CB0000
|
unclassified section
|
page execute and read and write
|
 |
|
|
Name: |
00000008.00000002.2654798948.0000000000CB0000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
CB0000
|
Size: |
192512
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Found malware configuration |
AV Detection |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
Yara signature match |
System Summary |
|
|
400000
|
remote allocation
|
page execute and read and write
|
 |
|
|
Name: |
00000006.00000002.1641106278.0000000000400000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
400000
|
Size: |
192512
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
Yara signature match |
System Summary |
|
|
B00000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
00000008.00000002.2654692262.0000000000B00000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
B00000
|
Size: |
192512
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
Yara signature match |
System Summary |
|
|
DF0000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000008.00000002.2654885406.0000000000DF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
DF0000
|
Size: |
192512
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
Yara signature match |
System Summary |
|
|
7FF5BE7E8000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1542743611.00007FF5BE7E8000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE7E8000
|
Size: |
12288
|
|
CF36000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1536456695.000000000CF36000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CF36000
|
Size: |
1982464
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
BAAE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1532365763.000000000BAAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BAAE000
|
Size: |
8192
|
|
7FF5BE6A5000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2674044043.00007FF5BE6A5000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE6A5000
|
Size: |
8192
|
|
CE9E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1535163726.000000000CE9E000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CE9E000
|
Size: |
20480
|
|
7FF5BE86B000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2676423890.00007FF5BE86B000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE86B000
|
Size: |
28672
|
|
7FFC3C930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1872653776.00007FFC3C930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFC3C930000
|
Size: |
4096
|
|
7A68000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1519605877.0000000007A68000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A68000
|
Size: |
4096
|
|
8EC0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1522693176.0000000008EC0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
8EC0000
|
Size: |
4096
|
|
C5E8000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2666842510.000000000C5E8000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C5E8000
|
Size: |
32768
|
|
CD08000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1535163726.000000000CD08000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CD08000
|
Size: |
4096
|
|
1A67D010000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1865220821.000001A67D010000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A67D010000
|
Size: |
8192
|
|
7FF5BE903000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1544788017.00007FF5BE903000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE903000
|
Size: |
4096
|
|
7B53000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1519605877.0000000007B53000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7B53000
|
Size: |
4096
|
|
7FF5BE298000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2670985990.00007FF5BE298000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE298000
|
Size: |
12288
|
|
8D7D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2662052714.0000000008D7D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8D7D000
|
Size: |
12288
|
|
A33A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2664006005.000000000A33A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
A33A000
|
Size: |
24576
|
|
CB6F000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1533280630.000000000CB6F000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB6F000
|
Size: |
4096
|
|
9ACE000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2072108638.0000000009ACE000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9ACE000
|
Size: |
4096
|
|
4DD1000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1518362137.0000000004DD1000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4DD1000
|
Size: |
4096
|
|
2F20000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.1651214835.0000000002F20000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
2F20000
|
Size: |
217088
|
|
1A67B050000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1860048586.000001A67B050000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1A67B050000
|
Size: |
65536
|
|
7FF5BE96E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2677755689.00007FF5BE96E000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE96E000
|
Size: |
4096
|
|
C66A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2666873394.000000000C66A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C66A000
|
Size: |
24576
|
|
7FF5BE80C000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2675776420.00007FF5BE80C000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE80C000
|
Size: |
12288
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1643918437.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|
CB93000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1533280630.000000000CB93000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB93000
|
Size: |
4096
|
|
7FF5BE898000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2676754513.00007FF5BE898000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE898000
|
Size: |
8192
|
|
9952000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2662609847.0000000009952000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9952000
|
Size: |
8192
|
|
7A6C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1519605877.0000000007A6C000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A6C000
|
Size: |
4096
|
|
3649000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2655849009.0000000003649000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3649000
|
Size: |
28672
|
|
35C9000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.2655735535.00000000035C9000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
35C9000
|
Size: |
4096
|
|
22D201BB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1352221428.0000022D201BB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D201BB000
|
Size: |
20480
|
|
3356000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.1656803800.0000000003356000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3356000
|
Size: |
8192
|
|
7FF5BE8FC000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1544788017.00007FF5BE8FC000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE8FC000
|
Size: |
24576
|
|
7FF5BE932000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1545289458.00007FF5BE932000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE932000
|
Size: |
8192
|
|
22D20240000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1353364973.0000022D20240000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D20240000
|
Size: |
4096
|
|
7A64000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658707759.0000000007A64000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A64000
|
Size: |
4096
|
|
39B3000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1517673112.00000000039B3000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
39B3000
|
Size: |
4096
|
|
9DF2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2663714060.0000000009DF2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9DF2000
|
Size: |
24576
|
|
A9F0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1528246779.000000000A9F0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
A9F0000
|
Size: |
90112
|
|
7FF5BE4A3000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2671936172.00007FF5BE4A3000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE4A3000
|
Size: |
12288
|
|
22D201D8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1352726040.0000022D201D8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D201D8000
|
Size: |
12288
|
|
CC76000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1535163726.000000000CC76000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CC76000
|
Size: |
8192
|
|
ABB5000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1528246779.000000000ABB5000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
ABB5000
|
Size: |
4096
|
|
7FF5BE76E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1542476246.00007FF5BE76E000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE76E000
|
Size: |
16384
|
|
7FF5BE4A3000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1539238170.00007FF5BE4A3000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE4A3000
|
Size: |
12288
|
|
D6BD000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2073378129.000000000D6BD000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D6BD000
|
Size: |
8192
|
|
97F0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2662578656.00000000097F0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
97F0000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2B59C61A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1516637066.000002B59C61A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B59C61A000
|
Size: |
372736
|
|
B8F0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1531987322.000000000B8F0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
B8F0000
|
Size: |
4096
|
|
4D40000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2657432976.0000000004D40000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4D40000
|
Size: |
20480
|
|
5700000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000007.00000002.2658381860.0000000005700000.00000008.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
5700000
|
Size: |
286720
|
|
2D30000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.1645597367.0000000002D30000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
2D30000
|
Size: |
4096
|
|
C93588D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1516287052.000000C93588D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C93588D000
|
Size: |
12288
|
|
A9D5000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1528246779.000000000A9D5000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
A9D5000
|
Size: |
8192
|
|
CA7E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1533189983.000000000CA7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
CA7E000
|
Size: |
8192
|
|
37C0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2656045500.00000000037C0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
37C0000
|
Size: |
4096
|
|
2F2C6FA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1352861366.0000002F2C6FA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2F2C6FA000
|
Size: |
24576
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1713992188.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|
7E80000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1521266909.0000000007E80000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7E80000
|
Size: |
4096
|
|
3549000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2655778853.0000000003549000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3549000
|
Size: |
28672
|
|
1A600437000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1815974500.000001A600437000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1A600437000
|
Size: |
81920
|
|
7FF5BEA4D000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2679391641.00007FF5BEA4D000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BEA4D000
|
Size: |
4096
|
|
4D40000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1518362137.0000000004D40000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4D40000
|
Size: |
20480
|
