000000002FF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FF4000
|
Size: |
4096
|
|
2A0D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1329524678.0000000002A0D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2A0D000
|
Size: |
4096
|
|
5FFE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3723715109.0000000005FFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5FFE000
|
Size: |
8192
|
|
4E40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1259268154.0000000004E40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4E40000
|
Size: |
700416
|
|
2A81000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1329524678.0000000002A81000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2A81000
|
Size: |
4096
|
|
E48000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1369248611.0000000000E48000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E48000
|
Size: |
4096
|
|
3680000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3722161485.0000000003680000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3680000
|
Size: |
24576
|
|
2FF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1328656342.0000000002FF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FF4000
|
Size: |
4096
|
|
625E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3723834626.000000000625E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
625E000
|
Size: |
8192
|
|
EA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1264557251.0000000000EA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EA0000
|
Size: |
24576
|
|
C30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1370205231.0000000000C30000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C30000
|
Size: |
4096
|
|
10DF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1264793908.00000000010DF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
10DF000
|
Size: |
4096
|
|
549D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3723170231.000000000549D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
549D000
|
Size: |
512000
|
|
2A31000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1329524678.0000000002A31000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2A31000
|
Size: |
12288
|
|
2FF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1277279421.0000000002FF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FF4000
|
Size: |
4096
|
|
2A64000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1329524678.0000000002A64000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2A64000
|
Size: |
4096
|
|
2A08000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1264873247.0000000002A08000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2A08000
|
Size: |
4096
|
|
3380000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1355389010.0000000003380000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3380000
|
Size: |
53248
|
|
337F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1355360393.000000000337F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
337F000
|
Size: |
4096
|
|
974000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.1253276821.0000000000974000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
974000
|
Size: |
73728
|
|
29A2000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1264873247.00000000029A2000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
29A2000
|
Size: |
4096
|
|
4590000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1281832616.0000000004590000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4590000
|
Size: |
94208
|
|
4B30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1355454272.0000000004B30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B30000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2FF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1354914795.0000000002FF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FF4000
|
Size: |
4096
|
|
53AE000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1285765957.00000000053AE000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
53AE000
|
Size: |
4096
|
|
4EE6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1355597563.0000000004EE6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4EE6000
|
Size: |
880640
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
5371000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1277086083.0000000005371000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5371000
|
Size: |
176128
|
|
5470000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1355921022.0000000005470000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5470000
|
Size: |
4096
|
|
50E9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1355722758.00000000050E9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
50E9000
|
Size: |
4096
|
|
57FD000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3723408584.00000000057FD000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
57FD000
|
Size: |
458752
|
|
36D5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.2617475641.00000000036D5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
36D5000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
537A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3723170231.000000000537A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
537A000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
E9C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1354968642.0000000000E9C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
E9C000
|
Size: |
16384
|
|
76E000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000002.1264108434.000000000076E000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
76E000
|
Size: |
8192
|
|
29DD000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1264873247.00000000029DD000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
29DD000
|
Size: |
4096
|
|
C0A000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1253492449.0000000000C0A000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
C0A000
|
Size: |
24576
|
|
2FF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1277928939.0000000002FF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FF4000
|
Size: |
4096
|
|
19D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1264089712.000000000019D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
19D000
|
Size: |
12288
|
|
2FE0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1355121985.0000000002FE0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FE0000
|
Size: |
4096
|
|
1120000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1264826360.0000000001120000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1120000
|
Size: |
16384
|
|
9B4000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1264346746.00000000009B4000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9B4000
|
Size: |
4096
|
|
29EF000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1329524678.00000000029EF000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
29EF000
|
Size: |
4096
|
|
4AB1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1283307573.0000000004AB1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4AB1000
|
Size: |
876544
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
5655000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1286016241.0000000005655000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5655000
|
Size: |
290816
|
|
441C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1281712457.000000000441C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
441C000
|
Size: |
16384
|
|
4A2F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1283307573.0000000004A2F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4A2F000
|
Size: |
524288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
E2A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1351054033.0000000000E2A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E2A000
|
Size: |
4096
|
|
2FF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1301221397.0000000002FF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FF4000
|
Size: |
4096
|
|
569D000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1286016241.000000000569D000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
569D000
|
Size: |
880640
|
|
2A48000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1329524678.0000000002A48000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2A48000
|
Size: |
4096
|
|
98B000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1264272814.000000000098B000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
98B000
|
Size: |
8192
|
|
2FF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1277804873.0000000002FF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FF4000
|
Size: |
4096
|
|
BF6000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1253492449.0000000000BF6000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BF6000
|
Size: |
8192
|
|
2984000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1264873247.0000000002984000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2984000
|
Size: |
4096
|
|
59B0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1356044117.00000000059B0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
59B0000
|
Size: |
4096
|
|
3700000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3722161485.0000000003700000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3700000
|
Size: |
16384
|
|
2A5D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1329524678.0000000002A5D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2A5D000
|
Size: |
4096
|
|
9A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1369824926.000000000009A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9A000
|
Size: |
24576
|
|
95D000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1264239323.000000000095D000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
95D000
|
Size: |
12288
|
|
603D000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3723746306.000000000603D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
603D000
|
Size: |
12288
|
|
11A9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1370776391.00000000011A9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11A9000
|
Size: |
16384
|
|
2FF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1301247709.0000000002FF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FF4000
