36F0000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
0000000D.00000002.2251107589.00000000036F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
36F0000
|
Size: |
2662400
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected RedLine Stealer |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected Credential Stealer |
Stealing of Sensitive Information |
|
|
4A60000
|
trusted library section
|
page read and write
|
 |
|
|
Name: |
0000000D.00000002.2262439782.0000000004A60000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
4A60000
|
Size: |
176128
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected DarkTortilla Crypter |
Data Obfuscation |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
42F3000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000014.00000002.2501089519.00000000042F3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
42F3000
|
Size: |
2531328
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected RedLine Stealer |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected Credential Stealer |
Stealing of Sensitive Information |
|
|
412D000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000014.00000002.2501089519.000000000412D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
412D000
|
Size: |
1716224
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected RedLine Stealer |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected Credential Stealer |
Stealing of Sensitive Information |
|
|
402000
|
remote allocation
|
page execute and read and write
|
 |
|
|
Name: |
00000012.00000002.2471183329.0000000000402000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
402000
|
Size: |
839680
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected RedLine Stealer |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected Credential Stealer |
Stealing of Sensitive Information |
|
|
462A000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000014.00000002.2501089519.000000000462A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
462A000
|
Size: |
1687552
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected RedLine Stealer |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected Credential Stealer |
Stealing of Sensitive Information |
|
|
25B1000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
0000000D.00000002.2237083332.00000000025B1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
25B1000
|
Size: |
856064
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected DarkTortilla Crypter |
Data Obfuscation |
|
|
3023000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000014.00000002.2476801289.0000000003023000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3023000
|
Size: |
507904
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected DarkTortilla Crypter |
Data Obfuscation |
|
|
3619000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
0000000D.00000002.2251107589.0000000003619000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3619000
|
Size: |
528384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected DarkTortilla Crypter |
Data Obfuscation |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
2AF1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002AF1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AF1000
|
Size: |
4096
|
|
11FA000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000000.2134064020.00000000011FA000.00000008.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
11FA000
|
Size: |
8192
|
|
18141670000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2402467115.0000018141670000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
18141670000
|
Size: |
8192
|
|
5500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2513754895.0000000005500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5500000
|
Size: |
57344
|
|
5721000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2441456353.0000000005721000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5721000
|
Size: |
135168
|
|
69B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1635376735.000000000069B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
69B000
|
Size: |
61440
|
|
6C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1379156492.00000000006C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6C0000
|
Size: |
4096
|
|
AC6000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.2235854388.0000000000AC6000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
AC6000
|
Size: |
8192
|
|
23AD8C3C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8C3C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8C3C000
|
Size: |
20480
|
|
3102000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003102000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3102000
|
Size: |
20480
|
|
D9000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2225388989.00000000000D9000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
D9000
|
Size: |
28672
|
|
352D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000352D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
352D000
|
Size: |
4096
|
|
23AAA250000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1906847867.0000023AAA250000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AAA250000
|
Size: |
4096
|
|
28A1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000028A1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
28A1000
|
Size: |
4096
|
|
13A6000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1904361707.00000000013A6000.00000004.00000001.01000000.00000006.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
13A6000
|
Size: |
4096
|
|
16D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476156998.00000000016D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16D0000
|
Size: |
24576
|
|
3512000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003512000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3512000
|
Size: |
4096
|
|
3653000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003653000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3653000
|
Size: |
12288
|
|
310D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000310D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
310D000
|
Size: |
20480
|
|
33BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000016.00000002.2445267027.00000000033BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
33BE000
|
Size: |
8192
|
|
516000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.0000000000516000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
516000
|
Size: |
20480
|
|
23AD8A99000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1661317128.0000023AD8A99000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8A99000
|
Size: |
24576
|
|
3436000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003436000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3436000
|
Size: |
4096
|
|
68C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1378651925.000000000068C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
68C000
|
Size: |
20480
|
|
3823000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003823000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3823000
|
Size: |
4096
|
|
1127000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000001127000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
1127000
|
Size: |
12288
|
|
31B9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000031B9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31B9000
|
Size: |
20480
|
|
37DC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000037DC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
37DC000
|
Size: |
4096
|
|
280C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.000000000280C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
280C000
|
Size: |
4096
|
|
2689000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002689000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2689000
|
Size: |
4096
|
|
23AD8B04000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1661317128.0000023AD8B04000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8B04000
|
Size: |
24576
|
|
30B2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000030B2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30B2000
|
Size: |
40960
|
|
7AA7000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2270418472.0000000007AA7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7AA7000
|
Size: |
8192
|
|
30FC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000030FC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30FC000
|
Size: |
20480
|
|
3510000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003510000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3510000
|
Size: |
4096
|
|
31BE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2010276134.00000000031BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
31BE000
|
Size: |
8192
|
|
D4D0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.2270892704.000000000D4D0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
D4D0000
|
Size: |
65536
|
|
294F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.000000000294F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
294F000
|
Size: |
57344
|
|
D65000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000D65000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
D65000
|
Size: |
8192
|
|
A0D4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2270679460.000000000A0D4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
A0D4000
|
Size: |
12288
|
|
54F000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.000000000054F000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
54F000
|
Size: |
20480
|
|
37A8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000037A8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
37A8000
|
Size: |
4096
|
|
28B6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000028B6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
28B6000
|
Size: |
4096
|
|
1067000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000001067000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
1067000
|
Size: |
4096
|
|
11DB000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2399969971.00000000011DB000.00000004.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
11DB000
|
Size: |
8192
|
|
23AD8243000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1933494984.0000023AD8243000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AD8243000
|
Size: |
90112
|
|
23AA9B7C000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1905977543.0000023AA9B7C000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AA9B7C000
|
Size: |
12288
|
|
23AA9AA7000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1905977543.0000023AA9AA7000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AA9AA7000
|
Size: |
4096
|
|
3710000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003710000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3710000
|
Size: |
4096
|
|
14E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2476826022.00000000014E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
14E0000
|
Size: |
61440
|
|
1376000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1904197574.0000000001376000.00000004.00000001.01000000.00000006.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1376000
|
Size: |
8192
|
|
378F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000378F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
378F000
|
Size: |
4096
|
|
78D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2519758074.00000000078D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
78D0000
|
Size: |
4096
|
|
32B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000032B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32B0000
|
Size: |
4096
|
|
53DD000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2012095032.00000000053DD000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
53DD000
|
Size: |
458752
|
|
5661000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1981980483.0000000005661000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5661000
|
Size: |
4096
|
|
44E000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.000000000044E000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
44E000
|
Size: |
16384
|
|
3356000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003356000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3356000
|
Size: |
28672
|
|
35C9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000035C9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
35C9000
|
Size: |
4096
|
|
4B60000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2262755461.0000000004B60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B60000
|
Size: |
4096
|
|
3400000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003400000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3400000
|
Size: |
4096
|
|
5BCE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2481668484.0000000005BCE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5BCE000
|
Size: |
8192
|
|
3727000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003727000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3727000
|
Size: |
4096
|
|
2994000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002994000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2994000
|
Size: |
4096
|
|
120B000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2400228275.000000000120B000.00000004.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
120B000
|
Size: |
4096
|
|
23AD8D60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8D60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8D60000
|
Size: |
40960
|
|
3366000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003366000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3366000
|
Size: |
4096
|
|
26B3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000026B3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
26B3000
|
Size: |
53248
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1946337126.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
120D000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000000.2134064020.000000000120D000.00000008.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
120D000
|
Size: |
4096
|
|
33E5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000033E5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33E5000
|
Size: |
4096
|
|
2B12000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002B12000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B12000
|
Size: |
4096
|
|
14A6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2472811392.00000000014A6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14A6000
|
Size: |
20480
|
|
2823000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002823000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2823000
|
Size: |
4096
|
|
339A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000339A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
339A000
|
Size: |
4096
|
|
29CA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000029CA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29CA000
|
Size: |
4096
|
|
34D7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000034D7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
34D7000
|
Size: |
4096
|
|
23AA80ED000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1636107946.0000023AA80ED000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AA80ED000
|
Size: |
32768
|
|
2691000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002691000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2691000
|
Size: |
4096
|
|
556E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2481120967.000000000556E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
556E000
|
Size: |
8192
|
|
32AE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000032AE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32AE000
|
Size: |
4096
|
|
23AD8CA3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8CA3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8CA3000
|
Size: |
20480
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1946376816.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
77E7000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2269953710.00000000077E7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
77E7000
|
Size: |
12288
|
|
64BB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2517830884.00000000064BB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
64BB000
|
Size: |
20480
|
|
26B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000026B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
26B0000
|
Size: |
4096
|
|
23AAA410000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1907163068.0000023AAA410000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AAA410000
|
Size: |
4096
|
|
31D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000031D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31D0000
|
Size: |
20480
|
|
31AE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000031AE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31AE000
|
Size: |
20480
|
|
23AD8E35000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1666315726.0000023AD8E35000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
23AD8E35000
|
Size: |
20480
|
|
34B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000034B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
34B0000
|
Size: |
45056
|
|
5560000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2514777153.0000000005560000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5560000
|
Size: |
65536
|
|
181414E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.2135863753.00000181414E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
181414E0000
|
Size: |
86016
|
|
3533000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003533000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3533000
|
Size: |
49152
|
|
297D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.000000000297D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
297D000
|
Size: |
4096
|
|
315D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000315D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
315D000
|
Size: |
20480
|
|
10AD000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.00000000010AD000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
10AD000
|
Size: |
12288
|
|
36B9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2251107589.00000000036B9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
36B9000
|
Size: |
151552
|
|
1200000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2474315450.0000000001200000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1200000
|
Size: |
4096
|
|
34C6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000034C6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
34C6000
|
Size: |
4096
|
|
3708000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003708000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3708000
|
Size: |
4096
|
|
7BAB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2520106850.0000000007BAB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7BAB000
|
Size: |
4096
|
|
6DB000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2233410270.00000000006DB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6DB000
|
Size: |
344064
|
|
23AD8E2F000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1666315726.0000023AD8E2F000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
23AD8E2F000
|
Size: |
20480
|
|
AC0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2235790558.0000000000AC0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
AC0000
|
Size: |
4096
|
|
69A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1378604262.000000000069A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
69A000
|
Size: |
4096
|
|
23AD8B22000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1661317128.0000023AD8B22000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8B22000
|
Size: |
24576
|
|
3224000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2443268397.0000000003224000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3224000
|
Size: |
4096
|
|
23AD82BB000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1933494984.0000023AD82BB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AD82BB000
|
Size: |
20480
|
|
2A52000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002A52000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A52000
|
Size: |
4096
|
|
26E4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000026E4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
26E4000
|
Size: |
4096
|
|
2AE1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002AE1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AE1000
|
Size: |
53248
|
|
18170DAF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2430329078.0000018170DAF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
18170DAF000
|
Size: |
20480
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
755E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2269437633.000000000755E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
755E000
|
Size: |
8192
|
|
35C3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000035C3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
35C3000
|
Size: |
4096
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1946693690.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
26E7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000026E7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
26E7000
|
Size: |
36864
|
|
4FF000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.00000000004FF000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
4FF000
|
Size: |
20480
|
|
487000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.0000000000487000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
487000
|
Size: |
20480
|
|
297B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.000000000297B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
297B000
|
Size: |
4096
|
|
1616000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000014.00000002.2475064648.0000000001616000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1616000
|
Size: |
8192
|
|
3298000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003298000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3298000
|
Size: |
20480
|
|
533000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.0000000000533000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
533000
|
Size: |
16384
|
|
5520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2514477506.0000000005520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5520000
|
Size: |
65536
|
|
E66000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000E66000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
E66000
|
Size: |
12288
|
|
1814306C000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2402659704.000001814306C000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
1814306C000
|
Size: |
12288
|
|
671A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2519237756.000000000671A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
671A000
|
Size: |
4096
|
|
367A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000367A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
367A000
|
Size: |
40960
|
|
54A000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.000000000054A000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
54A000
|
Size: |
16384
|
|
3FF1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2501089519.0000000003FF1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3FF1000
|
Size: |
36864
|
|
18143023000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2402659704.0000018143023000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
18143023000
|
Size: |
4096
|
|
23AD8ABF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1661317128.0000023AD8ABF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8ABF000
|
Size: |
24576
|
|
10EA000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000012.00000002.2474094183.00000000010EA000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
10EA000
|
Size: |
4096
|
|
27BB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000027BB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
27BB000
|
Size: |
4096
|
|
5660000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2012607606.0000000005660000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5660000
|
Size: |
49152
|
|
5AD5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2265211914.0000000005AD5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5AD5000
|
Size: |
40960
|
|
2B14000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002B14000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B14000
|
Size: |
57344
|
|
34DD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000034DD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
34DD000
|
Size: |
73728
|
|
32AA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000032AA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32AA000
|
Size: |
12288
|
|
781E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2519481374.000000000781E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
781E000
|
Size: |
8192
|
|
3220000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.2445163690.0000000003220000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3220000
|
Size: |
16384
|
|
498000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.0000000000498000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
498000
|
Size: |
20480
|
|
3108000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003108000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3108000
|
Size: |
16384
|
|
181414E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.2135691640.00000181414E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
181414E0000
|
Size: |
28672
|
|
57EE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2481349927.00000000057EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
57EE000
|
Size: |
8192
|
|
DAB000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000DAB000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
DAB000
|
Size: |
86016
|
|
2420000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2236528011.0000000002420000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2420000
|
Size: |
49152
|
|
3430000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003430000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3430000
|
Size: |
12288
|
|
11E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2471739710.00000000011E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11E0000
|
Size: |
8192
|
|
120B000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000012.00000002.2474451449.000000000120B000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
120B000
|
Size: |
4096
|
|
453000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.0000000000453000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
453000
|
Size: |
20480
|
|
23AD8E07000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1666315726.0000023AD8E07000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
23AD8E07000
|
Size: |
20480
|
|
2969000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002969000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2969000
|
Size: |
69632
|
|
36EB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000036EB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
36EB000
|
Size: |
12288
|
|
23AAA378000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1907163068.0000023AAA378000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AAA378000
|
Size: |
4096
|
|
27EF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000027EF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
27EF000
|
Size: |
4096
|
|
1500000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000012.00000002.2477024952.0000000001500000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
1500000
|
Size: |
4096
|
|
EF8000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000EF8000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
EF8000
|
Size: |
20480
|
|
2AF9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002AF9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AF9000
|
Size: |
4096
|
|
23AD8D71000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8D71000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8D71000
|
Size: |
98304
|
|
79C0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2270250883.00000000079C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
79C0000
|
Size: |
16384
|
|
514D000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2263869478.000000000514D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
514D000
|
Size: |
12288
|
|
3787000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003787000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3787000
|
Size: |
4096
|
|
23AD8A00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1661317128.0000023AD8A00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8A00000
|
Size: |
28672
|
|
D61000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000D61000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
D61000
|
Size: |
8192
|
|
3660000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003660000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3660000
|
Size: |
53248
|
|
313B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000313B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
313B000
|
Size: |
20480
|
|
2A04000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002A04000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A04000
|
Size: |
4096
|
|
355D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000355D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
355D000
|
Size: |
4096
|
|
620000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2233380864.0000000000620000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
620000
|
Size: |
8192
|
|
1620000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2475172049.0000000001620000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1620000
|
Size: |
4096
|
|
33F7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.2445598095.00000000033F7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33F7000
|
Size: |
8192
|
|
2AEF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002AEF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AEF000
|
Size: |
4096
|
|
1373000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1904179328.0000000001373000.00000004.00000001.01000000.00000006.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1373000
|
Size: |
4096
|
|
EF7D9FD000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1904847129.000000EF7D9FD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
EF7D9FD000
|
Size: |
12288
|
|
23AD8A08000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1661317128.0000023AD8A08000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8A08000
|
Size: |
53248
|
|
F40000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000F40000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
F40000
|
Size: |
4096
|
|
4EE8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2480695562.0000000004EE8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4EE8000
|
Size: |
4096
|
|
3789000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003789000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3789000
|
Size: |
4096
|
|
328B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000328B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
328B000
|
Size: |
4096
|
|
11F1000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2400052406.00000000011F1000.00000004.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
11F1000
|
Size: |
4096
|
|
148A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2472811392.000000000148A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
148A000
|
Size: |
20480
|
|
2440000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2236696354.0000000002440000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2440000
|
Size: |
65536
|
|
23AA9B4E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1905977543.0000023AA9B4E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AA9B4E000
|
Size: |
4096
|
|
136F000
|
unkown
|
page write copy
|
|
|
|
Name: |
0000000C.00000000.1632501936.000000000136F000.00000008.00000001.01000000.00000006.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
136F000
|
Size: |
446464
|
|
343A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000343A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
343A000
|
Size: |
4096
|
|
319D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000319D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
319D000
|
Size: |
40960
|
|
3546000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003546000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3546000
|
Size: |
4096
|
|
50B000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.000000000050B000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
50B000
|
Size: |
16384
|
|
549D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000016.00000002.2447514599.000000000549D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
549D000
|
Size: |
458752
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1978314594.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
26A6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000026A6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
26A6000
|
Size: |
4096
|
|
3672000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003672000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3672000
|
Size: |
12288
|
|
704FD000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2523050457.00000000704FD000.00000004.00000001.01000000.0000000C.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
704FD000
|
Size: |
8192
|
|
2783000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002783000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2783000
|
Size: |
49152
|
|
23AA9B98000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1905977543.0000023AA9B98000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AA9B98000
|
Size: |
4096
|
|
18141502000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.2136113353.0000018141502000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
18141502000
|
Size: |
32768
|
|
2AA1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002AA1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AA1000
|
Size: |
4096
|
|
54D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2513754895.00000000054D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
54D0000
|
Size: |
12288
|
|
23AD8A26000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1661317128.0000023AD8A26000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8A26000
|
Size: |
28672
|
|
66A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2518592342.00000000066A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
66A0000
|
Size: |
4096
|
|
566E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2481173326.000000000566E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
566E000
|
Size: |
8192
|
|
272E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.000000000272E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
272E000
|
Size: |
4096
|
|
4DD000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.00000000004DD000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
4DD000
|
Size: |