|
7FF5BE7F4000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2675670013.00007FF5BE7F4000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE7F4000
|
Size: |
8192
|
|
7B53000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2072664500.0000000007B53000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7B53000
|
Size: |
4096
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1644638761.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|
9C06000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2662764839.0000000009C06000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9C06000
|
Size: |
12288
|
|
7FF5BE97A000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2678034768.00007FF5BE97A000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE97A000
|
Size: |
8192
|
|
C9349F9000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1516049906.000000C9349F9000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C9349F9000
|
Size: |
28672
|
|
9B49000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1523845606.0000000009B49000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9B49000
|
Size: |
749568
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
7FF5BE96E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1545869743.00007FF5BE96E000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE96E000
|
Size: |
4096
|
|
2EF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1715170783.0000000002EF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EF0000
|
Size: |
167936
|
|
7A84000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1519605877.0000000007A84000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A84000
|
Size: |
61440
|
|
7FF5BE9BB000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1547231379.00007FF5BE9BB000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE9BB000
|
Size: |
4096
|
|
9C1D000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2071685840.0000000009C1D000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9C1D000
|
Size: |
8192
|
|
D7FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1537102734.000000000D7FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
D7FE000
|
Size: |
8192
|
|
7FF5BE51A000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2672675526.00007FF5BE51A000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE51A000
|
Size: |
8192
|
|
1A600422000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1815974500.000001A600422000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1A600422000
|
Size: |
81920
|
|
7A5C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1519605877.0000000007A5C000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A5C000
|
Size: |
4096
|
|
9D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1645560238.000000000009D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9D000
|
Size: |
12288
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1643869254.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|
7FF5BE8FC000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2677023133.00007FF5BE8FC000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE8FC000
|
Size: |
24576
|
|
7FF5BE3E8000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2671373028.00007FF5BE3E8000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE3E8000
|
Size: |
4096
|
|
A107000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1526610590.000000000A107000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
A107000
|
Size: |
192512
|
|
7FF5BE6E3000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2674322359.00007FF5BE6E3000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE6E3000
|
Size: |
8192
|
|
AA8A000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1528246779.000000000AA8A000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AA8A000
|
Size: |
4096
|
|
7FF5BE79A000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1542581848.00007FF5BE79A000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE79A000
|
Size: |
114688
|
|
7FF5BE33C000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1538559046.00007FF5BE33C000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE33C000
|
Size: |
4096
|
|
22D201DB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1351871889.0000022D201DB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D201DB000
|
Size: |
81920
|
|
4E0D000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1518362137.0000000004E0D000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4E0D000
|
Size: |
73728
|
|
9D37000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1523845606.0000000009D37000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9D37000
|
Size: |
98304
|
|
7FF5BE72C000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2674635177.00007FF5BE72C000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE72C000
|
Size: |
4096
|
|
CE83000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2668671033.000000000CE83000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CE83000
|
Size: |
53248
|
|
C56F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2666815969.000000000C56F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C56F000
|
Size: |
4096
|
|
7FFC3C880000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1869858762.00007FFC3C880000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFC3C880000
|
Size: |
65536
|
|
9992000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1523845606.0000000009992000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9992000
|
Size: |
327680
|
|
7FF5BE9D0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1547479090.00007FF5BE9D0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE9D0000
|
Size: |
20480
|
|
CB54000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2667015077.000000000CB54000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB54000
|
Size: |
8192
|
|
7FF5BE7E6000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2675384107.00007FF5BE7E6000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE7E6000
|
Size: |
4096
|
|
7FF5BE52C000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1540286560.00007FF5BE52C000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE52C000
|
Size: |
12288
|
|
98CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1523441779.00000000098CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
98CE000
|
Size: |
8192
|
|
3000000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1517136540.0000000003000000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3000000
|
Size: |
8192
|
|
2B59F912000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1517714752.000002B59F912000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B59F912000
|
Size: |
4505600
|
|
CE9E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2072496324.000000000CE9E000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CE9E000
|
Size: |
20480
|
|
4EC0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1519060398.0000000004EC0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4EC0000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
7A42000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658707759.0000000007A42000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A42000
|
Size: |
4096
|
|
8E7F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1522670684.0000000008E7F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8E7F000
|
Size: |
4096
|
|
9DF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2663714060.0000000009DF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9DF0000
|
Size: |
4096
|
|
2FB0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2655450759.0000000002FB0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2FB0000
|
Size: |
4096
|
|
33CA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2655633917.00000000033CA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
33CA000
|
Size: |
24576
|
|
CD3D000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1535163726.000000000CD3D000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CD3D000
|
Size: |
4096
|
|
7FF5BE4EA000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2672523208.00007FF5BE4EA000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE4EA000
|
Size: |
16384
|
|
9B25000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1523845606.0000000009B25000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9B25000
|
Size: |
139264
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
4E50000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658089965.0000000004E50000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4E50000
|
Size: |
4096
|
|
8FCB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2662226153.0000000008FCB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8FCB000
|
Size: |
20480
|
|
1A67D110000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1865332423.000001A67D110000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A67D110000
|
Size: |
36864
|
|
7FF5BE787000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2675269011.00007FF5BE787000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE787000
|
Size: |
57344
|
|
7FF5BE81E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2675776420.00007FF5BE81E000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE81E000
|
Size: |
8192
|
|
D6BE000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2073478423.000000000D6BE000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D6BE000
|
Size: |
4096
|
|
5E5F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2657044207.0000000005E5F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5E5F000
|
Size: |
4096
|
|
CB54000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1533280630.000000000CB54000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB54000
|
Size: |
8192
|
|
7FF5BE71F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2674497640.00007FF5BE71F000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE71F000
|
Size: |
24576
|
|
39C0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1517673112.00000000039C0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
39C0000
|
Size: |
57344
|
|
2D4F000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.1645597367.0000000002D4F000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
2D4F000
|
Size: |
4096
|
|
7FFC3C6CC000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1866584028.00007FFC3C6CC000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7FFC3C6CC000
|
Size: |
8192
|
|
7FF5BE9BE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2678476280.00007FF5BE9BE000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE9BE000
|
Size: |
4096
|
|
9C1D000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2662764839.0000000009C1D000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9C1D000
|
Size: |
8192
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1644835026.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|
7FF5BE8C4000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1544628974.00007FF5BE8C4000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE8C4000
|
Size: |
32768
|
|
1641000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1516592513.0000000001641000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1641000
|
Size: |
12288
|
|
10C93000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2669741529.0000000010C93000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
10C93000
|
Size: |
217088
|
|
2B5A435F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1517714752.000002B5A435F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B5A435F000
|
Size: |
10485760
|
|
CB5C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1533280630.000000000CB5C000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB5C000
|
Size: |
12288
|
|
7DF4C9801000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000007.00000000.1538053474.00007DF4C9801000.00000020.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7DF4C9801000
|
Size: |
4096
|
|
7FF5BE61A000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1540599308.00007FF5BE61A000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE61A000
|
Size: |
8192
|
|