|
Size: |
4096
|
|
986000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1264272814.0000000000986000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
986000
|
Size: |
16384
|
|
398F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1371477942.000000000398F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
398F000
|
Size: |
4096
|
|
48E2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1281935798.00000000048E2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
48E2000
|
Size: |
512000
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
4017000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1268251944.0000000004017000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4017000
|
Size: |
8192
|
|
303C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1355168830.000000000303C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
303C000
|
Size: |
176128
|
|
5471000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1277161057.0000000005471000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5471000
|
Size: |
237568
|
|
5371000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1276978606.0000000005371000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5371000
|
Size: |
176128
|
|
C7E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1370227672.0000000000C7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C7E000
|
Size: |
8192
|
|
50ED000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1355722758.00000000050ED000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
50ED000
|
Size: |
458752
|
|
1120000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1370757182.0000000001120000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1120000
|
Size: |
4096
|
|
3703000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.2617355953.0000000003703000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3703000
|
Size: |
8192
|
|
C11000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1253492449.0000000000C11000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
C11000
|
Size: |
90112
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
5550000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1285840775.0000000005550000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5550000
|
Size: |
176128
|
|
11A5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1370776391.00000000011A5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11A5000
|
Size: |
8192
|
|
986000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1370008418.0000000000986000.00000004.00000001.01000000.00000008.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
986000
|
Size: |
4096
|
|
2FF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1301054820.0000000002FF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FF4000
|
Size: |
4096
|
|
635E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3723863870.000000000635E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
635E000
|
Size: |
8192
|
|
E19000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1370316636.0000000000E19000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E19000
|
Size: |
4096
|
|
2C33000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1267563363.0000000002C33000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C33000
|
Size: |
8192
|
|
DF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1370316636.0000000000DF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DF0000
|
Size: |
24576
|
|
3688000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3722161485.0000000003688000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3688000
|
Size: |
270336
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
401000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000000.1252450024.0000000000401000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
401000
|
Size: |
5611520
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
E32000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1370546481.0000000000E32000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E32000
|
Size: |
4096
|
|
E7F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1264542415.0000000000E7F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
E7F000
|
Size: |
4096
|
|
29CF000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1264873247.00000000029CF000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
29CF000
|
Size: |
4096
|
|
61FF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3723815297.00000000061FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
61FF000
|
Size: |
4096
|
|
5360000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3723125452.0000000005360000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5360000
|
Size: |
53248
|
|
DCE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1370296466.0000000000DCE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
DCE000
|
Size: |
8192
|
|
511D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1284449910.000000000511D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
511D000
|
Size: |
458752
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
2FF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1277967096.0000000002FF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FF4000
|
Size: |
4096
|
|
2FF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1277474338.0000000002FF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FF4000
|
Size: |
4096
|
|
4032000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1268251944.0000000004032000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4032000
|
Size: |
4096
|
|
2FF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1328618837.0000000002FF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FF4000
|
Size: |
4096
|
|
400000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1252433476.0000000000400000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
400000
|
Size: |
4096
|
|
E22000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1351094916.0000000000E22000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E22000
|
Size: |
12288
|
|
4484000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1259239909.0000000004484000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4484000
|
Size: |
4096
|
|
2FF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1301142532.0000000002FF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FF4000
|
Size: |
4096
|
|
B30000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000A.00000002.3721482584.0000000000B30000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B30000
|
Size: |
4096
|
|
36EF000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.2617475641.00000000036EF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
36EF000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
5471000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1276867553.0000000005471000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5471000
|
Size: |
131072
|
|
2FF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1277994493.0000000002FF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FF4000
|
Size: |
4096
|
|
E2A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1351094916.0000000000E2A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E2A000
|
Size: |
4096
|
|
2FF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1276900995.0000000002FF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FF4000
|
Size: |
4096
|
|
E21000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1350906559.0000000000E21000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E21000
|
Size: |
4096
|
|
E5C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1354950115.0000000000E5C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
E5C000
|
Size: |
16384
|
|
1120000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000009.00000003.1329501284.0000000001120000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
1120000
|
Size: |
4096
|
|
3DC4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1268251944.0000000003DC4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3DC4000
|
Size: |
2179072
|
|
36CB000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3722161485.00000000036CB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
36CB000
|
Size: |
102400
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
299B000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1264873247.000000000299B000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
299B000
|
Size: |
4096
|
|
E35000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1370546481.0000000000E35000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E35000
|
Size: |
16384
|
|
4FF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1284449910.0000000004FF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4FF0000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
4EED000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1259268154.0000000004EED000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4EED000
|
Size: |
1171456
|
|
988000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1370008418.0000000000988000.00000004.00000001.01000000.00000008.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
988000
|
Size: |
4096
|
|
59AF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1356027291.00000000059AF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
59AF000
|
Size: |
4096
|
|
458E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1281810013.000000000458E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
458E000
|
Size: |
8192
|
|
2A2A000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1329524678.0000000002A2A000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2A2A000
|
Size: |
4096
|
|
3851000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1268251944.0000000003851000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3851000
|
Size: |
5709824
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
E29000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1370546481.0000000000E29000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E29000
|
Size: |
4096
|
|
B96000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3721760982.0000000000B96000.00000004.00000001.01000000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
B96000
|
Size: |
16384
|
|