40960
|
|
689000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1378724805.0000000000689000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
689000
|
Size: |
8192
|
|
23AD8DAC000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1666315726.0000023AD8DAC000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
23AD8DAC000
|
Size: |
90112
|
|
18143048000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2402659704.0000018143048000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
18143048000
|
Size: |
4096
|
|
33ED000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000033ED000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33ED000
|
Size: |
49152
|
|
26F9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000026F9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
26F9000
|
Size: |
118784
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1945958182.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
13BF000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1904437127.00000000013BF000.00000004.00000001.01000000.00000006.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
13BF000
|
Size: |
4096
|
|
F00000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000C.00000000.1631961717.0000000000F00000.00000002.00000001.01000000.00000006.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F00000
|
Size: |
4096
|
|
3224000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2445046849.0000000003224000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3224000
|
Size: |
4096
|
|
23AD8A2E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1661317128.0000023AD8A2E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8A2E000
|
Size: |
57344
|
|
348A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000348A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
348A000
|
Size: |
4096
|
|
507E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2480765156.000000000507E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
507E000
|
Size: |
8192
|
|
669E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2518552462.000000000669E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
669E000
|
Size: |
8192
|
|
23AD8C0A000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1666315726.0000023AD8C0A000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
23AD8C0A000
|
Size: |
290816
|
|
13B1000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1904382788.00000000013B1000.00000004.00000001.01000000.00000006.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
13B1000
|
Size: |
4096
|
|
1814302C000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2402659704.000001814302C000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
1814302C000
|
Size: |
12288
|
|
23AD8A1F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1661317128.0000023AD8A1F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8A1F000
|
Size: |
24576
|
|
23AD8C92000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8C92000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8C92000
|
Size: |
16384
|
|
1383000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1904239005.0000000001383000.00000004.00000001.01000000.00000006.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1383000
|
Size: |
4096
|
|
5867000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2515447055.0000000005867000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5867000
|
Size: |
159744
|
|
23AD8DEB000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1666315726.0000023AD8DEB000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
23AD8DEB000
|
Size: |
16384
|
|
23AD8CED000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8CED000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8CED000
|
Size: |
20480
|
|
687000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1378739371.0000000000687000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
687000
|
Size: |
8192
|
|
3150000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2009204776.0000000003150000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3150000
|
Size: |
4096
|
|
3561000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003561000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3561000
|
Size: |
4096
|
|
1156000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000001156000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
1156000
|
Size: |
20480
|
|
33E7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000033E7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33E7000
|
Size: |
4096
|
|
AA4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2235599202.0000000000AA4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
AA4000
|
Size: |
8192
|
|
2825000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002825000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2825000
|
Size: |
86016
|
|
23AA8158000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1904927879.0000023AA8158000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AA8158000
|
Size: |
147456
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
382B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000382B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
382B000
|
Size: |
4096
|
|
23AD8C53000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8C53000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8C53000
|
Size: |
40960
|
|
23AAA958000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1907513975.0000023AAA958000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AAA958000
|
Size: |
4096
|
|
E3A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2471165574.0000000000E3A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
E3A000
|
Size: |
24576
|
|
E51000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000E51000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
E51000
|
Size: |
4096
|
|
1627000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000014.00000002.2475301166.0000000001627000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1627000
|
Size: |
4096
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1980715075.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
8192
|
|
33B7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000033B7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33B7000
|
Size: |
4096
|
|
23AD82D2000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1933494984.0000023AD82D2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AD82D2000
|
Size: |
20480
|
|
125E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2471927544.000000000125E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
125E000
|
Size: |
8192
|
|
6CE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2266381886.0000000006CE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6CE0000
|
Size: |
24576
|
|
3725000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003725000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3725000
|
Size: |
4096
|
|
30AC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000030AC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30AC000
|
Size: |
20480
|
|
5661000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1982105874.0000000005661000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5661000
|
Size: |
4096
|
|
45F000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.000000000045F000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
45F000
|
Size: |
20480
|
|
23AAA960000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1907582467.0000023AAA960000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AAA960000
|
Size: |
4096
|
|
314E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2008940049.000000000314E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
314E000
|
Size: |
8192
|
|
1724000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2478423380.0000000001724000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1724000
|
Size: |
4096
|
|
7CFF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2270585442.0000000007CFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7CFF000
|
Size: |
4096
|
|
1659000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000C.00000000.1632619836.0000000001659000.00000002.00000001.01000000.00000006.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1659000
|
Size: |
610304
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
301D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000301D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
301D000
|
Size: |
8192
|
|
2E9D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2478908327.0000000002E9D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2E9D000
|
Size: |
12288
|
|
6AF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1635376735.00000000006AF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6AF000
|
Size: |
8192
|
|
27BF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000027BF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
27BF000
|
Size: |
4096
|
|
32A6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000032A6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32A6000
|
Size: |
4096
|
|
120B000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000000.2134064020.000000000120B000.00000008.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
120B000
|
Size: |
4096
|
|
26F5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000026F5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
26F5000
|
Size: |
4096
|
|
848E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2521887357.000000000848E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
848E000
|
Size: |
8192
|
|
148E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2476535779.000000000148E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
148E000
|
Size: |
8192
|
|
3770000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003770000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3770000
|
Size: |
4096
|
|
18143081000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2402659704.0000018143081000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
18143081000
|
Size: |
32768
|
|
23AD8A3D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1661317128.0000023AD8A3D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8A3D000
|
Size: |
28672
|
|
354A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000354A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
354A000
|
Size: |
4096
|
|
59B0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.2264540460.00000000059B0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
59B0000
|
Size: |
65536
|
|
371D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000371D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
371D000
|
Size: |
4096
|
|
2A06000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002A06000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A06000
|
Size: |
49152
|
|
23AD8A89000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1661317128.0000023AD8A89000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8A89000
|
Size: |
28672
|
|
2897000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002897000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2897000
|
Size: |
4096
|
|
11B3000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2399807505.00000000011B3000.00000004.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
11B3000
|
Size: |
4096
|
|
E61000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000E61000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
E61000
|
Size: |
8192
|
|
32C5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000032C5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32C5000
|
Size: |
4096
|
|
104E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2473379324.000000000104E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
104E000
|
Size: |
8192
|
|
476000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.0000000000476000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
476000
|
Size: |
40960
|
|
26C7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000026C7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
26C7000
|
Size: |
4096
|
|
31CB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000031CB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31CB000
|
Size: |
16384
|
|
5060000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2513674853.0000000005060000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5060000
|
Size: |
4096
|
|
36D8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000036D8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
36D8000
|
Size: |
4096
|
|
6D02000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2266381886.0000000006D02000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6D02000
|
Size: |
1572864
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2728000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002728000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2728000
|
Size: |
4096
|
|
634F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2481783421.000000000634F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
634F000
|
Size: |
4096
|
|
29AD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000029AD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29AD000
|
Size: |
4096
|
|
EF7DAFE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1904882099.000000EF7DAFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
EF7DAFE000
|
Size: |
8192
|
|
23AAA371000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1907163068.0000023AAA371000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AAA371000
|
Size: |
24576
|
|
2747000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002747000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2747000
|
Size: |
4096
|
|
1612000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2474953657.0000000001612000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1612000
|
Size: |
4096
|
|
274D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.000000000274D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
274D000
|
Size: |
4096
|
|
704FF000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2271697210.00000000704FF000.00000002.00000001.01000000.0000000C.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
704FF000
|
Size: |
12288
|
|
23AAA954000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1907513975.0000023AAA954000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AAA954000
|
Size: |
12288
|
|
365D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000365D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
365D000
|
Size: |
4096
|
|
110B000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.000000000110B000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
110B000
|
Size: |
12288
|
|
23AD8D2C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8D2C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8D2C000
|
Size: |
20480
|
|
2695000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002695000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2695000
|
Size: |
4096
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1978422857.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
F0A000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000F0A000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
F0A000
|
Size: |
16384
|
|
7AE06FD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2400668935.0000007AE06FD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7AE06FD000
|
Size: |
12288
|
|
2A54000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002A54000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A54000
|
Size: |
12288
|
|
11BA000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2399869972.00000000011BA000.00000004.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
11BA000
|
Size: |
4096
|
|
11FF000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000000.2134064020.00000000011FF000.00000008.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
11FF000
|
Size: |
8192
|
|
8170000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000014.00000002.2521532292.0000000008170000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
8170000
|
Size: |
65536
|
|
23AD7A86000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1657048421.0000023AD7A86000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AD7A86000
|
Size: |
2019328
|
|
1609000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2474615239.0000000001609000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1609000
|
Size: |
8192
|
|
12D0000
|
unkown
|
page execute read
|
|
|
|
Name: |
0000000C.00000002.1904066220.00000000012D0000.00000020.00000001.01000000.00000006.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
12D0000
|
Size: |
28672
|
|
4B63000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2262755461.0000000004B63000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B63000
|
Size: |
8192
|
|
2B72000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002B72000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B72000
|
Size: |
4096
|
|
3295000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003295000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3295000
|
Size: |
8192
|
|
181414F8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2400743173.00000181414F8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
181414F8000
|
Size: |
4096
|
|
18143D55000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.2157415259.0000018143D55000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
18143D55000
|
Size: |
4096
|
|
7B96000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2520106850.0000000007B96000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7B96000
|
Size: |
61440
|
|
3691000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003691000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3691000
|
Size: |
4096
|
|
D49E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2270733619.000000000D49E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
D49E000
|
Size: |
8192
|
|
7D3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2520649842.0000000007D3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7D3E000
|
Size: |
8192
|
|
48D000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.000000000048D000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
48D000
|
Size: |
16384
|
|
2DEE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2007944021.0000000002DEE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2DEE000
|
Size: |
8192
|
|
2766000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002766000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2766000
|
Size: |
4096
|
|
3396000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003396000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3396000
|
Size: |
12288
|
|
23AD8ACE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1661317128.0000023AD8ACE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8ACE000
|
Size: |
24576
|
|
23AAC8A1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1907942193.0000023AAC8A1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AAC8A1000
|
Size: |
172032
|
|
181414A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2400743173.00000181414A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
181414A0000
|
Size: |
32768
|
|
18171E71000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2431517792.0000018171E71000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
18171E71000
|
Size: |
4096
|
|
23AD8AF4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1661317128.0000023AD8AF4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8AF4000
|
Size: |
24576
|
|
35B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000035B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
35B0000
|
Size: |
4096
|
|
68B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1378681471.000000000068B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
68B000
|
Size: |
4096
|
|
18142FFE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2402659704.0000018142FFE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
18142FFE000
|
Size: |
4096
|
|
28B8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000028B8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
28B8000
|
Size: |
4096
|
|
1050000
|
heap
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2473462848.0000000001050000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1050000
|
Size: |
8192
|
|
6A4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1379314404.00000000006A4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6A4000
|
Size: |
12288
|
|
34C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000034C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
34C0000
|
Size: |
4096
|
|
33F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.2445598095.00000000033F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33F0000
|
Size: |
20480
|
|
1116000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000002.2399689587.0000000001116000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
1116000
|
Size: |
4096
|
|
27F3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000027F3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
27F3000
|
Size: |
4096
|
|
14D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2476647456.00000000014D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
14D0000
|
Size: |
45056
|
|
566000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.0000000000566000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
566000
|
Size: |
20480
|
|
DFF000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000DFF000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
DFF000
|
Size: |
16384
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1978351838.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
4A1D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2261082402.0000000004A1D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4A1D000
|
Size: |
8192
|
|
33C8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000033C8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33C8000
|
Size: |
4096
|
|
181437A1000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2403977009.00000181437A1000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
181437A1000
|
Size: |
4096
|
|
33D0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000016.00000002.2445541511.00000000033D0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
33D0000
|
Size: |
4096
|
|
DBAE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2522921349.000000000DBAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
DBAE000
|
Size: |
8192
|
|
36F5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000036F5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
36F5000
|
Size: |
4096
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1978297675.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
23AA9B5D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1905977543.0000023AA9B5D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AA9B5D000
|
Size: |
4096
|
|
2AF3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002AF3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AF3000
|
Size: |
4096
|
|
23AAA210000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1906847867.0000023AAA210000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AAA210000
|
Size: |
4096
|
|
51B0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2264379107.00000000051B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
51B0000
|
Size: |
8192
|
|
272A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.000000000272A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
272A000
|
Size: |
4096
|
|
13F4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2472677378.00000000013F4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
13F4000
|
Size: |
8192
|
|
13FD000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000014.00000002.2472738927.00000000013FD000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
13FD000
|
Size: |
4096
|
|
52D000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.000000000052D000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
52D000
|
Size: |
20480
|
|
23AD8DE5000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1666315726.0000023AD8DE5000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
23AD8DE5000
|
Size: |
20480
|
|
3124000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003124000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3124000
|
Size: |
20480
|
|
337B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000337B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
337B000
|
Size: |
4096
|
|
31D8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000031D8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31D8000
|
Size: |
729088
|
|
30C9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000030C9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30C9000
|
Size: |
16384
|
|
801E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2521243498.000000000801E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
801E000
|
Size: |
8192
|
|
7CBE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2270548070.0000000007CBE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7CBE000
|
Size: |
8192
|
|
3385000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003385000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3385000
|
Size: |
4096
|
|
7AD0000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2520067154.0000000007AD0000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
7AD0000
|
Size: |
8192
|
|
37C8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000037C8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
37C8000
|
Size: |
69632
|
|
10E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2474006125.00000000010E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
10E0000
|
Size: |
4096
|
|
2A6D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002A6D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A6D000
|
Size: |
4096
|
|
505E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2513632590.000000000505E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
505E000
|
Size: |
8192
|
|
DC7000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000DC7000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
DC7000
|
Size: |
40960
|
|
6A7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1378483174.00000000006A7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6A7000
|
Size: |
20480
|
|
341D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000341D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
341D000
|
Size: |
4096
|
|
181434F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2403487525.00000181434F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
181434F0000
|
Size: |
8192
|
|
F4B000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000F4B000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
F4B000
|
Size: |
4096
|
|
23AA9FD3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1906640820.0000023AA9FD3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AA9FD3000
|
Size: |
16384
|
|
30CE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000030CE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30CE000
|
Size: |
20480
|
|
697000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1378651925.0000000000697000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
697000
|
Size: |
12288
|
|
27DE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000027DE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
27DE000
|
Size: |
4096
|
|
181714E2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2431242997.00000181714E2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
181714E2000
|
Size: |
4096
|
|
3158000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003158000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3158000
|
Size: |
16384
|
|
23AAA950000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1907513975.0000023AAA950000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AAA950000
|
Size: |
12288
|
|
363E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000363E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
363E000
|
Size: |
4096
|
|
10C3000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.00000000010C3000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
10C3000
|
Size: |
4096
|
|
336C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000336C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
336C000
|
Size: |
57344
|
|
1270000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2472018997.0000000001270000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1270000
|
Size: |
16384
|
|
1234000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000000.2134754022.0000000001234000.00000002.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1234000
|
Size: |
4096
|
|
11DE000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2399998449.00000000011DE000.00000004.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
11DE000
|
Size: |
8192
|
|
2E50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2478757299.0000000002E50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E50000
|
Size: |
49152
|
|
33C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.2445382893.00000000033C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33C0000
|
Size: |
4096
|
|
2B27000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002B27000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B27000
|
Size: |
4096
|
|
3291000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003291000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3291000
|
Size: |
4096
|
|
37A6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000037A6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
37A6000
|
Size: |
4096
|
|
3402000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003402000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3402000
|
Size: |
4096
|
|
56E0000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000012.00000002.2481315553.00000000056E0000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
56E0000
|
Size: |
4096
|
|
2F3C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2479136612.0000000002F3C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F3C000
|
Size: |
16384
|
|
342E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000342E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
342E000
|
Size: |
4096
|
|
2A73000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002A73000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A73000
|
Size: |
12288
|
|
277D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.000000000277D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
277D000
|
Size: |
12288
|
|
23AAC8CC000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1907942193.0000023AAC8CC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AAC8CC000
|
Size: |
8048640
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
URLs found in memory or binary data |
Networking |
|
|
33CC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000033CC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33CC000
|
Size: |
4096
|
|
67F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1379114976.000000000067F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
67F000
|
Size: |
49152
|
|
5B1E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2012744935.0000000005B1E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5B1E000
|
Size: |
8192
|
|
55B000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.000000000055B000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
55B000
|
Size: |
40960
|
|
2B0A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002B0A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B0A000
|
Size: |
12288
|
|
583000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.0000000000583000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
583000
|
Size: |
98304
|
|
E4D000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000E4D000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
E4D000
|
Size: |
12288
|
|
69E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1378574196.000000000069E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
69E000
|
Size: |
36864
|
|
27B7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000027B7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
27B7000
|
Size: |
4096
|
|
EDD000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000EDD000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
EDD000
|
Size: |
20480
|
|
32A2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000032A2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32A2000
|
Size: |
4096
|
|
171C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2478211465.000000000171C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
171C000
|
Size: |
16384
|
|
F01000
|
unkown
|
page execute read
|
|
|
|
Name: |
0000000C.00000000.1631975629.0000000000F01000.00000020.00000001.01000000.00000006.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
F01000
|
Size: |
4644864
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
URLs found in memory or binary data |
Networking |
|
|
23AD82D8000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1933494984.0000023AD82D8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AD82D8000
|
Size: |
98304
|
|
2821000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002821000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2821000
|
Size: |
4096
|
|
5D0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2233309723.00000000005D0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5D0000
|
Size: |
4096
|
|
2B0E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002B0E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B0E000
|
Size: |
4096
|
|
18143064000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2402659704.0000018143064000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
18143064000
|
Size: |
24576
|
|
5499000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000016.00000002.2447514599.0000000005499000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
5499000
|
Size: |
4096
|
|
18143780000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2403977009.0000018143780000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
18143780000
|
Size: |
12288
|
|
70E0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2268875075.00000000070E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
70E0000
|
Size: |
53248
|
|
793D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2519850367.000000000793D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
793D000
|
Size: |
12288
|
|
6587000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2518228077.0000000006587000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6587000
|
Size: |
36864
|
|
650000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1635376735.0000000000650000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
650000
|
Size: |
32768
|
|
704E0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2271216371.00000000704E0000.00000002.00000001.01000000.0000000C.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
704E0000
|
Size: |
4096
|
|
6590000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2518394314.0000000006590000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6590000
|
Size: |
12288
|
|
5B5D000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2012781377.0000000005B5D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5B5D000