D134000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2071160029.000000000D134000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D134000
|
Size: |
110592
|
|
7FF5BE4DE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1539857847.00007FF5BE4DE000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE4DE000
|
Size: |
4096
|
|
2B59C7D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1517245352.000002B59C7D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B59C7D0000
|
Size: |
16384
|
|
7FF5BEA54000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1548755686.00007FF5BEA54000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BEA54000
|
Size: |
8192
|
|
1695000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2655176348.0000000001695000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1695000
|
Size: |
40960
|
|
7FF5BE285000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2670958723.00007FF5BE285000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE285000
|
Size: |
8192
|
|
341C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1643019869.000000000341C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
341C000
|
Size: |
4096
|
|
97F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1645845199.000000000097F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
97F000
|
Size: |
4096
|
|
7FF5BE9C0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2678476280.00007FF5BE9C0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE9C0000
|
Size: |
12288
|
|
C9FB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1533136647.000000000C9FB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C9FB000
|
Size: |
20480
|
|
5F60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1969643309.0000000005F60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F60000
|
Size: |
147456
|
|
D37C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1536826380.000000000D37C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
D37C000
|
Size: |
16384
|
|
314E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1641084267.000000000314E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
314E000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3030000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.1654119281.0000000003030000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
3030000
|
Size: |
49152
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7FFC3C860000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1869263897.00007FFC3C860000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFC3C860000
|
Size: |
65536
|
|
2B5A395F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1517714752.000002B5A395F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B5A395F000
|
Size: |
10485760
|
|
ABB5000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2664786423.000000000ABB5000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
ABB5000
|
Size: |
4096
|
|
7AC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2654607957.00000000007AC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7AC000
|
Size: |
16384
|
|
2F49000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1641394929.0000000002F49000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F49000
|
Size: |
24576
|
|
22D20203000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1353321933.0000022D20203000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D20203000
|
Size: |
147456
|
|
7FF5BE7E2000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1542644503.00007FF5BE7E2000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE7E2000
|
Size: |
12288
|
|
7FF5BEA37000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2678834689.00007FF5BEA37000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BEA37000
|
Size: |
16384
|
|
8009000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2660502059.0000000008009000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8009000
|
Size: |
28672
|
|
9D37000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2071685840.0000000009D37000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9D37000
|
Size: |
98304
|
|
7FF5BE1DE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2670875139.00007FF5BE1DE000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE1DE000
|
Size: |
20480
|
|
7FF5BE616000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2673321801.00007FF5BE616000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE616000
|
Size: |
4096
|
|
B7B0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2666344763.000000000B7B0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B7B0000
|
Size: |
8192
|
|
CEF8000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2668834654.000000000CEF8000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CEF8000
|
Size: |
12288
|
|
7FF5BEA1F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2678834689.00007FF5BEA1F000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BEA1F000
|
Size: |
16384
|
|
7FF5BE8BE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2676921983.00007FF5BE8BE000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE8BE000
|
Size: |
4096
|
|
7FF5BE3D2000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2671283910.00007FF5BE3D2000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE3D2000
|
Size: |
4096
|
|
7890000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658612696.0000000007890000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7890000
|
Size: |
4096
|
|
1490000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1644030200.0000000001490000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1490000
|
Size: |
32768
|
|
B1F1000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1530341065.000000000B1F1000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
B1F1000
|
Size: |
131072
|
|
D008000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2071644301.000000000D008000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D008000
|
Size: |
335872
|
|
7FF5BE69A000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2673940238.00007FF5BE69A000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE69A000
|
Size: |
4096
|
|
9ADA000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2072108638.0000000009ADA000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9ADA000
|
Size: |
69632
|
|
CC6F000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1535163726.000000000CC6F000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CC6F000
|
Size: |
24576
|
|
CE95000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2668671033.000000000CE95000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CE95000
|
Size: |
16384
|
|
7FF5BEA59000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2679518718.00007FF5BEA59000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BEA59000
|
Size: |
24576
|
|
4E70000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658161825.0000000004E70000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4E70000
|
Size: |
4096
|
|
22D201F3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1351871889.0000022D201F3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D201F3000
|
Size: |
57344
|
|
CB7B000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2667015077.000000000CB7B000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB7B000
|
Size: |
4096
|
|
7FF5BE6A1000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2673972924.00007FF5BE6A1000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE6A1000
|
Size: |
4096
|
|
7FF5BE501000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2672585120.00007FF5BE501000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE501000
|
Size: |
4096
|
|
7A64000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1519605877.0000000007A64000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A64000
|
Size: |
4096
|
|
22D2023D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1351745113.0000022D2023D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D2023D000
|
Size: |
16384
|
|
7FF5BE65C000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1541162048.00007FF5BE65C000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE65C000
|
Size: |
4096
|
|
CEFC000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2668834654.000000000CEFC000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CEFC000
|
Size: |
110592
|
|
7A74000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1519605877.0000000007A74000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A74000
|
Size: |
12288
|
|
D11B000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1536456695.000000000D11B000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D11B000
|
Size: |
98304
|
|
1A6003F5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1815974500.000001A6003F5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1A6003F5000
|
Size: |
81920
|
|
1A600118000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1815974500.000001A600118000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1A600118000
|
Size: |
8192
|
|
22D201DD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1353244519.0000022D201DD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D201DD000
|
Size: |
20480
|
|
D6B1000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1536868644.000000000D6B1000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D6B1000
|
Size: |
24576
|
|
7FF5BE3F9000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2671437693.00007FF5BE3F9000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE3F9000
|
Size: |
4096
|
|
1630000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1516568048.0000000001630000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1630000
|
Size: |
12288
|
|
9AC2000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1523845606.0000000009AC2000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9AC2000
|
Size: |
12288
|
|
7FF5BE943000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2677714391.00007FF5BE943000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE943000
|
Size: |
4096
|
|
7FF5BE6D0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2674322359.00007FF5BE6D0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE6D0000
|
Size: |
8192
|
|
398C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2656227759.000000000398C000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
398C000
|
Size: |
12288
|
|
7FF5BEA3D000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2679309701.00007FF5BEA3D000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BEA3D000
|
Size: |
8192
|
|
1695000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1516652763.0000000001695000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1695000
|
Size: |
40960
|
|
8DF8000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1522633582.0000000008DF8000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8DF8000
|
Size: |
32768
|
|
1A600162000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1815974500.000001A600162000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1A600162000
|
Size: |
602112
|
|
7FF5BEA40000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1548614411.00007FF5BEA40000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BEA40000
|
Size: |
12288
|
|
E30000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.2654921353.0000000000E30000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
E30000
|
Size: |
49152
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3490000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1517289517.0000000003490000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3490000
|
Size: |
8192
|
|
22D200B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1353045762.0000022D200B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D200B0000
|
Size: |
4096
|
|
2B59DF80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1517322004.000002B59DF80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B59DF80000
|
Size: |
335872
|
|
7FF5BE64A000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2673436668.00007FF5BE64A000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE64A000
|
Size: |
4096
|
|
7FF5BE91F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1544987780.00007FF5BE91F000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE91F000
|
Size: |
4096
|
|
CB87000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2667015077.000000000CB87000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB87000
|
Size: |
4096
|
|
9ACE000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2662764839.0000000009ACE000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9ACE000
|
Size: |
4096
|
|
7FF5BE985000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2678152683.00007FF5BE985000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE985000
|
Size: |
8192
|
|
7FF5BE1C0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2670875139.00007FF5BE1C0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE1C0000
|
Size: |
28672
|
|
9C06000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1523845606.0000000009C06000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9C06000
|
Size: |
12288
|
|
7A56000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1519605877.0000000007A56000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A56000
|
Size: |
4096
|
|
22D201D1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1352726040.0000022D201D1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D201D1000
|
Size: |
24576
|
|
2F3E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1641394929.0000000002F3E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F3E000
|
Size: |
24576
|
|
7FF5BE685000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1541197242.00007FF5BE685000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE685000
|
Size: |
4096
|
|
CB7B000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1533280630.000000000CB7B000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB7B000
|
Size: |
4096
|
|
CB73000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2667015077.000000000CB73000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB73000
|
Size: |
4096
|
|
D134000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1536456695.000000000D134000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D134000
|
Size: |
69632
|
|
7FF5BE9B3000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2678413300.00007FF5BE9B3000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE9B3000
|
Size: |
4096
|
|
A233000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1526664009.000000000A233000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
A233000
|
Size: |
20480
|
|
AA29000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1528246779.000000000AA29000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AA29000
|
Size: |
12288
|
|
1A60040B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1815974500.000001A60040B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1A60040B000
|
Size: |
86016
|
|
AA90000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2664786423.000000000AA90000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AA90000
|
Size: |
4096
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1643817385.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|
9016000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2662276120.0000000009016000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9016000
|
Size: |
139264
|
|
CF17000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2071160029.000000000CF17000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CF17000
|
Size: |
40960
|
|
14DD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1644030200.00000000014DD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14DD000
|
Size: |
8192
|
|
2F40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1641610165.0000000002F40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F40000
|
Size: |
40960
|
|
D6C2000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2073478423.000000000D6C2000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D6C2000
|
Size: |
12288
|
|
10D54000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1537541955.0000000010D54000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
10D54000
|
Size: |
229376
|
|
7ADF000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658707759.0000000007ADF000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7ADF000
|
Size: |
45056
|
|
4DCC000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1518362137.0000000004DCC000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4DCC000
|
Size: |
4096
|
|
1A67CF10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1861287764.000001A67CF10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A67CF10000
|
Size: |
28672
|
|
7FFC3C830000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1868379811.00007FFC3C830000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFC3C830000
|
Size: |
65536
|
|
4D68000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2657432976.0000000004D68000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4D68000
|
Size: |
12288
|
|
7DF4C9800000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1538031185.00007DF4C9800000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7DF4C9800000
|
Size: |
4096
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1713923510.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|
AB2D000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2664786423.000000000AB2D000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AB2D000
|
Size: |
4096
|
|
CCBC000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1535163726.000000000CCBC000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CCBC000
|
Size: |
4096
|
|
F3E9000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.2669496536.000000000F3E9000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
F3E9000
|
Size: |
4096
|
|
61A3FFF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1815240255.00000061A3FFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
61A3FFF000
|
Size: |
4096
|
|
7FF5BE937000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2677524587.00007FF5BE937000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE937000
|
Size: |
4096
|
|
CF36000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2071160029.000000000CF36000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CF36000
|
Size: |
2084864
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
A5EE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1527438395.000000000A5EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
A5EE000
|
Size: |
8192
|
|
2F2CBFF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1352936003.0000002F2CBFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2F2CBFF000
|
Size: |
4096
|
|
C934BB8000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1516129583.000000C934BB8000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C934BB8000
|
Size: |
32768
|
|
7FF5BE9E8000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1547974039.00007FF5BE9E8000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE9E8000
|
Size: |
12288
|
|
7FF5BE932000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2677384257.00007FF5BE932000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE932000
|
Size: |
8192
|
|
22D20195000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1353188725.0000022D20195000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D20195000
|
Size: |
40960
|
|
1A67CFE7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1863818697.000001A67CFE7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A67CFE7000
|
Size: |
163840
|
|
7FF5BE4A7000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2672145425.00007FF5BE4A7000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE4A7000
|
Size: |
12288
|
|
4DD3000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2657432976.0000000004DD3000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4DD3000
|
Size: |
208896
|
|
22D201B7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1353188725.0000022D201B7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D201B7000
|
Size: |
16384
|
|
AB52000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1528246779.000000000AB52000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AB52000
|
Size: |
4096
|
|
7AA2000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658707759.0000000007AA2000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7AA2000
|
Size: |
147456
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1713897843.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|
7FF5BE9F2000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1547974039.00007FF5BE9F2000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE9F2000
|
Size: |
32768
|
|
7A58000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658707759.0000000007A58000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A58000
|
Size: |
4096
|
|
7FF5BE5E2000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1540552375.00007FF5BE5E2000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE5E2000
|
Size: |
4096
|
|
7FFC3C7CA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1867274988.00007FFC3C7CA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFC3C7CA000
|
Size: |
24576
|
|
7FF5BE9C9000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1547479090.00007FF5BE9C9000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE9C9000
|
Size: |
12288
|
|
D6B2000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2669310032.000000000D6B2000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D6B2000
|
Size: |
8192
|
|
7FF5BE5E2000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2673243422.00007FF5BE5E2000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE5E2000
|
Size: |
4096
|
|
F2A5000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.2669389039.000000000F2A5000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
F2A5000
|
Size: |
4096
|
|
CB0B000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1533280630.000000000CB0B000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB0B000
|
Size: |
221184
|
|
349E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2655698805.000000000349E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
349E000
|
Size: |
8192
|
|
A650000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1527640419.000000000A650000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
A650000
|
Size: |
20480
|
|
7FF5BE6D5000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2674322359.00007FF5BE6D5000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE6D5000
|
Size: |
12288
|
|
CDEC000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2073074163.000000000CDEC000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CDEC000
|
Size: |
126976
|
|
2F30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2655145082.0000000002F30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F30000
|
Size: |
32768
|
|
2EF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1918774521.0000000002EF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EF0000
|
Size: |
147456
|
|
10C93000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1537541955.0000000010C93000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
10C93000
|
Size: |
217088
|
|
7FF5BE9BB000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2678476280.00007FF5BE9BB000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE9BB000
|
Size: |
4096
|
|
A8CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1528047879.000000000A8CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
A8CE000
|
Size: |
8192
|
|
7FFC3C870000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1869544397.00007FFC3C870000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFC3C870000
|
Size: |
65536
|
|
D6C2000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1536938353.000000000D6C2000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D6C2000
|
Size: |
12288
|
|
16A0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2655237901.00000000016A0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
16A0000
|
Size: |
36864
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1644537178.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|
133E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1643715080.000000000133E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
133E000
|
Size: |
8192
|
|