|
Size: |
12288
|
|
37A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000037A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
37A0000
|
Size: |
4096
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1946612038.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
2AD6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002AD6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AD6000
|
Size: |
4096
|
|
68B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1378931645.000000000068B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
68B000
|
Size: |
221184
|
|
15FF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2474558082.00000000015FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
15FF000
|
Size: |
4096
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1978438691.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
18143669000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2403657756.0000018143669000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
18143669000
|
Size: |
12288
|
|
26A4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000026A4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
26A4000
|
Size: |
4096
|
|
34AB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000034AB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
34AB000
|
Size: |
12288
|
|
23AA8090000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1904927879.0000023AA8090000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AA8090000
|
Size: |
32768
|
|
1814154C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2400743173.000001814154C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1814154C000
|
Size: |
245760
|
|
A8F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2235475061.0000000000A8F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
A8F000
|
Size: |
4096
|
|
23AD8D56000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1666315726.0000023AD8D56000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
23AD8D56000
|
Size: |
20480
|
|
23AD8C81000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8C81000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8C81000
|
Size: |
16384
|
|
3224000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2443494760.0000000003224000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3224000
|
Size: |
4096
|
|
292E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.000000000292E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
292E000
|
Size: |
4096
|
|
6C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1635502995.00000000006C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6C0000
|
Size: |
4096
|
|
2762000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002762000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2762000
|
Size: |
12288
|
|
372C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000372C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
372C000
|
Size: |
53248
|
|
2AFC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002AFC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AFC000
|
Size: |
53248
|
|
23AD7C83000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1661224462.0000023AD7C83000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AD7C83000
|
Size: |
4096
|
|
23AD8276000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1933494984.0000023AD8276000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AD8276000
|
Size: |
20480
|
|
26C3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000026C3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
26C3000
|
Size: |
4096
|
|
116D000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.000000000116D000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
116D000
|
Size: |
20480
|
|
23AD8D04000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8D04000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8D04000
|
Size: |
20480
|
|
26DC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000026DC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
26DC000
|
Size: |
4096
|
|
354C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000354C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
354C000
|
Size: |
4096
|
|
2730000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002730000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2730000
|
Size: |
4096
|
|
588F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2515447055.000000000588F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
588F000
|
Size: |
221184
|
|
1116000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000001116000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
1116000
|
Size: |
16384
|
|
7FF48F160000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1635894483.00007FF48F160000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
7FF48F160000
|
Size: |
360448
|
|
32CB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000032CB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32CB000
|
Size: |
90112
|
|
23AD8B0B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1661317128.0000023AD8B0B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8B0B000
|
Size: |
24576
|
|
2A6F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002A6F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A6F000
|
Size: |
4096
|
|
71DD000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2269245972.00000000071DD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
71DD000
|
Size: |
8192
|
|
297F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.000000000297F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
297F000
|
Size: |
4096
|
|
1290000
|
heap
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2474851091.0000000001290000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1290000
|
Size: |
24576
|
|
32A4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000032A4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32A4000
|
Size: |
4096
|
|
14A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2472811392.00000000014A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14A0000
|
Size: |
12288
|
|
28B2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000028B2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
28B2000
|
Size: |
12288
|
|
7B5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1635556345.00000000007B5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7B5000
|
Size: |
12288
|
|
5AB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2264978619.0000000005AB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5AB0000
|
Size: |
65536
|
|
34A5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000034A5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
34A5000
|
Size: |
4096
|
|
23AD8C86000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8C86000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8C86000
|
Size: |
20480
|
|
13E0000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1904487859.00000000013E0000.00000004.00000001.01000000.00000006.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
13E0000
|
Size: |
4096
|
|
3488000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003488000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3488000
|
Size: |
4096
|
|
679000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1379286290.0000000000679000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
679000
|
Size: |
4096
|
|
27F1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000027F1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
27F1000
|
Size: |
4096
|
|
59C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2264651042.00000000059C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
59C0000
|
Size: |
24576
|
|
35A6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000035A6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
35A6000
|
Size: |
4096
|
|
23AD8D95000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1666315726.0000023AD8D95000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
23AD8D95000
|
Size: |
90112
|
|
2749000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002749000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2749000
|
Size: |
4096
|
|
4C80000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.2262809801.0000000004C80000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
4C80000
|
Size: |
8192
|
|
3810000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003810000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3810000
|
Size: |
4096
|
|
1389000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1904258681.0000000001389000.00000004.00000001.01000000.00000006.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1389000
|
Size: |
4096
|
|
16DC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2477447569.00000000016DC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
16DC000
|
Size: |
4096
|
|
6AF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1379260231.00000000006AF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6AF000
|
Size: |
8192
|
|
3224000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2441402079.0000000003224000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3224000
|
Size: |
4096
|
|
3175000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003175000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3175000
|
Size: |
40960
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1946578566.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
1730000
|
heap
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2478603171.0000000001730000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1730000
|
Size: |
16384
|
|
16B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2475858306.00000000016B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
16B0000
|
Size: |
36864
|
|
30C3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000030C3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30C3000
|
Size: |
20480
|
|
7AE05FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2400607962.0000007AE05FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7AE05FE000
|
Size: |
8192
|
|
2683000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002683000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2683000
|
Size: |
20480
|
|
1814303D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2402659704.000001814303D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
1814303D000
|
Size: |
12288
|
|
5A0E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2264780810.0000000005A0E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5A0E000
|
Size: |
8192
|
|
35B2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000035B2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
35B2000
|
Size: |
57344
|
|
13BA000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1904403088.00000000013BA000.00000004.00000001.01000000.00000006.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
13BA000
|
Size: |
8192
|
|
373A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000373A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
373A000
|
Size: |
4096
|
|
1142000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000001142000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
1142000
|
Size: |
24576
|
|
54D4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2513754895.00000000054D4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
54D4000
|
Size: |
94208
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1978521044.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
AD2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2235920170.0000000000AD2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
AD2000
|
Size: |
4096
|
|
14DC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2476647456.00000000014DC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
14DC000
|
Size: |
4096
|
|
3163000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003163000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3163000
|
Size: |
20480
|
|
D80000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000D80000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
D80000
|
Size: |
4096
|
|
32BF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000032BF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32BF000
|
Size: |
4096
|
|
3360000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003360000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3360000
|
Size: |
4096
|
|
11C8000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000000.2134064020.00000000011C8000.00000008.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
11C8000
|
Size: |
8192
|
|
3224000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2443615854.0000000003224000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3224000
|
Size: |
4096
|
|
27C3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000027C3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
27C3000
|
Size: |
4096
|
|
640000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1635357270.0000000000640000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
640000
|
Size: |
4096
|
|
294D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.000000000294D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
294D000
|
Size: |
4096
|
|
35F5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000035F5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
35F5000
|
Size: |
4096
|
|
23AD8AA8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1661317128.0000023AD8AA8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8AA8000
|
Size: |
24576
|
|
827F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2521689893.000000000827F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
827F000
|
Size: |
4096
|
|
18170F0C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.2398607592.0000018170F0C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
18170F0C000
|
Size: |
90112
|
|
28B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000028B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
28B0000
|
Size: |
4096
|
|
16D4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2477447569.00000000016D4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
16D4000
|
Size: |
4096
|
|
34DB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000034DB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
34DB000
|
Size: |
4096
|
|
51A0000
|
trusted library section
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2264265966.00000000051A0000.00000002.08000000.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page readonly
|
Base address: |
51A0000
|
Size: |
65536
|
|
3130000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003130000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3130000
|
Size: |
16384
|
|
18143005000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2402659704.0000018143005000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
18143005000
|
Size: |
8192
|
|
4A9000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.00000000004A9000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
4A9000
|
Size: |
20480
|
|
CFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1635645583.0000000000CFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
CFE000
|
Size: |
8192
|
|
2996000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002996000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2996000
|
Size: |
4096
|
|
2A1B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002A1B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A1B000
|
Size: |
4096
|
|
28F7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000028F7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
28F7000
|
Size: |
16384
|
|
16F6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2477447569.00000000016F6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
16F6000
|
Size: |
4096
|
|
48DF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1635940638.00000000048DF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
48DF000
|
Size: |
4096
|
|
4A0E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2261082402.0000000004A0E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4A0E000
|
Size: |
4096
|
|
33FC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.2445598095.00000000033FC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33FC000
|
Size: |
45056
|
|
46AC000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2260966369.00000000046AC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
46AC000
|
Size: |
16384
|
|
3529000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003529000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3529000
|
Size: |
4096
|
|
3141000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003141000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3141000
|
Size: |
40960
|
|
181710F6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.2160549637.00000181710F6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
181710F6000
|
Size: |
4096
|
|
2DF0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2008069277.0000000002DF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DF0000
|
Size: |
8192
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1946657063.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
5821000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2441686925.0000000005821000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5821000
|
Size: |
188416
|
|
23AD8A5C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1661317128.0000023AD8A5C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8A5C000
|
Size: |
24576
|
|
760000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1635538533.0000000000760000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
760000
|
Size: |
8192
|
|
27F7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000027F7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
27F7000
|
Size: |
4096
|
|
DE8000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000DE8000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
DE8000
|
Size: |
4096
|
|
1814304F000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2402659704.000001814304F000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
1814304F000
|
Size: |
4096
|
|
11C9000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2399918725.00000000011C9000.00000004.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
11C9000
|
Size: |
4096
|
|
33AF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000033AF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33AF000
|
Size: |
12288
|
|
366E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000366E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
366E000
|
Size: |
4096
|
|
6A2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1379217197.00000000006A2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6A2000
|
Size: |
61440
|
|
12C8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2474851091.00000000012C8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12C8000
|
Size: |
176128
|
|
5C4F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2266245521.0000000005C4F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5C4F000
|
Size: |
16384
|
|
2779000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002779000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2779000
|
Size: |
4096
|
|
11FF000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2400160007.00000000011FF000.00000004.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
11FF000
|
Size: |
4096
|
|
3600000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.2446617139.0000000003600000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3600000
|
Size: |
53248
|
|
7AE02FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2400508448.0000007AE02FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7AE02FE000
|
Size: |
8192
|
|
2DA0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2007912843.0000000002DA0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA0000
|
Size: |
4096
|
|
23AD8D84000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1666315726.0000023AD8D84000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
23AD8D84000
|
Size: |
65536
|
|
7A1D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2270250883.0000000007A1D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A1D000
|
Size: |
4096
|
|
2A90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002A90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A90000
|
Size: |
4096
|
|
750000
|
heap
|
page readonly
|
|
|
|
Name: |
00000008.00000002.1635521369.0000000000750000.00000002.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page readonly
|
Base address: |
750000
|
Size: |
4096
|
|
382D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000382D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
382D000
|
Size: |
4096
|
|
181414EE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.2136191077.00000181414EE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
181414EE000
|
Size: |
81920
|
|
58AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2481516994.00000000058AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
58AE000
|
Size: |
8192
|
|
18143640000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2403657756.0000018143640000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
18143640000
|
Size: |
4096
|
|
13F4000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000C.00000000.1632619836.00000000013F4000.00000002.00000001.01000000.00000006.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
13F4000
|
Size: |
2506752
|
|
29FC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000029FC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29FC000
|
Size: |
4096
|
|
277B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.000000000277B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
277B000
|
Size: |
4096
|
|
32CE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2010299336.00000000032CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
32CE000
|
Size: |
8192
|
|
26E2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000026E2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
26E2000
|
Size: |
4096
|
|
2808000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002808000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2808000
|
Size: |
4096
|
|
30A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000030A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30A0000
|
Size: |
20480
|
|
5C36000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2266120435.0000000005C36000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5C36000
|
Size: |
65536
|
|
275C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.000000000275C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
275C000
|
Size: |
4096
|
|
586E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2481471923.000000000586E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
586E000
|
Size: |
8192
|
|
23AAA257000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1906847867.0000023AAA257000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AAA257000
|
Size: |
4096
|
|
1163000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000001163000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
1163000
|
Size: |
20480
|
|
2A88000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002A88000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A88000
|
Size: |
4096
|
|
23AD8C8C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8C8C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8C8C000
|
Size: |
20480
|
|
3676000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003676000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3676000
|
Size: |
4096
|
|
11FD000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000000.2134064020.00000000011FD000.00000008.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
11FD000
|
Size: |
4096
|
|
23AA9B8D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1905977543.0000023AA9B8D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AA9B8D000
|
Size: |
12288
|
|
23AD8282000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1933494984.0000023AD8282000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AD8282000
|
Size: |
40960
|
|
162B000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000014.00000002.2475332375.000000000162B000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
162B000
|
Size: |
4096
|
|
572000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.0000000000572000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
572000
|
Size: |
16384
|
|
32EC000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2010338707.00000000032EC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32EC000
|
Size: |
331776
|
|
5720000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.2447771759.0000000005720000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5720000
|
Size: |
4096
|
|
318C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000318C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
318C000
|
Size: |
16384
|
|
5180000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.2264026001.0000000005180000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5180000
|
Size: |
65536
|
|
23AD82C3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1933494984.0000023AD82C3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AD82C3000
|
Size: |
32768
|
|
7650000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.2269637181.0000000007650000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7650000
|
Size: |
61440
|
|
2745000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002745000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2745000
|
Size: |
4096
|
|
2781000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002781000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2781000
|
Size: |
4096
|
|
4019000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2501089519.0000000004019000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4019000
|
Size: |
4096
|
|
16D6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2477447569.00000000016D6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
16D6000
|
Size: |
4096
|
|
10C4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2473780693.00000000010C4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
10C4000
|
Size: |
4096
|
|
28BD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000028BD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
28BD000
|
Size: |
53248
|
|
4C6000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.00000000004C6000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
4C6000
|
Size: |
20480
|
|
4EE000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.00000000004EE000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
4EE000
|
Size: |
20480
|
|
3657000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003657000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3657000
|
Size: |
4096
|
|
23AD8232000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1933494984.0000023AD8232000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AD8232000
|
Size: |
65536
|
|
18141490000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2400714899.0000018141490000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
18141490000
|
Size: |
4096
|
|
3706000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003706000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3706000
|
Size: |
4096
|
|
3191000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003191000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3191000
|
Size: |
20480
|
|
16A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2475682431.00000000016A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16A0000
|
Size: |
36864
|
|
23AD8B2A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1661317128.0000023AD8B2A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8B2A000
|
Size: |
24576
|
|
EF8000
|
stack
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2473170462.0000000000EF8000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
EF8000
|
Size: |
32768
|
|
23AAA217000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1906847867.0000023AAA217000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AAA217000
|
Size: |
12288
|
|
2A8E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002A8E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A8E000
|
Size: |
4096
|
|
23AD8CC5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8CC5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8CC5000
|
Size: |
20480
|
|
2B42000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002B42000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B42000
|
Size: |
4096
|
|
5C1B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2265629292.0000000005C1B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5C1B000
|
Size: |
12288
|
|
67A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1378739371.000000000067A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
67A000
|
Size: |
40960
|
|
4A40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2262160588.0000000004A40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4A40000
|
Size: |
65536
|
|
23AD8C75000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8C75000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8C75000
|
Size: |
20480
|
|
3119000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003119000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3119000
|
Size: |
16384
|
|
644E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2481820427.000000000644E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
644E000
|
Size: |
8192
|
|
33FA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000033FA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33FA000
|
Size: |
12288
|
|
B7B000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2236102736.0000000000B7B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B7B000
|
Size: |
20480
|
|
23AD8972000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1936096484.0000023AD8972000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8972000
|
Size: |
65536
|
|
365B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000365B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
365B000
|
Size: |
4096
|
|
4CCE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2262841217.0000000004CCE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4CCE000
|
Size: |
8192
|
|
10F7000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.00000000010F7000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
10F7000
|
Size: |
32768
|
|
485F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1635899905.000000000485F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
485F000
|
Size: |
4096
|
|
3744000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003744000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3744000
|
Size: |
167936
|
|
2769000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002769000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2769000
|
Size: |
12288
|
|
23AD8DF6000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1666315726.0000023AD8DF6000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
23AD8DF6000
|
Size: |
45056
|
|
5A10000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2264813726.0000000005A10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5A10000
|
Size: |
8192
|
|
4DCF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2262871552.0000000004DCF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4DCF000
|
Size: |
4096
|
|
18170EF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2431152145.0000018170EF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
18170EF0000
|
Size: |
12288
|
|
23AD8A6B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1661317128.0000023AD8A6B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8A6B000
|
Size: |
24576
|
|
1069000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000001069000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
1069000
|
Size: |
94208
|
|
13F0000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1904704367.00000000013F0000.00000004.00000001.01000000.00000006.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
13F0000
|
Size: |
4096
|
|
23AA80E2000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1904927879.0000023AA80E2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AA80E2000
|
Size: |
438272
|
|
7D40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2520730462.0000000007D40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D40000
|
Size: |
65536
|
|
23AD8CD1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8CD1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8CD1000
|
Size: |
16384
|
|
462F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1635738979.000000000462F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
462F000
|
Size: |
4096
|
|
3612000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003612000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3612000
|
Size: |
4096
|
|
635D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2517548241.000000000635D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
635D000
|
Size: |
12288
|
|
3548000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003548000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3548000
|
Size: |
4096
|
|
23AD8E02000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1666315726.0000023AD8E02000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
23AD8E02000
|
Size: |
16384
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1979365307.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
40F9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2501089519.00000000040F9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
40F9000
|
Size: |
139264
|
|
5661000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1982433743.0000000005661000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5661000
|
Size: |
4096
|
|
23AD8A73000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1661317128.0000023AD8A73000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8A73000
|
Size: |
24576
|
|
27DC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000027DC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
27DC000
|
Size: |
4096
|
|
3293000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003293000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3293000
|
Size: |
4096
|
|
23AD8C00000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1668402892.0000023AD8C00000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
23AD8C00000
|
Size: |
217088
|
|
40AE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2501089519.00000000040AE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
40AE000
|
Size: |
4096
|
|
1270000
|
heap
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2474618457.0000000001270000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1270000
|
Size: |
4096
|
|
78A0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2270161619.00000000078A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
78A0000
|
Size: |
12288
|
|
625D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2517463739.000000000625D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
625D000
|
Size: |
12288
|
|
66C6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2518745503.00000000066C6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
66C6000
|
Size: |
49152
|
|