22D20150000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1353123974.0000022D20150000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D20150000
|
Size: |
32768
|
|
7FF5BE77B000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2675098936.00007FF5BE77B000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE77B000
|
Size: |
12288
|
|
9950000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1523527435.0000000009950000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9950000
|
Size: |
4096
|
|
1A67C9E7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1860930525.000001A67C9E7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A67C9E7000
|
Size: |
12288
|
|
7A4C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1519605877.0000000007A4C000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A4C000
|
Size: |
20480
|
|
A630000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2664458388.000000000A630000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
A630000
|
Size: |
16384
|
|
7FF5BE761000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2674900947.00007FF5BE761000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE761000
|
Size: |
20480
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1713941492.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|
1A67C917000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1860718864.000001A67C917000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
1A67C917000
|
Size: |
4096
|
|
3491000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1643019869.0000000003491000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3491000
|
Size: |
24576
|
|
2B59E026000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1517506397.000002B59E026000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B59E026000
|
Size: |
163840
|
|
7FF5BE1C0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1538299156.00007FF5BE1C0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE1C0000
|
Size: |
28672
|
|
CE60000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1535163726.000000000CE60000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CE60000
|
Size: |
24576
|
|
CE9E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2668671033.000000000CE9E000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CE9E000
|
Size: |
20480
|
|
2B59E486000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1517714752.000002B59E486000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B59E486000
|
Size: |
8192
|
|
78C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1645772576.000000000078C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
78C000
|
Size: |
24576
|
|
7FF5BE5D8000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2673182237.00007FF5BE5D8000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE5D8000
|
Size: |
4096
|
|
D072000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2072954364.000000000D072000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D072000
|
Size: |
585728
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1A60008A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1815974500.000001A60008A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1A60008A000
|
Size: |
503808
|
|
7FF5BE903000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2677023133.00007FF5BE903000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE903000
|
Size: |
4096
|
|
C93477E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1515958726.000000C93477E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C93477E000
|
Size: |
8192
|
|
5700000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000007.00000000.1519107956.0000000005700000.00000008.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
5700000
|
Size: |
286720
|
|
7FF5BEA4D000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1548677395.00007FF5BEA4D000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BEA4D000
|
Size: |
4096
|
|
A630000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1527538354.000000000A630000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
A630000
|
Size: |
16384
|
|
8A60000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2661830719.0000000008A60000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8A60000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1A60010C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1815974500.000001A60010C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1A60010C000
|
Size: |
16384
|
|
826E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2660773033.000000000826E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
826E000
|
Size: |
8192
|
|
7FF5BE687000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2673712556.00007FF5BE687000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE687000
|
Size: |
4096
|
|
7FF5BE1B7000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2670846950.00007FF5BE1B7000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE1B7000
|
Size: |
4096
|
|
7FF5BE973000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1545869743.00007FF5BE973000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE973000
|
Size: |
4096
|
|
2B59C59A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1516637066.000002B59C59A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B59C59A000
|
Size: |
196608
|
|
7C1D000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2072408044.0000000007C1D000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7C1D000
|
Size: |
73728
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
3857000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1517588405.0000000003857000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3857000
|
Size: |
36864
|
|
7FF5BE873000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1543808531.00007FF5BE873000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE873000
|
Size: |
8192
|
|
CB6D000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1533280630.000000000CB6D000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB6D000
|
Size: |
4096
|
|
7FF5BEA32000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2678834689.00007FF5BEA32000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BEA32000
|
Size: |
8192
|
|
7FF5BE9DC000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2678598725.00007FF5BE9DC000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE9DC000
|
Size: |
16384
|
|
7FF5BE481000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2671936172.00007FF5BE481000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE481000
|
Size: |
57344
|
|
7FF5BE729000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1542082234.00007FF5BE729000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE729000
|
Size: |
8192
|
|
7A6C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658707759.0000000007A6C000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A6C000
|
Size: |
4096
|
|
7FF5BE51D000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2672675526.00007FF5BE51D000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE51D000
|
Size: |
20480
|
|
3420000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1643019869.0000000003420000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3420000
|
Size: |
458752
|
|
AA75000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2664786423.000000000AA75000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AA75000
|
Size: |
12288
|
|
A33A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1526831893.000000000A33A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
A33A000
|
Size: |
24576
|
|
7FF5BE975000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2677755689.00007FF5BE975000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE975000
|
Size: |
4096
|
|
1A67B030000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1859966460.000001A67B030000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1A67B030000
|
Size: |
4096
|
|
9AC6000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2072108638.0000000009AC6000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9AC6000
|
Size: |
16384
|
|
7F50000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1521414167.0000000007F50000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7F50000
|
Size: |
8192
|
|
61A463E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1815796705.00000061A463E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
61A463E000
|
Size: |
8192
|
|
7FF5BE4C3000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2672170388.00007FF5BE4C3000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE4C3000
|
Size: |
8192
|
|
22D20201000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1351836513.0000022D20201000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D20201000
|
Size: |
155648
|
|
B7A0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1531281141.000000000B7A0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B7A0000
|
Size: |
8192
|
|
9C20000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1523845606.0000000009C20000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9C20000
|
Size: |
4096
|
|
7FF5BE79A000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2675269011.00007FF5BE79A000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE79A000
|
Size: |
114688
|
|
7FF5BE457000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1539169344.00007FF5BE457000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE457000
|
Size: |
28672
|
|
AB5E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1528246779.000000000AB5E000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AB5E000
|
Size: |
4096
|
|
CBCA000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2667669675.000000000CBCA000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CBCA000
|
Size: |
73728
|
|
7FF5BE6E3000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1541885249.00007FF5BE6E3000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE6E3000
|
Size: |
8192
|
|
B1F1000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2665962094.000000000B1F1000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
B1F1000
|
Size: |
53248
|
|
7FF5BE939000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2677524587.00007FF5BE939000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE939000
|
Size: |
8192
|
|
10D54000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2669741529.0000000010D54000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
10D54000
|
Size: |
229376
|
|
3251000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.2655458567.0000000003251000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
3251000
|
Size: |
4096
|
|
2B59E091000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1517714752.000002B59E091000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B59E091000
|
Size: |
462848
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
9AC6000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2662764839.0000000009AC6000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9AC6000
|
Size: |
16384
|
|
AA79000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1528246779.000000000AA79000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AA79000
|
Size: |
4096
|
|
D154000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2669098163.000000000D154000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D154000
|
Size: |
4096
|
|
7A5A000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1519605877.0000000007A5A000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A5A000
|
Size: |
4096
|
|
C934DBE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1516205741.000000C934DBE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C934DBE000
|
Size: |
8192
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1644771626.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|
CB00000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1533280630.000000000CB00000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB00000
|
Size: |
40960
|
|
1A600114000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1815974500.000001A600114000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1A600114000
|
Size: |
12288
|
|