3616000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003616000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3616000
|
Size: |
4096
|
|
481B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1635877693.000000000481B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
481B000
|
Size: |
20480
|
|
555000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.0000000000555000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
555000
|
Size: |
20480
|
|
465000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.0000000000465000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
465000
|
Size: |
16384
|
|
339C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000339C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
339C000
|
Size: |
4096
|
|
5C0E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2481731861.0000000005C0E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5C0E000
|
Size: |
8192
|
|
29D1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000029D1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29D1000
|
Size: |
53248
|
|
53D9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2012095032.00000000053D9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
53D9000
|
Size: |
4096
|
|
52B0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2012095032.00000000052B0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
52B0000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
1814307A000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2402659704.000001814307A000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
1814307A000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
18143647000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2403657756.0000018143647000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
18143647000
|
Size: |
12288
|
|
23AD8E3B000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1666315726.0000023AD8E3B000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
23AD8E3B000
|
Size: |
20480
|
|
23AA9B8B000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1905977543.0000023AA9B8B000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AA9B8B000
|
Size: |
4096
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1980415568.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
8192
|
|
23AD8D27000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8D27000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8D27000
|
Size: |
16384
|
|
36A2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000036A2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
36A2000
|
Size: |
4096
|
|
23AD82B0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1933494984.0000023AD82B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AD82B0000
|
Size: |
16384
|
|
23AD8C47000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8C47000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8C47000
|
Size: |
20480
|
|
26F3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000026F3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
26F3000
|
Size: |
4096
|
|
35FB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000035FB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
35FB000
|
Size: |
4096
|
|
704E1000
|
unkown
|
page execute read
|
|
|
|
Name: |
0000000D.00000002.2271418534.00000000704E1000.00000020.00000001.01000000.0000000C.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
704E1000
|
Size: |
86016
|
|
1222000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2400254234.0000000001222000.00000004.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1222000
|
Size: |
4096
|
|
815E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2521321905.000000000815E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
815E000
|
Size: |
8192
|
|
49F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2261082402.00000000049F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
49F0000
|
Size: |
12288
|
|
ECF000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000ECF000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
ECF000
|
Size: |
4096
|
|
37AC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000037AC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
37AC000
|
Size: |
49152
|
|
DD7000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000DD7000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
DD7000
|
Size: |
32768
|
|
C7E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1635606963.0000000000C7E000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
C7E000
|
Size: |
8192
|
|
23AAA232000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1906847867.0000023AAA232000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AAA232000
|
Size: |
24576
|
|
4D1000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.00000000004D1000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
4D1000
|
Size: |
20480
|
|
FBA000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000FBA000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
FBA000
|
Size: |
8192
|
|
576B000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1946117715.000000000576B000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
576B000
|
Size: |
200704
|
|
2A8A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002A8A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A8A000
|
Size: |
12288
|
|
7A9E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2270418472.0000000007A9E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A9E000
|
Size: |
12288
|
|
13F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2472526278.00000000013F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
13F0000
|
Size: |
12288
|
|
23AA9B83000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1905977543.0000023AA9B83000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AA9B83000
|
Size: |
20480
|
|
2A58000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002A58000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A58000
|
Size: |
4096
|
|
3387000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003387000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3387000
|
Size: |
57344
|
|
2EB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2478986405.0000000002EB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EB0000
|
Size: |
16384
|
|
5BF0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2265427513.0000000005BF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5BF0000
|
Size: |
20480
|
|
AC2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2235827476.0000000000AC2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
AC2000
|
Size: |
4096
|
|
77A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2519269660.00000000077A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
77A0000
|
Size: |
81920
|
|
23AD8C4D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8C4D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8C4D000
|
Size: |
20480
|
|
368D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000368D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
368D000
|
Size: |
4096
|
|
23AA80AA000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1904927879.0000023AA80AA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AA80AA000
|
Size: |
221184
|
|
23AD8D54000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8D54000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8D54000
|
Size: |
20480
|
|
5821000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2441341269.0000000005821000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5821000
|
Size: |
131072
|
|
33CE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000033CE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33CE000
|
Size: |
4096
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1978371744.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
79F5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2270250883.00000000079F5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
79F5000
|
Size: |
8192
|
|
112D000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.000000000112D000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
112D000
|
Size: |
12288
|
|
14CD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2476597085.00000000014CD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
14CD000
|
Size: |
12288
|
|
27D4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000027D4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
27D4000
|
Size: |
20480
|
|
7B73000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2520106850.0000000007B73000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7B73000
|
Size: |
53248
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1978174326.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
23AA80D1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1635743392.0000023AA80D1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AA80D1000
|
Size: |
69632
|
|
3540000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2010821478.0000000003540000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3540000
|
Size: |
53248
|
|
2AB8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002AB8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AB8000
|
Size: |
118784
|
|
11D6000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2399941983.00000000011D6000.00000004.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
11D6000
|
Size: |
8192
|
|
13CB000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1904471003.00000000013CB000.00000004.00000001.01000000.00000006.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
13CB000
|
Size: |
4096
|
|
3812000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003812000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3812000
|
Size: |
57344
|
|
2A6B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002A6B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A6B000
|
Size: |
4096
|
|
3518000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003518000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3518000
|
Size: |
49152
|
|
33BC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000033BC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33BC000
|
Size: |
45056
|
|
1814153E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.2135756304.000001814153E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1814153E000
|
Size: |
4096
|
|
23AA9AA0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1905977543.0000023AA9AA0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AA9AA0000
|
Size: |
4096
|
|
472F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1635820120.000000000472F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
472F000
|
Size: |
4096
|
|
357A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000357A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
357A000
|
Size: |
4096
|
|
3670000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003670000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3670000
|
Size: |
4096
|
|
BC0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2236327548.0000000000BC0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
BC0000
|
Size: |
65536
|
|
1210000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2471822531.0000000001210000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1210000
|
Size: |
16384
|
|
1814364B000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2403657756.000001814364B000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
1814364B000
|
Size: |
4096
|
|
FEB000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000FEB000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
FEB000
|
Size: |
4096
|
|
34BE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000034BE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
34BE000
|
Size: |
4096
|
|
3423000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003423000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3423000
|
Size: |
40960
|
|
23AD8CE8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8CE8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8CE8000
|
Size: |
16384
|
|
23AD8271000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1933494984.0000023AD8271000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AD8271000
|
Size: |
16384
|
|
344B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000344B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
344B000
|
Size: |
20480
|
|
12B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2474851091.00000000012B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12B0000
|
Size: |
40960
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1946460419.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
23AA9BBC000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1905977543.0000023AA9BBC000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AA9BBC000
|
Size: |
12288
|
|
5BA0000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2012829784.0000000005BA0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5BA0000
|
Size: |
4096
|
|
5000000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2513456963.0000000005000000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5000000
|
Size: |
20480
|
|
79C7000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2270250883.00000000079C7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
79C7000
|
Size: |
4096
|
|
3618000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003618000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3618000
|
Size: |
4096
|
|
114D000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.000000000114D000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
114D000
|
Size: |
20480
|
|
328F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000328F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
328F000
|
Size: |
4096
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1980191151.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
3169000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003169000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3169000
|
Size: |
45056
|
|
10C3000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000012.00000002.2473749241.00000000010C3000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
10C3000
|
Size: |
4096
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1978069946.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
2990000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002990000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2990000
|
Size: |
4096
|
|
37DA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000037DA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
37DA000
|
Size: |
4096
|
|
ADB000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.2236009402.0000000000ADB000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
ADB000
|
Size: |
4096
|
|
2A9F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002A9F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A9F000
|
Size: |
4096
|
|
341F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000341F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
341F000
|
Size: |
4096
|
|
119E000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.000000000119E000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
119E000
|
Size: |
69632
|
|
3224000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2442069410.0000000003224000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3224000
|
Size: |
4096
|
|
FDF000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000FDF000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
FDF000
|
Size: |
32768
|
|
518D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2513707939.000000000518D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
518D000
|
Size: |
12288
|
|
1726000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2478423380.0000000001726000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1726000
|
Size: |
8192
|
|
121C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2400254234.000000000121C000.00000004.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
121C000
|
Size: |
4096
|
|
23AD8D10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8D10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8D10000
|
Size: |
16384
|
|
7B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1635556345.00000000007B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7B0000
|
Size: |
16384
|
|
ED1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000ED1000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
ED1000
|
Size: |
28672
|
|
23AAA390000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1907163068.0000023AAA390000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AAA390000
|
Size: |
4096
|
|
33B5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000033B5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33B5000
|
Size: |
4096
|
|
56AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2481243848.00000000056AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
56AE000
|
Size: |
8192
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1980041218.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
3516000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003516000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3516000
|
Size: |
4096
|
|
5AD0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2265211914.0000000005AD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5AD0000
|
Size: |
12288
|
|
65A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1635376735.000000000065A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
65A000
|
Size: |
200704
|
|
23AAA368000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1907163068.0000023AAA368000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AAA368000
|
Size: |
16384
|
|
F77000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000F77000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
F77000
|
Size: |
4096
|
|
30F6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000030F6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30F6000
|
Size: |
20480
|
|
23AA9F40000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1906604605.0000023AA9F40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AA9F40000
|
Size: |
4096
|
|
2ADE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002ADE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2ADE000
|
Size: |
4096
|
|
5C50000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000014.00000002.2517299554.0000000005C50000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5C50000
|
Size: |
65536
|
|
6B6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1378415377.00000000006B6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B6000
|
Size: |
40960
|
|
23AD8986000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1936096484.0000023AD8986000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8986000
|
Size: |
458752
|
|
3408000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003408000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3408000
|
Size: |
57344
|
|
33CA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000033CA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33CA000
|
Size: |
4096
|
|
3421000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003421000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3421000
|
Size: |
4096
|
|
FC1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000FC1000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
FC1000
|
Size: |
8192
|
|
3514000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003514000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3514000
|
Size: |
4096
|
|
10CD000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000012.00000002.2473815538.00000000010CD000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
10CD000
|
Size: |
4096
|
|
76B0000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2269749494.00000000076B0000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
76B0000
|
Size: |
73728
|
|
355F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000355F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
355F000
|
Size: |
4096
|
|
F54000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000F54000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
F54000
|
Size: |
98304
|
|
352B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000352B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
352B000
|
Size: |
4096
|
|
3EE1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2480500256.0000000003EE1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3EE1000
|
Size: |
24576
|
|
3EE8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2480500256.0000000003EE8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3EE8000
|
Size: |
4096
|
|
2717000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002717000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2717000
|
Size: |
4096
|
|
7AE03FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2400538604.0000007AE03FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7AE03FE000
|
Size: |
8192
|
|
1280000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000012.00000002.2474690654.0000000001280000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1280000
|
Size: |
65536
|
|
23AD8D43000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8D43000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8D43000
|
Size: |
20480
|
|
1209000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000000.2134064020.0000000001209000.00000008.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
1209000
|
Size: |
4096
|
|
501D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2263267076.000000000501D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
501D000
|
Size: |
49152
|
|
3180000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003180000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3180000
|
Size: |
20480
|
|
789D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2519565993.000000000789D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
789D000
|
Size: |
8192
|
|
16C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2475978582.00000000016C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
16C0000
|
Size: |
65536
|
|
3451000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003451000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3451000
|
Size: |
4096
|
|
1640000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2475404934.0000000001640000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1640000
|
Size: |
4096
|
|
30E5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000030E5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30E5000
|
Size: |
20480
|
|
3540000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003540000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3540000
|
Size: |
4096
|
|
18142FF0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2402659704.0000018142FF0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
18142FF0000
|
Size: |
4096
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1979706831.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
181437B8000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2403977009.00000181437B8000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
181437B8000
|
Size: |
4096
|
|
350E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000350E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
350E000
|
Size: |
4096
|
|
181434F3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2403487525.00000181434F3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
181434F3000
|
Size: |
16384
|
|
23AA9B47000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1905977543.0000023AA9B47000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AA9B47000
|
Size: |
8192
|
|
33EB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000033EB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33EB000
|
Size: |
4096
|
|
D85000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000D85000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
D85000
|
Size: |
8192
|
|
18142F57000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2402659704.0000018142F57000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
18142F57000
|
Size: |
4096
|
|
23AA9AB5000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1905977543.0000023AA9AB5000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AA9AB5000
|
Size: |
28672
|
|
3224000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2441740244.0000000003224000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3224000
|
Size: |
4096
|
|
1210000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000000.2134064020.0000000001210000.00000008.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
1210000
|
Size: |
4096
|
|
343C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000343C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
343C000
|
Size: |
57344
|
|
7B00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2520106850.0000000007B00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7B00000
|
Size: |
4096
|
|
2A86000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002A86000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A86000
|
Size: |
4096
|
|
7FF48F100000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1939940364.00007FF48F100000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
7FF48F100000
|
Size: |
360448
|
|
6BF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1378560637.00000000006BF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6BF000
|
Size: |
4096
|
|
337F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000016.00000002.2445212712.000000000337F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
337F000
|
Size: |
4096
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1978274539.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
11C3000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2399896372.00000000011C3000.00000004.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
11C3000
|
Size: |
4096
|
|
527000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.0000000000527000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
527000
|
Size: |
20480
|
|
23AA9AAE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1905977543.0000023AA9AAE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AA9AAE000
|
Size: |
4096
|
|
5661000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1945925717.0000000005661000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5661000
|
Size: |
131072
|
|
5661000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1981935835.0000000005661000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5661000
|
Size: |
4096
|
|
11B6000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2399832463.00000000011B6000.00000004.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
11B6000
|
Size: |
8192
|
|
AA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2235536769.0000000000AA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
AA0000
|
Size: |
12288
|
|
2E4E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2478666445.0000000002E4E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2E4E000
|
Size: |
8192
|
|
39B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1635315263.000000000039B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
39B000
|
Size: |
20480
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1946274400.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
37DF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000037DF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
37DF000
|
Size: |
131072
|
|
5AA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2264847993.0000000005AA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5AA0000
|
Size: |
57344
|
|
2928000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002928000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2928000
|
Size: |
4096
|
|
76D0000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2269880279.00000000076D0000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
76D0000
|
Size: |
4096
|
|
DCAD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2522979885.000000000DCAD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
DCAD000
|
Size: |
12288
|
|
28D3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000028D3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
28D3000
|
Size: |
4096
|
|
2810000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002810000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2810000
|
Size: |
4096
|
|
14F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2476944128.00000000014F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
14F0000
|
Size: |
28672
|
|
10E7000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.00000000010E7000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
10E7000
|
Size: |
36864
|
|
18141700000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2402520673.0000018141700000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
18141700000
|
Size: |
4096
|
|
AA3000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.2235573565.0000000000AA3000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
AA3000
|
Size: |
4096
|
|
2A1D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002A1D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A1D000
|
Size: |
135168
|
|
1094000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000001094000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
1094000
|
Size: |
4096
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1947171729.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
704F6000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2271574294.00000000704F6000.00000002.00000001.01000000.0000000C.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
704F6000
|
Size: |
28672
|
|
F0F000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000F0F000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
F0F000
|
Size: |
24576
|
|
1227000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2400254234.0000000001227000.00000004.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1227000
|
Size: |
16384
|
|
23AD8ADD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1661317128.0000023AD8ADD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8ADD000
|
Size: |
28672
|
|
7E40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2270614271.0000000007E40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7E40000
|
Size: |
12288
|
|
36F8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000036F8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
36F8000
|
Size: |
53248
|
|
5190000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2264146294.0000000005190000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5190000
|
Size: |
65536
|
|
5ADE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2012713435.0000000005ADE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5ADE000
|
Size: |
8192
|
|
16F1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2477447569.00000000016F1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
16F1000
|
Size: |
8192
|
|
410000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225538355.0000000000410000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
410000
|
Size: |
4096
|
|
23AA9BA6000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1905977543.0000023AA9BA6000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AA9BA6000
|
Size: |
8192
|
|
27B9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000027B9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
27B9000
|
Size: |
4096
|
|
18143662000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2403657756.0000018143662000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
18143662000
|
Size: |
24576
|
|
35E4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000035E4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
35E4000
|
Size: |
65536
|
|
27BD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000027BD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
27BD000
|
Size: |
4096
|
|
D61E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2271087119.000000000D61E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
D61E000
|
Size: |
8192
|
|
538000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.0000000000538000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
538000
|
Size: |
20480
|
|
33E0000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2010688952.00000000033E0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
33E0000
|
Size: |
4096
|
|
1230000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2400375526.0000000001230000.00000004.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1230000
|
Size: |
4096
|
|
5150000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2263908273.0000000005150000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5150000
|
Size: |
65536
|
|
2AD8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002AD8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AD8000
|
Size: |
4096
|
|
139E000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1904319033.000000000139E000.00000004.00000001.01000000.00000006.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
139E000
|
Size: |
8192
|
|
A90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2235502203.0000000000A90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
A90000
|
Size: |
8192
|
|
3419000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003419000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3419000
|
Size: |
12288
|
|
23AD7B8E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1931973316.0000023AD7B8E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AD7B8E000
|
Size: |
1527808
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
66D9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2518745503.00000000066D9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
66D9000
|
Size: |
24576
|
|
65A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2233410270.000000000065A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
65A000
|
Size: |
57344
|
|
481000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.0000000000481000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
481000
|
Size: |
20480
|
|
32A8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000032A8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32A8000
|
Size: |
4096
|
|
980000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2235431052.0000000000980000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
980000
|
Size: |
16384
|
|
23AD8C9D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8C9D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8C9D000
|
Size: |
20480
|
|
139B000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1904298448.000000000139B000.00000004.00000001.01000000.00000006.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
139B000
|
Size: |
8192
|
|
23AD8D0A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8D0A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8D0A000
|
Size: |
20480
|
|
23AA9F60000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000002.1906620993.0000023AA9F60000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
23AA9F60000
|
Size: |
4096
|
|
29E5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000029E5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29E5000
|
Size: |
4096
|
|
11B1000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000000.2134064020.00000000011B1000.00000008.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