9083000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1522843899.0000000009083000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9083000
|
Size: |
20480
|
|
7FF5BE6D5000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1541885249.00007FF5BE6D5000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE6D5000
|
Size: |
12288
|
|
9CE2000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2662764839.0000000009CE2000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9CE2000
|
Size: |
16384
|
|
CB42000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1533280630.000000000CB42000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB42000
|
Size: |
53248
|
|
7FF5BE61A000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2673321801.00007FF5BE61A000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE61A000
|
Size: |
8192
|
|
AA08000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1528246779.000000000AA08000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AA08000
|
Size: |
12288
|
|
D680000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1536868644.000000000D680000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D680000
|
Size: |
184320
|
|
22D201DC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1352467182.0000022D201DC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D201DC000
|
Size: |
24576
|
|
39EF000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2656472532.00000000039EF000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
39EF000
|
Size: |
69632
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7FF5BE501000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1540045277.00007FF5BE501000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE501000
|
Size: |
4096
|
|
7FF5BE64E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1540797059.00007FF5BE64E000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE64E000
|
Size: |
4096
|
|
7FF5BE5F9000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2673290460.00007FF5BE5F9000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE5F9000
|
Size: |
12288
|
|
AA8E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1528246779.000000000AA8E000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AA8E000
|
Size: |
4096
|
|
7AC8000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658707759.0000000007AC8000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7AC8000
|
Size: |
86016
|
|
7FF5BE9E5000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2678834689.00007FF5BE9E5000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE9E5000
|
Size: |
8192
|
|
4E70000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1518918747.0000000004E70000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4E70000
|
Size: |
4096
|
|
61A40FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1815363949.00000061A40FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
61A40FE000
|
Size: |
8192
|
|
22D201CE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1353244519.0000022D201CE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D201CE000
|
Size: |
12288
|
|
7FF5BE415000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2671469084.00007FF5BE415000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE415000
|
Size: |
4096
|
|
7FF5BEA66000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2679518718.00007FF5BEA66000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BEA66000
|
Size: |
36864
|
|
32F3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1643019869.00000000032F3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32F3000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
22D20129000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1352789617.0000022D20129000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D20129000
|
Size: |
24576
|
|
1670000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1516625472.0000000001670000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1670000
|
Size: |
4096
|
|
FC0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1516223401.0000000000FC0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
FC0000
|
Size: |
4096
|
|
9B06000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1523845606.0000000009B06000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9B06000
|
Size: |
122880
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1714049992.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|
2B59E055000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1517506397.000002B59E055000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B59E055000
|
Size: |
126976
|
|
22D201C6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1352202034.0000022D201C6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D201C6000
|
Size: |
86016
|
|
9DFA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2663714060.0000000009DFA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9DFA000
|
Size: |
20480
|
|
3175000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2655340409.0000000003175000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3175000
|
Size: |
4096
|
|
7FF5BE4D1000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1539699249.00007FF5BE4D1000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE4D1000
|
Size: |
16384
|
|
1A60011B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1815974500.000001A60011B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1A60011B000
|
Size: |
8192
|
|
7FF5BE7D2000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2675384107.00007FF5BE7D2000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE7D2000
|
Size: |
20480
|
|
7FF5BE3E8000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1538801463.00007FF5BE3E8000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE3E8000
|
Size: |
4096
|
|
4DB9000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1518362137.0000000004DB9000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4DB9000
|
Size: |
12288
|
|
7FF5BE0CC000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1538154486.00007FF5BE0CC000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE0CC000
|
Size: |
4096
|
|
22D20090000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1353030655.0000022D20090000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D20090000
|
Size: |
8192
|
|
CD3D000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2667669675.000000000CD3D000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CD3D000
|
Size: |
4096
|
|
CE95000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1535163726.000000000CE95000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CE95000
|
Size: |
16384
|
|
7FF5BE697000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2673807112.00007FF5BE697000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE697000
|
Size: |
4096
|
|
7FF5BE9C0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1547231379.00007FF5BE9C0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE9C0000
|
Size: |
12288
|
|
7AC5000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2072664500.0000000007AC5000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7AC5000
|
Size: |
98304
|
|
7BAE000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2072408044.0000000007BAE000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7BAE000
|
Size: |
450560
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
7FF5BE1B7000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1538227918.00007FF5BE1B7000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE1B7000
|
Size: |
4096
|
|
7FF5BE891000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2676601895.00007FF5BE891000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE891000
|
Size: |
8192
|
|
39C0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2656227759.00000000039C0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
39C0000
|
Size: |
57344
|
|
22D2012C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1348738978.0000022D2012C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D2012C000
|
Size: |
12288
|
|
A3C0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2664119438.000000000A3C0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
A3C0000
|
Size: |
32768
|
|
7FF5BE290000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2670985990.00007FF5BE290000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE290000
|
Size: |
28672
|
|
7FF5BE498000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2671936172.00007FF5BE498000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE498000
|
Size: |
36864
|
|
7FF5BEA12000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2678834689.00007FF5BEA12000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BEA12000
|
Size: |
20480
|
|
7FF5BE3D2000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1538711515.00007FF5BE3D2000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE3D2000
|
Size: |
4096
|
|
1A67B040000
|
heap
|
page readonly
|
|
|
|
Name: |
00000001.00000002.1860005883.000001A67B040000.00000002.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page readonly
|
Base address: |
1A67B040000
|
Size: |
4096
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1643898703.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|
14C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1644030200.00000000014C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14C1000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
CE18000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2668365476.000000000CE18000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CE18000
|
Size: |
290816
|
|
7FF5BE68A000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2673775784.00007FF5BE68A000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE68A000
|
Size: |
24576
|
|
1600000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1516543070.0000000001600000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1600000
|
Size: |
8192
|
|
7D70000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2660216944.0000000007D70000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7D70000
|
Size: |
4096
|
|
2F2CFFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1352983556.0000002F2CFFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2F2CFFE000
|
Size: |
8192
|
|
F220000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.2669389039.000000000F220000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
F220000
|
Size: |
282624
|
|
13CA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2072475598.00000000013CA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13CA000
|
Size: |
61440
|
|
7DF4C9800000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2670637337.00007DF4C9800000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7DF4C9800000
|
Size: |
4096
|
|
8BFF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2661993435.0000000008BFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8BFF000
|
Size: |
4096
|
|
9C28000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1523845606.0000000009C28000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9C28000
|
Size: |
741376
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
7FF5BE432000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2671523951.00007FF5BE432000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE432000
|
Size: |
32768
|
|
1A6006B8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1815974500.000001A6006B8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1A6006B8000
|
Size: |
45056
|
|
B140000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1530341065.000000000B140000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
B140000
|
Size: |
4096
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1644597125.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|
22D201F3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1353244519.0000022D201F3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D201F3000
|
Size: |
57344
|
|
1A610011000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1850110008.000001A610011000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1A610011000
|
Size: |
385024
|
|
1600000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2655016041.0000000001600000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1600000