11B1000
|
Size: |
12288
|
|
18170FF6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2431190852.0000018170FF6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
18170FF6000
|
Size: |
4096
|
|
EB9000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000EB9000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
EB9000
|
Size: |
24576
|
|
3492000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003492000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3492000
|
Size: |
4096
|
|
1436000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2472811392.0000000001436000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1436000
|
Size: |
307200
|
|
3825000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003825000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3825000
|
Size: |
4096
|
|
18171571000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2431242997.0000018171571000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
18171571000
|
Size: |
4096
|
|
2A3F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002A3F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A3F000
|
Size: |
4096
|
|
2B2D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002B2D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B2D000
|
Size: |
12288
|
|
30A6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000030A6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30A6000
|
Size: |
20480
|
|
544000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.0000000000544000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
544000
|
Size: |
20480
|
|
1298000
|
heap
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2474851091.0000000001298000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1298000
|
Size: |
94208
|
|
29F8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000029F8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29F8000
|
Size: |
12288
|
|
47DE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1635857320.00000000047DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
47DE000
|
Size: |
8192
|
|
3332000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003332000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3332000
|
Size: |
143360
|
|
5C27000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2266065957.0000000005C27000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5C27000
|
Size: |
12288
|
|
181414FA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2400743173.00000181414FA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
181414FA000
|
Size: |
327680
|
|
3678000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003678000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3678000
|
Size: |
4096
|
|
5573000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2514924557.0000000005573000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5573000
|
Size: |
8192
|
|
23AD8A45000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1661317128.0000023AD8A45000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8A45000
|
Size: |
24576
|
|
2935000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002935000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2935000
|
Size: |
53248
|
|
2693000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002693000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2693000
|
Size: |
4096
|
|
3640000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003640000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3640000
|
Size: |
4096
|
|
23AA9BB4000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1905977543.0000023AA9BB4000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AA9BB4000
|
Size: |
24576
|
|
2ADA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002ADA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2ADA000
|
Size: |
4096
|
|
2EC0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476442681.0000000002EC0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EC0000
|
Size: |
49152
|
|
5730000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2514997380.0000000005730000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5730000
|
Size: |
65536
|
|
336A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000336A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
336A000
|
Size: |
4096
|
|
34BC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000034BC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
34BC000
|
Size: |
4096
|
|
66B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2518592342.00000000066B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
66B0000
|
Size: |
36864
|
|
64C0000
|
trusted library section
|
page readonly
|
|
|
|
Name: |
00000014.00000002.2517920309.00000000064C0000.00000002.08000000.00040000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page readonly
|
Base address: |
64C0000
|
Size: |
4096
|
|
23AD8C52000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1666315726.0000023AD8C52000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
23AD8C52000
|
Size: |
1060864
|
|
23AAA388000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1907163068.0000023AAA388000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AAA388000
|
Size: |
4096
|
|
27FC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000027FC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
27FC000
|
Size: |
20480
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1378452655.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
20480
|
|
72DE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2269282777.00000000072DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
72DE000
|
Size: |
8192
|
|
311E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000311E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
311E000
|
Size: |
20480
|
|
66EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2518745503.00000000066EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
66EA000
|
Size: |
77824
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
DC3000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000DC3000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
DC3000
|
Size: |
4096
|
|
684000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1378710687.0000000000684000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
684000
|
Size: |
28672
|
|
2F0C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2479136612.0000000002F0C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F0C000
|
Size: |
4096
|
|
37BF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000037BF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
37BF000
|
Size: |
4096
|
|
23AD81F3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1933494984.0000023AD81F3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AD81F3000
|
Size: |
90112
|
|
1207000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000000.2134064020.0000000001207000.00000008.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
1207000
|
Size: |
4096
|
|
115E000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.000000000115E000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
115E000
|
Size: |
12288
|
|
3525000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003525000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3525000
|
Size: |
4096
|
|
5010000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2263267076.0000000005010000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5010000
|
Size: |
49152
|
|
7AE04FD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2400572249.0000007AE04FD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7AE04FD000
|
Size: |
12288
|
|
1131000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000001131000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
1131000
|
Size: |
28672
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1946294134.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
23AD8C97000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8C97000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8C97000
|
Size: |
20480
|
|
D41000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000D41000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
D41000
|
Size: |
24576
|
|
36EF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000036EF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
36EF000
|
Size: |
4096
|
|
13C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2472373410.00000000013C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13C0000
|
Size: |
4096
|
|
2A02000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002A02000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A02000
|
Size: |
4096
|
|
7A63000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2520030347.0000000007A63000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A63000
|
Size: |
4096
|
|
10B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2473602888.00000000010B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
10B0000
|
Size: |
8192
|
|
4F9000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.00000000004F9000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
4F9000
|
Size: |
20480
|
|
3712000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003712000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3712000
|
Size: |
40960
|
|
23AD8800000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1936096484.0000023AD8800000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8800000
|
Size: |
1462272
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
23AD8CB4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8CB4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8CB4000
|
Size: |
20480
|
|
830E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2521762209.000000000830E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
830E000
|
Size: |
8192
|
|
4F10000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2262971533.0000000004F10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4F10000
|
Size: |
204800
|
|
357C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000357C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
357C000
|
Size: |
4096
|
|
23AD8CBA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8CBA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8CBA000
|
Size: |
40960
|
|
31BF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000031BF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31BF000
|
Size: |
20480
|
|
35CE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000035CE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
35CE000
|
Size: |
61440
|
|
136F000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1904160531.000000000136F000.00000004.00000001.01000000.00000006.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
136F000
|
Size: |
4096
|
|
5BDE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2265359301.0000000005BDE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5BDE000
|
Size: |
8192
|
|
54F6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2513754895.00000000054F6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
54F6000
|
Size: |
16384
|
|
2B70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002B70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B70000
|
Size: |
4096
|
|
13EC000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1904676550.00000000013EC000.00000004.00000001.01000000.00000006.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
13EC000
|
Size: |
8192
|
|
2932000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002932000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2932000
|
Size: |
4096
|
|
23AD8E41000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1666315726.0000023AD8E41000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
23AD8E41000
|
Size: |
98304
|
|
351F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2010722386.000000000351F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
351F000
|
Size: |
4096
|
|
11FD000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2400134028.00000000011FD000.00000004.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
11FD000
|
Size: |
4096
|
|
33B9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000033B9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33B9000
|
Size: |
4096
|
|
37AA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000037AA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
37AA000
|
Size: |
4096
|
|
35C1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000035C1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
105C000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.000000000105C000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
105C000
|
Size: |
16384
|
|
715E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2269204303.000000000715E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
715E000
|
Size: |
8192
|
|
23AD8DDF000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1666315726.0000023AD8DDF000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
23AD8DDF000
|
Size: |
20480
|
|
23AD8B1D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1661317128.0000023AD8B1D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8B1D000
|
Size: |
16384
|
|
D58000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000D58000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
D58000
|
Size: |
8192
|
|
795000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2235319092.0000000000795000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
795000
|
Size: |
12288
|
|
13DC000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1904487859.00000000013DC000.00000004.00000001.01000000.00000006.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
13DC000
|
Size: |
4096
|
|
7EDE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2521169451.0000000007EDE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7EDE000
|
Size: |
8192
|
|
57CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2515290028.00000000057CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
57CE000
|
Size: |
8192
|
|
292A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.000000000292A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
292A000
|
Size: |
4096
|
|
33E9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000033E9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33E9000
|
Size: |
4096
|
|
26CB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000026CB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
26CB000
|
Size: |
16384
|
|
1814153E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.2136191077.000001814153E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1814153E000
|
Size: |
4096
|
|
3406000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003406000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3406000
|
Size: |
4096
|
|
3563000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003563000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3563000
|
Size: |
4096
|
|
1814153E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.2136113353.000001814153E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1814153E000
|
Size: |
4096
|
|
18172203000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2431596296.0000018172203000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
18172203000
|
Size: |
4096
|
|
354E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000354E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
354E000
|
Size: |
57344
|
|
50EC000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2263707781.00000000050EC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
50EC000
|
Size: |
69632
|
|
289B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.000000000289B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
289B000
|
Size: |
12288
|
|
23AD825A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1933494984.0000023AD825A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AD825A000
|
Size: |
90112
|
|
6C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2233410270.00000000006C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6C1000
|
Size: |
16384
|
|
23AD8A7A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1661317128.0000023AD8A7A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8A7A000
|
Size: |
24576
|
|
2895000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002895000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2895000
|
Size: |
4096
|
|
1710000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2478211465.0000000001710000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1710000
|
Size: |
36864
|
|
580D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2515331098.000000000580D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
580D000
|
Size: |
12288
|
|
4F4000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.00000000004F4000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
4F4000
|
Size: |
16384
|
|
26D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000026D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
26D0000
|
Size: |
20480
|
|
F03000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000F03000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
F03000
|
Size: |
24576
|
|
380A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000380A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
380A000
|
Size: |
4096
|
|
1220000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2400254234.0000000001220000.00000004.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1220000
|
Size: |
4096
|
|
23AD8CDC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8CDC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8CDC000
|
Size: |
20480
|
|
36DA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000036DA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
36DA000
|
Size: |
57344
|
|
54EE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2513754895.00000000054EE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
54EE000
|
Size: |
4096
|
|
13EB000
|
unkown
|
page write copy
|
|
|
|
Name: |
0000000C.00000000.1632501936.00000000013EB000.00000008.00000001.01000000.00000006.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
13EB000
|
Size: |
28672
|
|
35F7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000035F7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
35F7000
|
Size: |
4096
|
|
4A50000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.2262331284.0000000004A50000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
4A50000
|
Size: |
65536
|
|
337D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000337D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
337D000
|
Size: |
4096
|
|
5661000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1981386954.0000000005661000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5661000
|
Size: |
4096
|
|
704FD000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2271655712.00000000704FD000.00000004.00000001.01000000.0000000C.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
704FD000
|
Size: |
8192
|
|
36E9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000036E9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
36E9000
|
Size: |
4096
|
|
23AD82A4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1933494984.0000023AD82A4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AD82A4000
|
Size: |
45056
|
|
2697000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002697000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2697000
|
Size: |
49152
|
|
2439000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2236598888.0000000002439000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2439000
|
Size: |
28672
|
|
7600000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2269473720.0000000007600000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7600000
|
Size: |
65536
|
|
274B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.000000000274B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
274B000
|
Size: |
4096
|
|
181414A9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2400743173.00000181414A9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
181414A9000
|
Size: |
319488
|
|
1100000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2471701651.0000000001100000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1100000
|
Size: |
4096
|
|
5820000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2515378989.0000000005820000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5820000
|
Size: |
4096
|
|
3565000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003565000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3565000
|
Size: |
73728
|
|
23AAA197000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1906686563.0000023AAA197000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AAA197000
|
Size: |
4096
|
|
3490000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003490000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3490000
|
Size: |
4096
|
|
27FA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000027FA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
27FA000
|
Size: |
4096
|
|
29CC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000029CC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29CC000
|
Size: |
4096
|
|
11F2000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000000.2134064020.00000000011F2000.00000008.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
11F2000
|
Size: |
8192
|
|
2B46000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002B46000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B46000
|
Size: |
4096
|
|
3614000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003614000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3614000
|
Size: |
4096
|
|
3224000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2445022089.0000000003224000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3224000
|
Size: |
4096
|
|
13E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2472449093.00000000013E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
13E0000
|
Size: |
12288
|
|
1510000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2477064204.0000000001510000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1510000
|
Size: |
36864
|
|
69A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1379128153.000000000069A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
69A000
|
Size: |
114688
|
|
3651000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003651000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3651000
|
Size: |
4096
|
|
27E1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000027E1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
27E1000
|
Size: |
53248
|
|
2964000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002964000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2964000
|
Size: |
4096
|
|
12C5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2474851091.00000000012C5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12C5000
|
Size: |
4096
|
|
33E1000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1946005304.00000000033E1000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
33E1000
|
Size: |
143360
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1946715855.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1947066257.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
1054000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000001054000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
1054000
|
Size: |
16384
|
|
2777000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002777000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2777000
|
Size: |
4096
|
|
1202000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000000.2134064020.0000000001202000.00000008.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
1202000
|
Size: |
4096
|
|
35E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000035E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
35E0000
|
Size: |
4096
|
|
2A00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002A00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A00000
|
Size: |
4096
|
|
382F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000382F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
382F000
|
Size: |
16384
|
|
23AD8CA9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8CA9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8CA9000
|
Size: |
16384
|
|
23AA9B40000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1905977543.0000023AA9B40000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AA9B40000
|
Size: |
4096
|
|
2930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2930000
|
Size: |
4096
|
|
2ED9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476547278.0000000002ED9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2ED9000
|
Size: |
28672
|
|
45A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1635705044.00000000045A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
45A0000
|
Size: |
4096
|
|
F6E000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000F6E000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
F6E000
|
Size: |
4096
|
|
2B10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002B10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B10000
|
Size: |
4096
|
|
7A2E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2519993924.0000000007A2E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A2E000
|
Size: |
8192
|
|
23AD8DEE000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1939876531.0000023AD8DEE000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
23AD8DEE000
|
Size: |
4096
|
|
13C7000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1904455003.00000000013C7000.00000004.00000001.01000000.00000006.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
13C7000
|
Size: |
4096
|
|
66D3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2518745503.00000000066D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
66D3000
|
Size: |
12288
|
|
5B9E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2012809905.0000000005B9E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5B9E000
|
Size: |
8192
|
|
34A7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000034A7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
34A7000
|
Size: |
4096
|
|
EF7DBFD000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1904902465.000000EF7DBFD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
EF7DBFD000
|
Size: |
12288
|
|
181417A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2402566501.00000181417A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
181417A0000
|
Size: |
16384
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1979855747.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
5B8F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2481618493.0000000005B8F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5B8F000
|
Size: |
4096
|
|
27C6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000027C6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
27C6000
|
Size: |
53248
|
|
168E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2475464471.000000000168E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
168E000
|
Size: |
8192
|
|
6BB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1378986083.00000000006BB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6BB000
|
Size: |
24576
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1978215206.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
10CD000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.00000000010CD000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
10CD000
|
Size: |
53248
|
|
18172076000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000003.2164223092.0000018172076000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
18172076000
|
Size: |
4096
|
|
35C5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000035C5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
35C5000
|
Size: |
4096
|
|
694000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1379020644.0000000000694000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
694000
|
Size: |
159744
|
|
495E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1635993436.000000000495E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
495E000
|
Size: |
8192
|
|
23AAA8E0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1907486481.0000023AAA8E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AAA8E0000
|
Size: |
4096
|
|
1814378C000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2403977009.000001814378C000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
1814378C000
|
Size: |
4096
|
|
3477000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003477000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3477000
|
Size: |
65536
|
|
23AD8D5C000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1666315726.0000023AD8D5C000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
23AD8D5C000
|
Size: |
65536
|
|
23AD820A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1933494984.0000023AD820A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AD820A000
|
Size: |
65536
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1980572847.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
8192
|
|
31C5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000031C5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31C5000
|
Size: |
20480
|
|
2B44000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002B44000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B44000
|
Size: |
4096
|
|
23AD8D32000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8D32000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8D32000
|
Size: |
20480
|
|
49E000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.000000000049E000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
49E000
|
Size: |
20480
|
|
18141690000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2402494454.0000018141690000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
18141690000
|
Size: |
4096
|
|
3197000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003197000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3197000
|
Size: |
20480
|
|
6460000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2517631107.0000000006460000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6460000
|
Size: |
65536
|
|
18143653000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2403657756.0000018143653000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
18143653000
|
Size: |
45056
|
|
275E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.000000000275E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
275E000
|
Size: |
4096
|
|
32C3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000032C3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32C3000
|
Size: |
4096
|
|
11AF000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2399784903.00000000011AF000.00000004.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
11AF000
|
Size: |
4096
|
|
23AA9B73000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1905977543.0000023AA9B73000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AA9B73000
|
Size: |
4096
|
|
357E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000357E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
357E000
|
Size: |
4096
|
|
4D0000
|
remote allocation
|
page execute and read and write
|
|
|
|
Name: |
00000012.00000002.2471183329.00000000004D0000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
4D0000
|
Size: |
4096
|
|
37C1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000037C1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
37C1000
|
Size: |
4096
|
|
834E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2521804308.000000000834E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
834E000
|
Size: |
8192
|
|
731E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2269324797.000000000731E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
731E000
|
Size: |
8192
|
|
23AD8CF9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8CF9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8CF9000
|
Size: |
40960
|
|
638000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2233410270.0000000000638000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
638000
|
Size: |
135168
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1978485254.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
280A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.000000000280A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
280A000
|
Size: |
4096
|
|
36AC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000036AC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
36AC000
|
Size: |
167936
|
|
AB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2235670604.0000000000AB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
AB0000
|
Size: |
45056
|
|
2F39000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2479136612.0000000002F39000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F39000
|
Size: |
8192
|
|
693000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1635376735.0000000000693000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
693000
|
Size: |
28672
|
|
DB6D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2522817226.000000000DB6D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
DB6D000
|
Size: |
12288
|
|
26E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000026E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
26E0000
|
Size: |
4096
|
|
7F1E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2521206373.0000000007F1E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7F1E000
|
Size: |
8192
|
|
2B49000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002B49000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B49000
|
Size: |
147456
|
|
5921000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2441567792.0000000005921000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5921000
|
Size: |
192512
|
|
67A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1379071115.000000000067A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
67A000
|
Size: |
69632
|
|
790000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2235319092.0000000000790000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
790000
|
Size: |
16384
|
|
459000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.0000000000459000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
459000
|
Size: |
20480
|
|
26C1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000026C1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
26C1000
|
Size: |
4096
|
|
D4C000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000D4C000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
D4C000
|
Size: |
4096
|
|
23AA9B64000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1905977543.0000023AA9B64000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AA9B64000
|
Size: |
8192
|
|
10A8000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.00000000010A8000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
10A8000
|
Size: |
4096
|
|
1814303B000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2402659704.000001814303B000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
1814303B000
|
Size: |
4096
|
|
1400000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2472811392.0000000001400000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1400000
|
Size: |
24576
|
|
18143D55000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.2160646162.0000018143D55000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
18143D55000
|
Size: |
4096
|
|
2A50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002A50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A50000
|
Size: |
4096
|
|
276D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.000000000276D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
276D000
|
Size: |
36864
|
|
18143791000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2403977009.0000018143791000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
18143791000
|
Size: |
4096
|
|
2F48000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2479136612.0000000002F48000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F48000
|
Size: |
73728
|
|
550E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000016.00000002.2447514599.000000000550E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
550E000
|
Size: |
24576
|
|
5C17000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2265629292.0000000005C17000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5C17000
|
Size: |
12288
|
|
26DE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000026DE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
26DE000
|
Size: |
4096
|
|
F8E000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000F8E000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
F8E000
|
Size: |
122880
|
|
23AAA2D0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1906847867.0000023AAA2D0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AAA2D0000
|
Size: |
4096
|
|
505000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.0000000000505000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
505000
|
Size: |
20480
|
|
3791000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003791000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3791000
|
Size: |
57344
|
|
764D000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2269597132.000000000764D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
764D000
|
Size: |
12288
|
|
23AD89F7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1936096484.0000023AD89F7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD89F7000
|
Size: |
4096
|
|
470000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.0000000000470000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
470000
|
Size: |
20480
|
|
4CC000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.00000000004CC000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
4CC000
|
Size: |
16384
|
|
10E7000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000012.00000002.2474038420.00000000010E7000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
10E7000
|
Size: |
4096
|
|
5661000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1983726810.0000000005661000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5661000
|
Size: |
4096
|
|
EC2000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000EC2000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
EC2000
|
Size: |
36864
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1979590154.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
F37000
|
stack
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2471333603.0000000000F37000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
F37000
|
Size: |
36864
|
|
37A2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000037A2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
37A2000
|
Size: |
12288
|
|
35E2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000035E2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
35E2000
|
Size: |
4096
|
|
2985000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002985000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2985000
|
Size: |
40960
|
|
2B2B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002B2B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B2B000
|
Size: |
4096
|
|
10F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2474138370.00000000010F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10F0000
|
Size: |
16384
|
|
23AAA550000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1907430741.0000023AAA550000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AAA550000
|
Size: |
4096
|
|
69E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1378604262.000000000069E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
69E000
|
Size: |
36864
|
|
11FF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2474266321.00000000011FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
11FF000
|
Size: |
4096
|
|
2ED0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2479069958.0000000002ED0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2ED0000
|
Size: |
4096
|
|
6AC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1635376735.00000000006AC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6AC000
|
Size: |
8192
|
|
10C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2473685645.00000000010C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
10C0000
|
Size: |
4096
|
|
3643000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003643000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3643000
|
Size: |
53248
|
|
E04000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000E04000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
E04000
|
Size: |
184320
|
|
18143014000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2402659704.0000018143014000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
18143014000
|
Size: |
8192
|
|
32C9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000032C9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32C9000
|
Size: |
4096
|
|
F89000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000F89000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
F89000
|
Size: |
16384
|
|
2992000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002992000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2992000
|
Size: |
4096
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1978406286.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
23AA9B55000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1905977543.0000023AA9B55000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AA9B55000
|
Size: |
8192
|
|
27C1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000027C1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
27C1000
|
Size: |
4096
|
|
689000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1379247999.0000000000689000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
689000
|
Size: |
8192
|
|
23AD8A63000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1661317128.0000023AD8A63000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8A63000
|
Size: |
24576
|
|
23AD8AA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1661317128.0000023AD8AA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8AA0000
|
Size: |
24576
|
|
352F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000352F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
352F000
|
Size: |
4096
|
|
23AD8CAE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8CAE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8CAE000
|
Size: |
20480
|
|
328D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000328D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
328D000
|
Size: |
4096
|
|
18143D50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2404302955.0000018143D50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
18143D50000
|
Size: |
16384
|
|
FCB000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000FCB000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
FCB000
|
Size: |
4096
|
|
3404000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003404000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3404000
|
Size: |
4096
|
|
35FD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000035FD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
35FD000
|
Size: |
12288
|
|
2AF5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002AF5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AF5000
|
Size: |
4096
|
|
2B40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002B40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B40000
|
Size: |
4096
|
|
23AA82F5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1905916211.0000023AA82F5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AA82F5000
|
Size: |
28672
|
|
684000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1379183199.0000000000684000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
684000
|
Size: |
8192
|
|
5C54000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2266291334.0000000005C54000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5C54000
|
Size: |
8192
|
|
5663000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1983893395.0000000005663000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5663000
|
Size: |
4096
|
|
3152000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003152000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3152000
|
Size: |
20480
|
|
12F8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2474851091.00000000012F8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12F8000
|
Size: |
8192
|
|
23AD8D21000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8D21000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8D21000
|
Size: |
20480
|
|
EE7000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000EE7000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
EE7000
|
Size: |
45056
|
|
1817225E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2431596296.000001817225E000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1817225E000
|
Size: |
4096
|
|
2F6C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000016.00000002.2445094383.0000000002F6C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2F6C000
|
Size: |
16384
|
|
29B3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000029B3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29B3000
|
Size: |
4096
|
|
361A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000361A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
361A000
|
Size: |
143360
|
|
18142FF7000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2402659704.0000018142FF7000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
18142FF7000
|
Size: |
8192
|
|
10D3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2473852944.00000000010D3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
10D3000
|
Size: |
40960
|
|
2735000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002735000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2735000
|
Size: |
12288
|
|
11D0000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000000.2134064020.00000000011D0000.00000008.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
11D0000
|
Size: |
8192
|
|
400000
|
remote allocation
|
page execute and read and write
|
|
|
|
Name: |
00000012.00000002.2471183329.0000000000400000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
400000
|
Size: |
4096
|
|
2EE1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2479136612.0000000002EE1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EE1000
|
Size: |
172032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
DE0000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000DE0000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
DE0000
|
Size: |
12288
|
|
35F9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000035F9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
35F9000
|
Size: |
4096
|
|
3527000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003527000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3527000
|
Size: |
4096
|
|
6A7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1379260231.00000000006A7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6A7000
|
Size: |
24576
|
|
2812000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002812000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2812000
|
Size: |
49152
|
|
13F3000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000014.00000002.2472628419.00000000013F3000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
13F3000
|
Size: |
4096
|
|
23AAA35C000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1907163068.0000023AAA35C000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AAA35C000
|
Size: |
4096
|
|
1814305D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2402659704.000001814305D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
1814305D000
|
Size: |
20480
|
|
D89000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000D89000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
D89000
|
Size: |
4096
|
|
59A0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2264506976.00000000059A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
59A0000
|
Size: |
4096
|
|
161A000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000014.00000002.2475108714.000000000161A000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
161A000
|
Size: |
8192
|
|
3170000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2009357300.0000000003170000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3170000
|
Size: |
16384
|
|
28CD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000028CD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
28CD000
|
Size: |
20480
|
|
268D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.000000000268D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
268D000
|
Size: |
4096
|
|
3808000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003808000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3808000
|
Size: |
4096
|
|
78F7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2519802692.00000000078F7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
78F7000
|
Size: |
12288
|
|
745E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2269392541.000000000745E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
745E000
|
Size: |
8192
|
|
5830000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000014.00000002.2515408472.0000000005830000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
5830000
|
Size: |
8192
|
|
3694000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003694000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3694000
|
Size: |
53248
|
|
18143056000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2402659704.0000018143056000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
18143056000
|
Size: |
8192
|
|
12FE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2474851091.00000000012FE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12FE000
|
Size: |
8192
|
|
11D7000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000000.2134064020.00000000011D7000.00000008.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
11D7000
|
Size: |
4096
|
|
26C5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000026C5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
26C5000
|
Size: |
4096
|
|
33B3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000033B3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33B3000
|
Size: |
4096
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1978151100.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
23AA82A0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1905821261.0000023AA82A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AA82A0000
|
Size: |
4096
|
|
23AD8D6B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8D6B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8D6B000
|
Size: |
20480
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1946398940.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
23AD8DD4000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1666315726.0000023AD8DD4000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
23AD8DD4000
|
Size: |
40960
|
|
23AD8A4C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1661317128.0000023AD8A4C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8A4C000
|
Size: |
24576
|
|
16E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2477447569.00000000016E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
16E0000
|
Size: |
8192
|
|
4A11000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2261082402.0000000004A11000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4A11000
|
Size: |
16384
|
|
E32000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000E32000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
E32000
|
Size: |
65536
|
|
23AD8293000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1933494984.0000023AD8293000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AD8293000
|
Size: |
20480
|
|
669000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2233410270.0000000000669000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
669000
|
Size: |
339968
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1946316381.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
A30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1635591313.0000000000A30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A30000
|
Size: |
16384
|
|
54F1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2513754895.00000000054F1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
54F1000
|
Size: |
16384
|
|
2760000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002760000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2760000
|
Size: |
4096
|
|
3821000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003821000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3821000
|
Size: |
4096
|
|
D7A000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000D7A000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
D7A000
|
Size: |
4096
|
|
26A8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000026A8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
26A8000
|
Size: |
20480
|
|
70EE000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2268875075.00000000070EE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
70EE000
|
Size: |
24576
|
|
27F5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000027F5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
27F5000
|
Size: |
4096
|
|
2802000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002802000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2802000
|
Size: |
20480
|
|
26C9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000026C9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
26C9000
|
Size: |
4096
|
|
23AD8C6A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8C6A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8C6A000
|
Size: |
16384
|
|
151A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2477064204.000000000151A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
151A000
|
Size: |
24576
|
|
36F3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000036F3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
36F3000
|
Size: |
4096
|
|
10AA000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.00000000010AA000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
10AA000
|
Size: |
8192
|
|
28CB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000028CB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
28CB000
|
Size: |
4096
|
|
4084000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2501089519.0000000004084000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4084000
|
Size: |
4096
|
|
29EB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000029EB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29EB000
|
Size: |
49152
|
|
3580000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003580000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3580000
|
Size: |
151552
|
|
23AD8299000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1933494984.0000023AD8299000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AD8299000
|
Size: |
16384
|
|
7D60000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000014.00000002.2520919561.0000000007D60000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7D60000
|
Size: |
65536
|
|
1408000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2472811392.0000000001408000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1408000
|
Size: |
131072
|
|
32B2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000032B2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32B2000
|
Size: |
49152
|
|
2FFB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000002FFB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2FFB000
|
Size: |
24576
|
|
23AAA249000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1906847867.0000023AAA249000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AAA249000
|
Size: |
4096
|
|
40D9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2501089519.00000000040D9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
40D9000
|
Size: |
4096
|
|
23AA80D9000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1636144021.0000023AA80D9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AA80D9000
|
Size: |
81920
|
|
FB3000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000FB3000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
FB3000
|
Size: |
4096
|
|
3772000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003772000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3772000
|
Size: |
4096
|
|
28FC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000028FC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
28FC000
|
Size: |
135168
|
|
23AAA239000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1906847867.0000023AAA239000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AAA239000
|
Size: |
12288
|
|
23AA81A0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1905668495.0000023AA81A0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AA81A0000
|
Size: |
4096
|
|
57D000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.000000000057D000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
57D000
|
Size: |
20480
|
|
FD8000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000FD8000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
FD8000
|
Size: |
16384
|
|
6550000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2517994216.0000000006550000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6550000
|
Size: |
4096
|
|
5530000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2514628963.0000000005530000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5530000
|
Size: |
65536
|
|
3224000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2441840213.0000000003224000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3224000
|
Size: |
4096
|
|
181437A6000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2403977009.00000181437A6000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
181437A6000
|
Size: |
4096
|
|
23AAA36D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1907163068.0000023AAA36D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AAA36D000
|
Size: |
12288
|
|
18142F50000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2402659704.0000018142F50000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
18142F50000
|
Size: |
4096
|
|
1220000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2474528951.0000000001220000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1220000
|
Size: |
4096
|
|
4EDA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.2446774056.0000000004EDA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4EDA000
|
Size: |
512000
|
|
23AD8800000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1661317128.0000023AD8800000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8800000
|
Size: |
2093056
|
|
582E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2481422958.000000000582E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
582E000
|
Size: |
8192
|
|
FD1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000FD1000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
FD1000
|
Size: |
4096
|
|
1275000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2472018997.0000000001275000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1275000
|
Size: |
12288
|
|
268F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.000000000268F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
268F000
|
Size: |
4096
|
|
EF7D7FE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1904800846.000000EF7D7FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
EF7D7FE000
|
Size: |
8192
|
|
23AAA117000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1906686563.0000023AAA117000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AAA117000
|
Size: |
4096
|
|
2F41000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2479136612.0000000002F41000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F41000
|
Size: |
12288
|
|
ACA000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.2235885392.0000000000ACA000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
ACA000
|
Size: |
8192
|
|
30BD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000030BD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30BD000
|
Size: |
20480
|
|
28AE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000028AE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
28AE000
|
Size: |
4096
|
|
5B40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2516728080.0000000005B40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5B40000
|
Size: |
192512
|
|
1396000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1904279285.0000000001396000.00000004.00000001.01000000.00000006.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1396000
|
Size: |
8192
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1946486018.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
18145D0F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2404750737.0000018145D0F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
18145D0F000
|
Size: |
4096
|
|
BD8000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2236413133.0000000000BD8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BD8000
|
Size: |
28672
|
|
1207000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2400195232.0000000001207000.00000004.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1207000
|
Size: |
4096
|
|
3542000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003542000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3542000
|
Size: |
12288
|
|
29B6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000029B6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29B6000
|
Size: |
61440
|
|
69B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1378542236.000000000069B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
69B000
|
Size: |
49152
|
|
3601000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003601000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3601000
|
Size: |
57344
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1946869630.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
23AD8C5E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8C5E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8C5E000
|
Size: |
20480
|
|
333E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2010338707.000000000333E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
333E000
|
Size: |
32768
|
|
23AD7920000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1931659483.0000023AD7920000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
23AD7920000
|
Size: |
8192
|
|
23AAA361000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1907163068.0000023AAA361000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AAA361000
|
Size: |
4096
|
|
32C1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000032C1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32C1000
|
Size: |
4096
|
|
3531000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003531000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3531000
|
Size: |
4096
|
|
3729000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003729000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3729000
|
Size: |
4096
|
|
5661000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1982241617.0000000005661000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5661000
|
Size: |
4096
|
|
D4A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2270818336.000000000D4A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
D4A0000
|
Size: |
36864
|
|
7AB0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2270418472.0000000007AB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7AB0000
|
Size: |
8192
|
|
11AF000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000000.2134064020.00000000011AF000.00000008.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
11AF000
|
Size: |
4096
|
|
691000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1379000044.0000000000691000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
691000
|
Size: |
172032
|
|
5370000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000016.00000002.2447514599.0000000005370000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
5370000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
23AD8C42000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8C42000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8C42000
|
Size: |
16384
|
|
3800000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003800000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3800000
|
Size: |
28672
|
|
4A4000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.00000000004A4000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
4A4000
|
Size: |
16384
|
|
FCD000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000FCD000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
FCD000
|
Size: |
8192
|
|
2A19000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002A19000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A19000
|
Size: |
4096
|
|
23AA9AC7000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1905977543.0000023AA9AC7000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AA9AC7000
|
Size: |
8192
|
|
335E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000335E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
335E000
|
Size: |
4096
|
|
489B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1635919409.000000000489B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
489B000
|
Size: |
20480
|
|
23AD8AB7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1661317128.0000023AD8AB7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8AB7000
|
Size: |
24576
|
|
7ADFFC7000
|
stack
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2400436836.0000007ADFFC7000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7ADFFC7000
|
Size: |
36864
|
|
50A8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2011552525.00000000050A8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
50A8000
|
Size: |
2121728
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
271A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.000000000271A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
271A000
|
Size: |
53248
|
|
510000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.0000000000510000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
510000
|
Size: |
20480
|
|
13BD000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1904420064.00000000013BD000.00000004.00000001.01000000.00000006.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
13BD000
|
Size: |
4096
|
|
3417000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003417000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3417000
|
Size: |
4096
|
|
29C8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000029C8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29C8000
|
Size: |
4096
|
|
2A79000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002A79000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A79000
|
Size: |
40960
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1978389592.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
121A000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000000.2134064020.000000000121A000.00000008.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
121A000
|
Size: |
8192
|
|
36F1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000036F1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
36F1000
|
Size: |
4096
|
|
61D000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2233336092.000000000061D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
61D000
|
Size: |
12288
|
|
2EE0000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000014.00000002.2476702573.0000000002EE0000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
2EE0000
|
Size: |
4096
|
|
26F7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000026F7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
26F7000
|
Size: |
4096
|
|
295E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.000000000295E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
295E000
|
Size: |
12288
|
|
11E3000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2400027243.00000000011E3000.00000004.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
11E3000
|
Size: |
4096
|
|
5740000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000014.00000002.2515143559.0000000005740000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5740000
|
Size: |
65536
|
|
23AA9FD0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1906640820.0000023AA9FD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AA9FD0000
|
Size: |
8192
|
|
23AD8C64000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8C64000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8C64000
|
Size: |
20480
|
|
37BD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000037BD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
37BD000
|
Size: |
4096
|
|
6AF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1378483174.00000000006AF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6AF000
|
Size: |
8192
|
|
23AD8A82000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1661317128.0000023AD8A82000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8A82000
|
Size: |
24576
|
|
1061000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000001061000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
1061000
|
Size: |
4096
|
|
14AE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2472811392.00000000014AE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14AE000
|
Size: |
8192
|
|
126E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2474582568.000000000126E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
126E000
|
Size: |
8192
|
|
3224000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.2444843166.0000000003224000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3224000
|
Size: |
4096
|
|
37C5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000037C5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
37C5000
|
Size: |
8192
|
|
13E2000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1904487859.00000000013E2000.00000004.00000001.01000000.00000006.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
13E2000
|
Size: |
4096
|
|
4A30000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2262026772.0000000004A30000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4A30000
|
Size: |
65536
|
|
6595000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2518394314.0000000006595000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6595000
|
Size: |
40960
|
|