|
Size: |
8192
|
|
7FF5BE0E3000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1538175015.00007FF5BE0E3000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE0E3000
|
Size: |
8192
|
|
22D20178000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1352545123.0000022D20178000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D20178000
|
Size: |
212992
|
|
7FF5BE7E6000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1542644503.00007FF5BE7E6000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE7E6000
|
Size: |
4096
|
|
7A58000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1519605877.0000000007A58000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A58000
|
Size: |
4096
|
|
7F42000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2660388130.0000000007F42000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7F42000
|
Size: |
49152
|
|
7FF5BE51A000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1540156553.00007FF5BE51A000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE51A000
|
Size: |
8192
|
|
7FF5BE838000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1543460875.00007FF5BE838000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE838000
|
Size: |
4096
|
|
CB85000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2667015077.000000000CB85000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB85000
|
Size: |
4096
|
|
1460000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1643918310.0000000001460000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1460000
|
Size: |
8192
|
|
D6B4000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2073459067.000000000D6B4000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D6B4000
|
Size: |
12288
|
|
7FF5BE417000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2671523951.00007FF5BE417000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE417000
|
Size: |
16384
|
|
7FFC3C6C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1866440614.00007FFC3C6C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFC3C6C0000
|
Size: |
4096
|
|
10FC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1643046963.00000000010FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
10FC000
|
Size: |
16384
|
|
9C1D000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1523845606.0000000009C1D000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9C1D000
|
Size: |
8192
|
|
2E40000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2655374503.0000000002E40000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2E40000
|
Size: |
8192
|
|
4E9A000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1518972039.0000000004E9A000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4E9A000
|
Size: |
12288
|
|
780000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1645772576.0000000000780000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
780000
|
Size: |
40960
|
|
9DF2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1526477819.0000000009DF2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9DF2000
|
Size: |
24576
|
|
CB50000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1533280630.000000000CB50000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB50000
|
Size: |
8192
|
|
7A4C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658707759.0000000007A4C000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A4C000
|
Size: |
20480
|
|
7FF5BE744000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1542367691.00007FF5BE744000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE744000
|
Size: |
57344
|
|
3986000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1517673112.0000000003986000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3986000
|
Size: |
12288
|
|
22D201DC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1352404694.0000022D201DC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D201DC000
|
Size: |
24576
|
|
7FF5BE1C9000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1538299156.00007FF5BE1C9000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE1C9000
|
Size: |
36864
|
|
8199000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1521668760.0000000008199000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8199000
|
Size: |
28672
|
|
7FF5BE9A3000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2678308058.00007FF5BE9A3000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE9A3000
|
Size: |
8192
|
|
22D21ED6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1348779216.0000022D21ED6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D21ED6000
|
Size: |
20480
|
|
2E50000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.2655013115.0000000002E50000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
2E50000
|
Size: |
65536
|
|
7FFC3C7D0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1867605493.00007FFC3C7D0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7FFC3C7D0000
|
Size: |
16384
|
|
93B8000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2662448075.00000000093B8000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
93B8000
|
Size: |
32768
|
|
8030000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2660586552.0000000008030000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8030000
|
Size: |
49152
|
|
AA3C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2664786423.000000000AA3C000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AA3C000
|
Size: |
4096
|
|
7FF5BE94B000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2677755689.00007FF5BE94B000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE94B000
|
Size: |
32768
|
|
9C0B000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2662764839.0000000009C0B000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9C0B000
|
Size: |
69632
|
|
A640000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1527561857.000000000A640000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
A640000
|
Size: |
4096
|
|
35C9000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1517355859.00000000035C9000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
35C9000
|
Size: |
28672
|
|
7FF5BE4AB000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2672170388.00007FF5BE4AB000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE4AB000
|
Size: |
36864
|
|
CEA7000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2668671033.000000000CEA7000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CEA7000
|
Size: |
8192
|
|
A650000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2664574538.000000000A650000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
A650000
|
Size: |
20480
|
|
7DF4C97E1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000007.00000002.2670550516.00007DF4C97E1000.00000020.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7DF4C97E1000
|
Size: |
4096
|
|
9952000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1523527435.0000000009952000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9952000
|
Size: |
8192
|
|
7FF5BE0E3000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2670793564.00007FF5BE0E3000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE0E3000
|
Size: |
8192
|
|
2B5A115F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1517714752.000002B5A115F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B5A115F000
|
Size: |
10485760
|
|
5F70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2179813764.0000000005F70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F70000
|
Size: |
139264
|
|
8081000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2660618412.0000000008081000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
8081000
|
Size: |
200704
|
|
A540000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2664209262.000000000A540000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
A540000
|
Size: |
4096
|
|
7FF5BE45F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1539169344.00007FF5BE45F000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE45F000
|
Size: |
53248
|
|
1529000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2654974554.0000000001529000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1529000
|
Size: |
28672
|
|
AB6A000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1528246779.000000000AB6A000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AB6A000
|
Size: |
16384
|
|
8030000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1521565516.0000000008030000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8030000
|
Size: |
49152
|
|
C934AB6000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1516088337.000000C934AB6000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C934AB6000
|
Size: |
40960
|
|
CB77000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2667015077.000000000CB77000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB77000
|
Size: |
4096
|
|
CB75000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2667015077.000000000CB75000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB75000
|
Size: |
4096
|
|
F266000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.2669389039.000000000F266000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
F266000
|
Size: |
4096
|
|
7FF5BE422000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1538901587.00007FF5BE422000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE422000
|
Size: |
12288
|
|
D37C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2669223696.000000000D37C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
D37C000
|
Size: |
16384
|
|
DF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1643587634.0000000000DF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
DF0000
|
Size: |
167936
|
|
1A610001000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1850110008.000001A610001000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1A610001000
|
Size: |
57344
|
|
4DCC000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2657432976.0000000004DCC000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4DCC000
|
Size: |
4096
|
|
7FF5BE773000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1542476246.00007FF5BE773000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE773000
|
Size: |
12288
|
|
7FF5BE8F6000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1544788017.00007FF5BE8F6000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE8F6000
|
Size: |
12288
|
|
22D201E3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1352513444.0000022D201E3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D201E3000
|
Size: |
49152
|
|
7FF5BE5D2000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1540475440.00007FF5BE5D2000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE5D2000
|
Size: |
4096
|
|
918D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1522917616.000000000918D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
918D000
|
Size: |
12288
|
|
7FF5BE646000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2673436668.00007FF5BE646000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE646000
|
Size: |
4096
|
|
BB2C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1532478553.000000000BB2C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BB2C000
|
Size: |
16384
|
|
7A7C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658707759.0000000007A7C000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A7C000
|
Size: |
12288
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1714030933.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|
83FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2660857414.00000000083FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
83FE000
|
Size: |
8192
|
|
7FF5BE481000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1539238170.00007FF5BE481000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE481000
|
Size: |
57344
|
|
CEA7000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1535163726.000000000CEA7000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CEA7000
|
Size: |
8192
|
|
7FF5BE93E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2677631401.00007FF5BE93E000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE93E000
|
Size: |
8192
|
|