181437A3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2403977009.00000181437A3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
181437A3000
|
Size: |
4096
|
|
36D6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000036D6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
36D6000
|
Size: |
4096
|
|
1429000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2472811392.0000000001429000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1429000
|
Size: |
49152
|
|
FED000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000FED000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
FED000
|
Size: |
57344
|
|
505F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2011552525.000000000505F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
505F000
|
Size: |
290816
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
53E000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.000000000053E000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
53E000
|
Size: |
20480
|
|
11EB000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000000.2134064020.00000000011EB000.00000008.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
11EB000
|
Size: |
4096
|
|
23AD821B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1933494984.0000023AD821B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AD821B000
|
Size: |
90112
|
|
3689000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003689000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3689000
|
Size: |
12288
|
|
3368000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003368000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3368000
|
Size: |
4096
|
|
373C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000373C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
373C000
|
Size: |
20480
|
|
7993000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2519965439.0000000007993000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7993000
|
Size: |
4096
|
|
B80000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.2236151021.0000000000B80000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
B80000
|
Size: |
65536
|
|
34F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000034F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
34F0000
|
Size: |
118784
|
|
697000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1378681471.0000000000697000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
697000
|
Size: |
12288
|
|
5AC0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.2265096755.0000000005AC0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5AC0000
|
Size: |
65536
|
|
2FAD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000016.00000002.2445121036.0000000002FAD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2FAD000
|
Size: |
12288
|
|
5C40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2517139270.0000000005C40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5C40000
|
Size: |
65536
|
|
816F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2521359435.000000000816F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
816F000
|
Size: |
4096
|
|
2FEE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476742301.0000000002FEE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2FEE000
|
Size: |
8192
|
|
30D4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000030D4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30D4000
|
Size: |
20480
|
|
23AD8AFC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1661317128.0000023AD8AFC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8AFC000
|
Size: |
24576
|
|
23AD8AE5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1661317128.0000023AD8AE5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8AE5000
|
Size: |
24576
|
|
7814000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2519441135.0000000007814000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7814000
|
Size: |
8192
|
|
30F1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000030F1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
16384
|
|
23AD8B31000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1661317128.0000023AD8B31000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8B31000
|
Size: |
24576
|
|
33D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000033D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33D0000
|
Size: |
81920
|
|
11DE000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000000.2134064020.00000000011DE000.00000008.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
11DE000
|
Size: |
12288
|
|
18170EFC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.2156997755.0000018170EFC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
18170EFC000
|
Size: |
4096
|
|
34C2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000034C2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
34C2000
|
Size: |
12288
|
|
23AD8C6F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8C6F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8C6F000
|
Size: |
20480
|
|
66BE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2518715397.00000000066BE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
66BE000
|
Size: |
4096
|
|
7DDE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2521086082.0000000007DDE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7DDE000
|
Size: |
8192
|
|
5AAF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2264847993.0000000005AAF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5AAF000
|
Size: |
4096
|
|
2CFC000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2007815424.0000000002CFC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2CFC000
|
Size: |
16384
|
|
1216000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000000.2134064020.0000000001216000.00000008.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
1216000
|
Size: |
4096
|
|
23AD7D06000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1931973316.0000023AD7D06000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AD7D06000
|
Size: |
491520
|
|
2460000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2236881198.0000000002460000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2460000
|
Size: |
36864
|
|
370E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000370E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
370E000
|
Size: |
4096
|
|
2750000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002750000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2750000
|
Size: |
45056
|
|
13A3000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1904342053.00000000013A3000.00000004.00000001.01000000.00000006.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
13A3000
|
Size: |
4096
|
|
785D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2270063486.000000000785D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
785D000
|
Size: |
20480
|
|
23AD8D4F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8D4F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8D4F000
|
Size: |
16384
|
|
23AD8D1B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8D1B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8D1B000
|
Size: |
20480
|
|
23AD82CC000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1933494984.0000023AD82CC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AD82CC000
|
Size: |
20480
|
|
380C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000380C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
380C000
|
Size: |
4096
|
|
4C0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.00000000004C0000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
4C0000
|
Size: |
20480
|
|
2B29000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002B29000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B29000
|
Size: |
4096
|
|
E5A000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000E5A000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
E5A000
|
Size: |
20480
|
|
3453000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003453000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3453000
|
Size: |
143360
|
|
B90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2236241072.0000000000B90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
B90000
|
Size: |
36864
|
|
23AD8E0D000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1666315726.0000023AD8E0D000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
23AD8E0D000
|
Size: |
20480
|
|
7C2D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2520560361.0000000007C2D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7C2D000
|
Size: |
16384
|
|
2998000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002998000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2998000
|
Size: |
81920
|
|
2966000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002966000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2966000
|
Size: |
4096
|
|
34C9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000034C9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
34C9000
|
Size: |
53248
|
|
5C57000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2266291334.0000000005C57000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5C57000
|
Size: |
8192
|
|
23AAA2D7000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1906847867.0000023AAA2D7000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AAA2D7000
|
Size: |
4096
|
|
76E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2235211900.000000000076E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
76E000
|
Size: |
8192
|
|
23AD8D5C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8D5C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8D5C000
|
Size: |
12288
|
|
2962000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002962000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2962000
|
Size: |
4096
|
|
693000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1379088358.0000000000693000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
693000
|
Size: |
4096
|
|
23AD806D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1933494984.0000023AD806D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AD806D000
|
Size: |
507904
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
BF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2473096442.0000000000BF0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BF0000
|
Size: |
4096
|
|
50B1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2263601402.00000000050B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
50B1000
|
Size: |
4096
|
|
6560000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2518046146.0000000006560000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6560000
|
Size: |
4096
|
|
479B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1635837828.000000000479B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
479B000
|
Size: |
20480
|
|
3DB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1635336346.00000000003DB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3DB000
|
Size: |
20480
|
|
2A77000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002A77000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A77000
|
Size: |
4096
|
|
31A8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000031A8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31A8000
|
Size: |
20480
|
|
2A41000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002A41000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A41000
|
Size: |
57344
|
|
6AD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1379232903.00000000006AD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6AD000
|
Size: |
16384
|
|
3687000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003687000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3687000
|
Size: |
4096
|
|
23AD8AB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1661317128.0000023AD8AB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8AB0000
|
Size: |
24576
|
|
272C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.000000000272C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
272C000
|
Size: |
4096
|
|
18170D00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2430329078.0000018170D00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
18170D00000
|
Size: |
430080
|
|
5010000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000014.00000002.2513527072.0000000005010000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5010000
|
Size: |
40960
|
|
491B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1635975900.000000000491B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
491B000
|
Size: |
20480
|
|
23AAA0D8000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1906686563.0000023AAA0D8000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AAA0D8000
|
Size: |
4096
|
|
5BFA000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2265484938.0000000005BFA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5BFA000
|
Size: |
90112
|
|
3578000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003578000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3578000
|
Size: |
4096
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1946531231.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
B8B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2472964695.0000000000B8B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B8B000
|
Size: |
20480
|
|
3610000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003610000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3610000
|
Size: |
4096
|
|
6BE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1379044055.00000000006BE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6BE000
|
Size: |
12288
|
|
23AA9AC0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1905977543.0000023AA9AC0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AA9AC0000
|
Size: |
8192
|
|
268B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.000000000268B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
268B000
|
Size: |
4096
|
|
36AA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000036AA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
36AA000
|
Size: |
4096
|
|
23AA82F0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1905916211.0000023AA82F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AA82F0000
|
Size: |
16384
|
|
33FE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000033FE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33FE000
|
Size: |
4096
|
|
5C1F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2266015610.0000000005C1F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5C1F000
|
Size: |
12288
|
|
782D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2270016171.000000000782D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
782D000
|
Size: |
12288
|
|
5661000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1982141979.0000000005661000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5661000
|
Size: |
4096
|
|
35AA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000035AA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
35AA000
|
Size: |
4096
|
|
3829000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003829000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3829000
|
Size: |
4096
|
|
5510000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2514325708.0000000005510000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5510000
|
Size: |
65536
|
|
3364000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003364000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3364000
|
Size: |
4096
|
|
F50000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000F50000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
F50000
|
Size: |
4096
|
|
23AD8D15000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8D15000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8D15000
|
Size: |
20480
|
|
2450000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2236792644.0000000002450000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2450000
|
Size: |
65536
|
|
E89000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000E89000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
E89000
|
Size: |
40960
|
|
7B8E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2520106850.0000000007B8E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7B8E000
|
Size: |
28672
|
|
1530000
|
heap
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2477262495.0000000001530000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1530000
|
Size: |
16384
|
|
1D7000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2225444566.00000000001D7000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1D7000
|
Size: |
36864
|
|
56E000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.000000000056E000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
56E000
|
Size: |
12288
|
|
5105000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2263707781.0000000005105000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5105000
|
Size: |
20480
|
|
31B4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000031B4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31B4000
|
Size: |
16384
|
|
16E4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2477447569.00000000016E4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
16E4000
|
Size: |
8192
|
|
370A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000370A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
370A000
|
Size: |
12288
|
|
2FF1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000002FF1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2FF1000
|
Size: |
4096
|
|
23AD8CE2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8CE2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8CE2000
|
Size: |
20480
|
|
329E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000329E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
329E000
|
Size: |
12288
|
|
EF7D8FE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1904821597.000000EF7D8FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
EF7D8FE000
|
Size: |
8192
|
|
1600000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2474615239.0000000001600000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1600000
|
Size: |
32768
|
|
46EB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1635801518.00000000046EB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
46EB000
|
Size: |
20480
|
|
4E0D000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2262897577.0000000004E0D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4E0D000
|
Size: |
12288
|
|
137F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2472212789.000000000137F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
137F000
|
Size: |
4096
|
|
23AD8A09000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937899477.0000023AD8A09000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
23AD8A09000
|
Size: |
4096
|
|
333E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000016.00000002.2445189024.000000000333E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
333E000
|
Size: |
8192
|
|
23AD8DC3000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1666315726.0000023AD8DC3000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
23AD8DC3000
|
Size: |
65536
|
|
23AA9BC3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1905977543.0000023AA9BC3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AA9BC3000
|
Size: |
16384
|
|
23AD827C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1933494984.0000023AD827C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AD827C000
|
Size: |
20480
|
|
23AD8AC6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1661317128.0000023AD8AC6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8AC6000
|
Size: |
28672
|
|
2B23000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002B23000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B23000
|
Size: |
4096
|
|
5661000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1982915954.0000000005661000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5661000
|
Size: |
4096
|
|
23AAA350000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1907163068.0000023AAA350000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AAA350000
|
Size: |
12288
|
|
181417A5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2402566501.00000181417A5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
181417A5000
|
Size: |
28672
|
|
7FF4A1760000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000003.2136032660.00007FF4A1760000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
7FF4A1760000
|
Size: |
4096
|
|
371F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000371F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
371F000
|
Size: |
4096
|
|
5840000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2515447055.0000000005840000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5840000
|
Size: |
155648
|
|
586E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2264417696.000000000586E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
586E000
|
Size: |
8192
|
|
796D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2519899083.000000000796D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
796D000
|
Size: |
20480
|
|
32C7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000032C7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32C7000
|
Size: |
4096
|
|
2430000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2236598888.0000000002430000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2430000
|
Size: |
32768
|
|
376E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000376E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
376E000
|
Size: |
4096
|
|
AAD000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.2235633778.0000000000AAD000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
AAD000
|
Size: |
4096
|
|
1230000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000000.2134064020.0000000001230000.00000008.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
1230000
|
Size: |
4096
|
|
339E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000339E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
339E000
|
Size: |
4096
|
|
16F8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2477447569.00000000016F8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
16F8000
|
Size: |
4096
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1947108559.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
11E3000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000000.2134064020.00000000011E3000.00000008.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
11E3000
|
Size: |
4096
|
|
466C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1635758612.000000000466C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
466C000
|
Size: |
16384
|
|
54FD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2513754895.00000000054FD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
54FD000
|
Size: |
8192
|
|
5B3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2516685717.0000000005B3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5B3E000
|
Size: |
8192
|
|
29E7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000029E7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29E7000
|
Size: |
4096
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1978193946.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
29C6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000029C6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29C6000
|
Size: |
4096
|
|
3659000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003659000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3659000
|
Size: |
4096
|
|
4E1C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2010853752.0000000004E1C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4E1C000
|
Size: |
512000
|
|
29AF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000029AF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29AF000
|
Size: |
4096
|
|
544E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2012095032.000000000544E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
544E000
|
Size: |
24576
|
|
E95000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000E95000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
E95000
|
Size: |
81920
|
|
64C9000
|
trusted library section
|
page readonly
|
|
|
|
Name: |
00000014.00000002.2517920309.00000000064C9000.00000002.08000000.00040000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page readonly
|
Base address: |
64C9000
|
Size: |
4096
|
|
30EB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000030EB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30EB000
|
Size: |
20480
|
|
2A5E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002A5E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A5E000
|
Size: |
49152
|
|
29E9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000029E9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29E9000
|
Size: |
4096
|
|
280E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.000000000280E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
280E000
|
Size: |
4096
|
|
37B9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000037B9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
37B9000
|
Size: |
12288
|
|
23AD7A83000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1903138736.0000023AD7A83000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AD7A83000
|
Size: |
217088
|
|
630000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2233410270.0000000000630000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
630000
|
Size: |
28672
|
|
23AAA110000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1906686563.0000023AAA110000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AAA110000
|
Size: |
8192
|
|
23AD80EA000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1933494984.0000023AD80EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AD80EA000
|
Size: |
1081344
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
D40000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000000.2129318502.0000000000D40000.00000002.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
D40000
|
Size: |
4096
|
|
2B31000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002B31000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B31000
|
Size: |
57344
|
|
28BA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000028BA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
28BA000
|
Size: |
4096
|
|
59C000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2233264167.000000000059C000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
59C000
|
Size: |
4096
|
|
23AD8966000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1936096484.0000023AD8966000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8966000
|
Size: |
16384
|
|
11B5000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000000.2134064020.00000000011B5000.00000008.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
11B5000
|
Size: |
40960
|
|
805E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2521281799.000000000805E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
805E000
|
Size: |
8192
|
|
337F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000337F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
337F000
|
Size: |
20480
|
|
4B5000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.00000000004B5000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
4B5000
|
Size: |
16384
|
|
2A92000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002A92000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A92000
|
Size: |
49152
|
|
29B1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000029B1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29B1000
|
Size: |
4096
|
|
29FE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000029FE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29FE000
|
Size: |
4096
|
|
BA0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2236303337.0000000000BA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BA0000
|
Size: |
4096
|
|
37C3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000037C3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
37C3000
|
Size: |
4096
|
|
1622000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2475209902.0000000001622000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1622000
|
Size: |
4096
|
|
46AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1635780898.00000000046AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
46AE000
|
Size: |
8192
|
|
12BB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2474851091.00000000012BB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12BB000
|
Size: |
12288
|
|
23BE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2236503552.00000000023BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
23BE000
|
Size: |
8192
|
|
4A16000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2261082402.0000000004A16000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4A16000
|
Size: |
16384
|
|
14BA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2472811392.00000000014BA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14BA000
|
Size: |
8192
|
|
2A71000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002A71000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A71000
|
Size: |
4096
|
|
26DA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000026DA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
26DA000
|
Size: |
4096
|
|
1814300D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2402659704.000001814300D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
1814300D000
|
Size: |
4096
|
|
77C0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2269919216.00000000077C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
77C0000
|
Size: |
4096
|
|
23AD8C7B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8C7B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8C7B000
|
Size: |
20480
|
|
5570000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2514924557.0000000005570000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5570000
|
Size: |
4096
|
|
3774000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003774000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3774000
|
Size: |
4096
|
|
137A000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1904218573.000000000137A000.00000004.00000001.01000000.00000006.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
137A000
|
Size: |
4096
|
|
23AAA0D0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1906686563.0000023AAA0D0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AAA0D0000
|
Size: |
16384
|
|
2A84000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002A84000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A84000
|
Size: |
4096
|
|
281F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.000000000281F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
281F000
|
Size: |
4096
|
|
181414E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.2135278923.00000181414E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
181414E0000
|
Size: |
389120
|
|
EF7D6F7000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1904762159.000000EF7D6F7000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
EF7D6F7000
|
Size: |
36864
|
|
4F0E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2262939785.0000000004F0E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4F0E000
|
Size: |
8192
|
|
289F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.000000000289F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
289F000
|
Size: |
4096
|
|
34A9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000034A9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
34A9000
|
Size: |
4096
|
|
23AD8B13000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1661317128.0000023AD8B13000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8B13000
|
Size: |
24576
|
|
23AD8AD6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1661317128.0000023AD8AD6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8AD6000
|
Size: |
24576
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1947089029.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1979247396.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
2AA3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002AA3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AA3000
|
Size: |
4096
|
|
2739000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002739000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2739000
|
Size: |
45056
|
|
13E7000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1904487859.00000000013E7000.00000004.00000001.01000000.00000006.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
13E7000
|
Size: |
16384
|
|
23AD8D49000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8D49000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8D49000
|
Size: |
20480
|
|
492000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.0000000000492000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
492000
|
Size: |
20480
|
|
312A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000312A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
312A000
|
Size: |
20480
|
|
25A0000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.2237058815.00000000025A0000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
25A0000
|
Size: |
4096
|
|
3777000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003777000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3777000
|
Size: |
61440
|
|
23AD8E2C000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1666315726.0000023AD8E2C000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
23AD8E2C000
|
Size: |
8192
|
|
23AD8DF0000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1666315726.0000023AD8DF0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
23AD8DF0000
|
Size: |
20480
|
|
30DA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000030DA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30DA000
|
Size: |
40960
|
|
18171516000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2431242997.0000018171516000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
18171516000
|
Size: |
4096
|
|
1814159B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2400743173.000001814159B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1814159B000
|
Size: |
16384
|
|
6470000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2517783047.0000000006470000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6470000
|
Size: |
8192
|
|
4580000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1635682624.0000000004580000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4580000
|
Size: |
4096
|
|
3721000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003721000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3721000
|
Size: |
12288
|
|
D6D000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000D6D000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
D6D000
|
Size: |
45056
|
|
36A4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000036A4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
36A4000
|
Size: |
20480
|
|
4CF9000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2010853752.0000000004CF9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CF9000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
352F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000016.00000002.2445937724.000000000352F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
352F000
|
Size: |
4096
|
|
AF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2236041283.0000000000AF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
AF0000
|
Size: |
4096
|
|
51C000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.000000000051C000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
51C000
|
Size: |
40960
|
|
5167000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000016.00000002.2447141095.0000000005167000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5167000
|
Size: |
2121728
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
DD2000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000DD2000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
DD2000
|
Size: |
12288
|
|
687000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1378768177.0000000000687000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
687000
|
Size: |
8192
|
|
283B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.000000000283B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
283B000
|
Size: |
364544
|
|
5520000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000012.00000002.2480923797.0000000005520000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5520000
|
Size: |
65536
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1946638039.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
1070000
|
heap
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2473543246.0000000001070000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1070000
|
Size: |
4096
|
|
5820000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.2447794546.0000000005820000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5820000
|
Size: |
4096
|
|
3434000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003434000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3434000
|
Size: |
4096
|
|
23AD8E1E000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1666315726.0000023AD8E1E000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
23AD8E1E000
|
Size: |
20480
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1947021085.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
368F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000368F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
368F000
|
Size: |
4096
|
|
49F4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2261082402.00000000049F4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
49F4000
|
Size: |
94208
|
|
18143679000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2403657756.0000018143679000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
18143679000
|
Size: |
4096
|
|
3186000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003186000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3186000
|
Size: |
20480
|
|
5039000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2263267076.0000000005039000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5039000
|
Size: |
77824
|
|
3135000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003135000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3135000
|
Size: |
20480
|
|
23AA9B9F000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1905977543.0000023AA9B9F000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AA9B9F000
|
Size: |
4096
|
|
10F5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2474138370.00000000010F5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10F5000
|
Size: |
12288
|
|
3742000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003742000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3742000
|
Size: |
4096
|
|
18143500000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2403559447.0000018143500000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
18143500000
|
Size: |
16384
|
|
3495000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003495000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3495000
|
Size: |
61440
|
|
4DB7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.2446774056.0000000004DB7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DB7000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
10B3000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.00000000010B3000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
10B3000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
35AC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000035AC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
35AC000
|
Size: |
4096
|
|
8160000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2521359435.0000000008160000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8160000
|
Size: |
57344
|
|
4A20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2261082402.0000000004A20000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4A20000
|
Size: |
57344
|
|
D94000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000D94000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
D94000
|
Size: |
16384
|
|
118F000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.000000000118F000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
118F000
|
Size: |
16384
|
|
691000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1378574196.0000000000691000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
691000
|
Size: |
40960
|
|
2790000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002790000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2790000
|
Size: |
122880
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1379156492.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
20480
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1947045432.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
27AF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000027AF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
27AF000
|
Size: |
28672
|
|
F22000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000F22000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
F22000
|
Size: |
81920
|
|
23AD829E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1933494984.0000023AD829E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AD829E000
|
Size: |
20480
|
|
6A2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1378637816.00000000006A2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6A2000
|
Size: |
20480
|
|
23AD8AED000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1661317128.0000023AD8AED000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8AED000
|
Size: |
24576
|
|
416F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1635667333.000000000416F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
416F000
|
Size: |
4096
|
|
18141598000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2400743173.0000018141598000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
18141598000
|
Size: |
8192
|
|
4AF000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.00000000004AF000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
4AF000
|
Size: |
20480
|
|
DA1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000DA1000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
DA1000
|
Size: |
36864
|
|
7FF4A1700000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2431685412.00007FF4A1700000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
7FF4A1700000
|
Size: |
4096
|
|
181414F5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.2135756304.00000181414F5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
181414F5000
|
Size: |
36864
|
|
7892000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2519517400.0000000007892000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7892000
|
Size: |
12288
|
|
23AD82B5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1933494984.0000023AD82B5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AD82B5000
|
Size: |
20480
|
|
599B000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2264455666.000000000599B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
599B000
|
Size: |
20480
|
|
AD7000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.2235978433.0000000000AD7000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
AD7000
|
Size: |
4096
|
|
5A3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2516642235.0000000005A3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5A3E000
|
Size: |
8192
|
|
23AA8099000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1904927879.0000023AA8099000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AA8099000
|
Size: |
65536
|
|
EC0000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000EC0000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
EC0000
|
Size: |
4096
|
|
291E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.000000000291E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
291E000
|
Size: |
36864
|
|
23AAA21B000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1906847867.0000023AAA21B000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AAA21B000
|
Size: |
4096
|
|
160D000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000014.00000002.2474828054.000000000160D000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
160D000
|
Size: |
4096
|
|
5068000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2263267076.0000000005068000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5068000
|
Size: |
8192
|
|
23AD8A54000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1661317128.0000023AD8A54000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8A54000
|
Size: |
24576
|
|
16EE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2477447569.00000000016EE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
16EE000
|
Size: |
4096
|
|
13F2000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000C.00000000.1632605487.00000000013F2000.00000002.00000001.01000000.00000006.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
13F2000
|
Size: |
4096
|
|
5937000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2516553711.0000000005937000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5937000
|
Size: |
32768
|
|
741F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2269359003.000000000741F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
741F000
|
Size: |
4096
|
|
5661000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1980743733.0000000005661000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5661000
|
Size: |
4096
|
|
26AE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000026AE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
26AE000
|
Size: |
4096
|
|
26D6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000026D6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
26D6000
|
Size: |
12288
|
|
23AD787E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1907942193.0000023AD787E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AD787E000
|
Size: |
20480
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
838E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2521843613.000000000838E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
838E000
|
Size: |
8192
|
|
23AAA190000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1906686563.0000023AAA190000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AAA190000
|
Size: |
8192
|
|
ECC000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000ECC000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
ECC000
|
Size: |
4096
|
|
13BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2472291306.00000000013BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
13BE000
|
Size: |
8192
|
|
1690000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000014.00000002.2475508466.0000000001690000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1690000
|
Size: |
65536
|
|
5BE0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2265394917.0000000005BE0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5BE0000
|
Size: |
4096
|
|
35AE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000035AE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
35AE000
|
Size: |
4096
|
|
6580000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2518228077.0000000006580000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6580000
|
Size: |
24576
|
|
4059000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2501089519.0000000004059000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4059000
|
Size: |
4096
|
|
23AAA223000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1906847867.0000023AAA223000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AAA223000
|
Size: |
49152
|
|
35A8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000035A8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
35A8000
|
Size: |
4096
|
|
3362000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003362000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3362000
|
Size: |
4096
|
|
23AD7A80000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1931948763.0000023AD7A80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AD7A80000
|
Size: |
12288
|
|
28D5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000028D5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
28D5000
|
Size: |
135168
|
|
2A13000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002A13000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A13000
|
Size: |
20480
|
|
D71D000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2271124231.000000000D71D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
D71D000
|
Size: |
12288
|
|
3210000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.2445142734.0000000003210000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3210000
|
Size: |
4096
|
|
59C7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2264651042.00000000059C7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
59C7000
|
Size: |
36864
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1946507035.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
1031000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000001031000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
1031000
|
Size: |
12288
|
|
6AC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1378435257.00000000006AC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6AC000
|
Size: |
40960
|
|
23AD8CCB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8CCB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8CCB000
|
Size: |
20480
|
|
686000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1379144265.0000000000686000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
686000
|
Size: |
20480
|
|
23AD828D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1933494984.0000023AD828D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AD828D000
|
Size: |
20480
|
|
378B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000378B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
378B000
|
Size: |
4096
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1978469968.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
181437A8000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2403977009.00000181437A8000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
181437A8000
|
Size: |
4096
|
|
A712000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2522126308.000000000A712000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
A712000
|
Size: |
12288
|
|
1198000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000001198000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
1198000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
6B6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1379044055.00000000006B6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B6000
|
Size: |
20480
|
|
3438000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003438000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3438000
|
Size: |
4096
|
|
256E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2236941377.000000000256E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
256E000
|
Size: |
8192
|
|
5661000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1946200326.0000000005661000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5661000
|
Size: |
196608
|
|
23AA80CD000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1635572976.0000023AA80CD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AA80CD000
|
Size: |
385024
|
|
32E2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000032E2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32E2000
|
Size: |
323584
|
|
18141720000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000013.00000002.2402542888.0000018141720000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
18141720000
|
Size: |
4096
|
|
23AD8A91000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1661317128.0000023AD8A91000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8A91000
|
Size: |
24576
|
|
23AD8D6D000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1666315726.0000023AD8D6D000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
23AD8D6D000
|
Size: |
90112
|
|
3685000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003685000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3685000
|
Size: |
4096
|
|
577000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.0000000000577000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
577000
|
Size: |
20480
|
|
2ADC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002ADC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2ADC000
|
Size: |
4096
|
|
2947000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002947000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2947000
|
Size: |
20480
|
|
2ED0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476547278.0000000002ED0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2ED0000
|
Size: |
4096
|
|
32E7000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2010338707.00000000032E7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32E7000
|
Size: |
8192
|
|
78C4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2270216759.00000000078C4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
78C4000
|
Size: |
4096
|
|
2F0E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2479136612.0000000002F0E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F0E000
|
Size: |
172032
|
|
314C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000314C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
314C000
|
Size: |
20480
|
|
16D8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476156998.00000000016D8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16D8000
|
Size: |
28672
|
|
10B7000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.00000000010B7000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
10B7000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
412000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.0000000000412000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
412000
|
Size: |
241664
|
|
2A5A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002A5A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A5A000
|
Size: |
4096
|
|
2983000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002983000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2983000
|
Size: |
4096
|
|
4BA000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.00000000004BA000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
4BA000
|
Size: |
20480
|
|
3113000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003113000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3113000
|
Size: |
20480
|
|
29CE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000029CE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29CE000
|
Size: |
4096
|
|
2B6E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002B6E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B6E000
|
Size: |
4096
|
|
67F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1379286290.000000000067F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
67F000
|
Size: |
20480
|
|
18142F5E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2402659704.0000018142F5E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
18142F5E000
|
Size: |
4096
|
|
2732000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002732000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2732000
|
Size: |
4096
|
|
5661000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1982016058.0000000005661000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5661000
|
Size: |
4096
|
|
1207000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000012.00000002.2474409587.0000000001207000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1207000
|
Size: |
4096
|
|
10BA000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.00000000010BA000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
10BA000
|
Size: |
32768
|
|
23AD8B39000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1661317128.0000023AD8B39000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8B39000
|
Size: |
131072
|
|
50A7000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2263601402.00000000050A7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
50A7000
|
Size: |
12288
|
|
11D9000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000000.2134064020.00000000011D9000.00000008.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
11D9000
|
Size: |
12288
|
|
23AD8E24000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1666315726.0000023AD8E24000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
23AD8E24000
|
Size: |
20480
|
|
96F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2235400481.000000000096F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
96F000
|
Size: |
4096
|
|
DE4000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000DE4000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
DE4000
|
Size: |
8192
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1946246116.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
2943000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002943000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2943000
|
Size: |
4096
|
|
34D9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000034D9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
34D9000
|
Size: |
4096
|
|
23AA8280000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1905796497.0000023AA8280000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AA8280000
|
Size: |
8192
|
|
29E1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000029E1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29E1000
|
Size: |
12288
|
|
23AD8C00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8C00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8C00000
|
Size: |
241664
|
|
66E2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2518745503.00000000066E2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
66E2000
|
Size: |
4096
|
|
14E4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2474327966.00000000014E4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14E4000
|
Size: |
110592
|
|
2EBC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476365651.0000000002EBC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2EBC000
|
Size: |
16384
|
|
348C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000348C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
348C000
|
Size: |
12288
|
|
35C7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000035C7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
35C7000
|
Size: |
4096
|
|
29DF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000029DF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29DF000
|
Size: |
4096
|
|
172A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2478423380.000000000172A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
172A000
|
Size: |
24576
|
|
18143508000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2403559447.0000018143508000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
18143508000
|
Size: |
4096
|
|
35DE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000035DE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
35DE000
|
Size: |
4096
|
|
2D3A000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2007847922.0000000002D3A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2D3A000
|
Size: |
24576
|
|
544E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2480830448.000000000544E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
544E000
|
Size: |
8192
|
|
23AA9BD1000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1905977543.0000023AA9BD1000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AA9BD1000
|
Size: |
32768
|
|
4E8000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.00000000004E8000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
4E8000
|
Size: |
20480
|
|
23AD8E13000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1666315726.0000023AD8E13000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
23AD8E13000
|
Size: |
40960
|
|
7889000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2270116280.0000000007889000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7889000
|
Size: |
4096
|
|
3174000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1946422077.0000000003174000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
4096
|
|
B3E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2236068909.0000000000B3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B3E000
|
Size: |
8192
|
|
45EE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1635723726.00000000045EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
45EE000
|
Size: |
8192
|
|
18143073000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2402659704.0000018143073000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
18143073000
|
Size: |
16384
|
|
2AAB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002AAB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AAB000
|
Size: |
49152
|
|
68F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1379088358.000000000068F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
68F000
|
Size: |
8192
|
|
378D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000378D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
378D000
|
Size: |
4096
|
|
FE9000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000FE9000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
FE9000
|
Size: |
4096
|
|
2899000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002899000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2899000
|
Size: |
4096
|
|
35CB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000035CB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
35CB000
|
Size: |
4096
|
|
292C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.000000000292C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
292C000
|
Size: |
4096
|
|
1625000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000014.00000002.2475243638.0000000001625000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1625000
|
Size: |
4096
|
|
2AA5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002AA5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AA5000
|
Size: |
20480
|
|
23AA9BAD000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1905977543.0000023AA9BAD000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AA9BAD000
|
Size: |
20480
|
|
23AA9BCA000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1905977543.0000023AA9BCA000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23AA9BCA000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
D5D000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000D5D000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
D5D000
|
Size: |
12288
|
|
28A3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000028A3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
28A3000
|
Size: |
40960
|
|
2B25000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002B25000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B25000
|
Size: |
4096
|
|
1610000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2474857327.0000000001610000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1610000
|
Size: |
4096
|
|
11FA000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2400076361.00000000011FA000.00000004.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
11FA000
|
Size: |
8192
|
|
33A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.00000000033A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33A0000
|
Size: |
57344
|
|
4B50000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2262728557.0000000004B50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B50000
|
Size: |
4096
|
|
78C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2519602230.00000000078C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
78C0000
|
Size: |
65536
|
|
23AD8CD6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8CD6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8CD6000
|
Size: |
20480
|
|
23AD8CF3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8CF3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8CF3000
|
Size: |
20480
|
|
2945000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002945000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2945000
|
Size: |
4096
|
|
2AF7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002AF7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AF7000
|
Size: |
4096
|
|
18142F65000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2402659704.0000018142F65000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
18142F65000
|
Size: |
28672
|
|
6570000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000014.00000002.2518075626.0000000006570000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
6570000
|
Size: |
65536
|
|
1312000
|
heap
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2474851091.0000000001312000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1312000
|
Size: |
184320
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
380E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.000000000380E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
380E000
|
Size: |
4096
|
|
23AA80E2000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1635695856.0000023AA80E2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AA80E2000
|
Size: |
36864
|
|
AD5000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.2235942701.0000000000AD5000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
AD5000
|
Size: |
4096
|
|
2F45000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2479136612.0000000002F45000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F45000
|
Size: |
8192
|
|
32E0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2010338707.00000000032E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32E0000
|
Size: |
20480
|
|
18143798000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2403977009.0000018143798000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
18143798000
|
Size: |
12288
|
|
23AD8D93000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1939876531.0000023AD8D93000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
23AD8D93000
|
Size: |
4096
|
|
511E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000016.00000002.2447141095.000000000511E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
511E000
|
Size: |
290816
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
687000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1379183199.0000000000687000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
687000
|
Size: |
16384
|
|
23AD8A17000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1661317128.0000023AD8A17000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8A17000
|
Size: |
28672
|
|
2981000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002981000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2981000
|
Size: |
4096
|
|
ABD000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.2235761677.0000000000ABD000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
ABD000
|
Size: |
4096
|
|
3827000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000014.00000002.2476801289.0000000003827000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
20
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3827000
|
Size: |
4096
|
|
2A5C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.0000000002A5C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A5C000
|
Size: |
4096
|
|
23AD7890000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1931659483.0000023AD7890000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
23AD7890000
|
Size: |
348160
|
|
35B1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2251107589.00000000035B1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
35B1000
|
Size: |
339968
|
|
100E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2473299595.000000000100E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
100E000
|
Size: |
8192
|
|
FD4000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000FD4000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
FD4000
|
Size: |
4096
|
|
18170D9D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2430329078.0000018170D9D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
18170D9D000
|
Size: |
12288
|
|
50B5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2263601402.00000000050B5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
50B5000
|
Size: |
4096
|
|
CBF000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1635624900.0000000000CBF000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CBF000
|
Size: |
4096
|
|
18143033000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2402659704.0000018143033000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
18143033000
|
Size: |
20480
|
|
1705000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000012.00000002.2477447569.0000000001705000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
18
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1705000
|
Size: |
36864
|
|
46A000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.000000000046A000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
46A000
|
Size: |
20480
|
|
23AD8D38000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1937945411.0000023AD8D38000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AD8D38000
|
Size: |
40960
|
|
2570000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2236969684.0000000002570000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2570000
|
Size: |
65536
|
|
FFF000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.2129385817.0000000000FFF000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
FFF000
|
Size: |
180224
|
|
4D7000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2225569033.00000000004D7000.00000002.00000001.01000000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
4D7000
|
Size: |
20480
|
|
26F1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000026F1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
26F1000
|
Size: |
4096
|
|
310F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2008785543.000000000310F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
310F000
|
Size: |
4096
|
|
BD0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2236413133.0000000000BD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BD0000
|
Size: |
24576
|
|
D5DD000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2271041981.000000000D5DD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
D5DD000
|
Size: |
12288
|
|
27DA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2237083332.00000000027DA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
27DA000
|
Size: |
4096
|
|