C93590D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1516329064.000000C93590D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C93590D000
|
Size: |
12288
|
|
7FF5BE426000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2671523951.00007FF5BE426000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE426000
|
Size: |
32768
|
|
CBEB000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1535163726.000000000CBEB000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CBEB000
|
Size: |
503808
|
|
A3BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1526915695.000000000A3BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
A3BE000
|
Size: |
8192
|
|
7FF5BE7D2000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1542644503.00007FF5BE7D2000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE7D2000
|
Size: |
20480
|
|
A3C0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1527008970.000000000A3C0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
A3C0000
|
Size: |
32768
|
|
E49000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.2654921353.0000000000E49000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
E49000
|
Size: |
8192
|
|
7FFC3C840000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1868648968.00007FFC3C840000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFC3C840000
|
Size: |
65536
|
|
7FF5BEA1F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1547974039.00007FF5BEA1F000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BEA1F000
|
Size: |
16384
|
|
3049000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.1654119281.0000000003049000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
3049000
|
Size: |
8192
|
|
7FF5BE430000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2671523951.00007FF5BE430000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE430000
|
Size: |
4096
|
|
CB73000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1533280630.000000000CB73000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB73000
|
Size: |
4096
|
|
7B56000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658707759.0000000007B56000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7B56000
|
Size: |
303104
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4E50000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1518821857.0000000004E50000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4E50000
|
Size: |
4096
|
|
9996000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2072846978.0000000009996000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9996000
|
Size: |
311296
|
|
7FF5BE6C7000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1541849994.00007FF5BE6C7000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE6C7000
|
Size: |
12288
|
|
8B7F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2661915702.0000000008B7F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8B7F000
|
Size: |
4096
|
|
7FFC3C820000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1868108193.00007FFC3C820000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFC3C820000
|
Size: |
65536
|
|
C4EB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2666786372.000000000C4EB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C4EB000
|
Size: |
20480
|
|
7FF5BE495000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2671936172.00007FF5BE495000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE495000
|
Size: |
8192
|
|
7FF5BE715000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1542082234.00007FF5BE715000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE715000
|
Size: |
12288
|
|
8478000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2660924403.0000000008478000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8478000
|
Size: |
32768
|
|
301D000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.1653632772.000000000301D000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
301D000
|
Size: |
4096
|
|
363E000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.2655735535.000000000363E000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
363E000
|
Size: |
1220608
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
A84F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2664747659.000000000A84F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
A84F000
|
Size: |
4096
|
|
9AB1000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1523845606.0000000009AB1000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9AB1000
|
Size: |
8192
|
|
7F42000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1521365697.0000000007F42000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7F42000
|
Size: |
49152
|
|
7A62000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658707759.0000000007A62000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A62000
|
Size: |
4096
|
|
CDED000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2668365476.000000000CDED000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CDED000
|
Size: |
122880
|
|
D68C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2669253444.000000000D68C000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D68C000
|
Size: |
135168
|
|
7FF5BE1B0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1538227918.00007FF5BE1B0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE1B0000
|
Size: |
20480
|
|
8E7F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2662119352.0000000008E7F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8E7F000
|
Size: |
4096
|
|
7FF5BE9CD000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1547479090.00007FF5BE9CD000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE9CD000
|
Size: |
8192
|
|
7FF5BE4DE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2672383615.00007FF5BE4DE000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE4DE000
|
Size: |
4096
|
|
B8D0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1531652077.000000000B8D0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
B8D0000
|
Size: |
4096
|
|
7FF5BE33C000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2671124767.00007FF5BE33C000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE33C000
|
Size: |
4096
|
|
61A42BF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1815674769.00000061A42BF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
61A42BF000
|
Size: |
4096
|
|
7BFF000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2072617750.0000000007BFF000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7BFF000
|
Size: |
118784
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
B201000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2666107121.000000000B201000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
B201000
|
Size: |
40960
|
|
7FFC3C800000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1867773648.00007FFC3C800000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7FFC3C800000
|
Size: |
4096
|
|
7FF5BE71C000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2674497640.00007FF5BE71C000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE71C000
|
Size: |
4096
|
|
7A38000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658707759.0000000007A38000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A38000
|
Size: |
4096
|
|
1A67C990000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1860891556.000001A67C990000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A67C990000
|
Size: |
4096
|
|
7B56000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2072664500.0000000007B56000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7B56000
|
Size: |
303104
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4E80000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658190512.0000000004E80000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4E80000
|
Size: |
4096
|
|
2FE0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1517104772.0000000002FE0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2FE0000
|
Size: |
8192
|
|
BB2C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2666522159.000000000BB2C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BB2C000
|
Size: |
16384
|
|
D6C6000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2073378129.000000000D6C6000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D6C6000
|
Size: |
12288
|
|
7FF5BE6AE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1541611226.00007FF5BE6AE000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE6AE000
|
Size: |
8192
|
|
39BA000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1517673112.00000000039BA000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
39BA000
|
Size: |
4096
|
|
BE2A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2666730021.000000000BE2A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BE2A000
|
Size: |
24576
|
|
4E25000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1518362137.0000000004E25000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4E25000
|
Size: |
57344
|
|
9C22000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1523845606.0000000009C22000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9C22000
|
Size: |
4096
|
|
10D14000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1537541955.0000000010D14000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
10D14000
|
Size: |
229376
|
|
7A52000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658707759.0000000007A52000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A52000
|
Size: |
4096
|
|
7DF4C97E1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000007.00000000.1537944685.00007DF4C97E1000.00000020.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7DF4C97E1000
|
Size: |
4096
|
|
11D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1643136646.00000000011D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11D0000
|
Size: |
4096
|
|
4E3D000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1518362137.0000000004E3D000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4E3D000
|
Size: |
8192
|
|
7FF5BE397000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2671176818.00007FF5BE397000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE397000
|
Size: |
4096
|
|
7FF5BE4E3000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2672426694.00007FF5BE4E3000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE4E3000
|
Size: |
12288
|
|
7FF5BE47C000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1539238170.00007FF5BE47C000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE47C000
|
Size: |
16384
|
|
22D201C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1352310645.0000022D201C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D201C1000
|
Size: |
20480
|
|
7FF5BE876000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1543808531.00007FF5BE876000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE876000
|
Size: |
8192
|
|
1A67D030000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1865220821.000001A67D030000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A67D030000
|
Size: |
12288
|
|
AA8A000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2664786423.000000000AA8A000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AA8A000
|
Size: |
4096
|
|
22D21A90000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1353378252.0000022D21A90000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D21A90000
|
Size: |
4096
|
|
D87F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2669363067.000000000D87F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
D87F000
|
Size: |
4096
|
|
2F4A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1641584707.0000000002F4A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F4A000
|
Size: |
20480
|
|
12E9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2654770366.00000000012E9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12E9000
|
Size: |
921600
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
4D82000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1518362137.0000000004D82000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4D82000
|
Size: |
20480
|
|
4D7B000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1518362137.0000000004D7B000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4D7B000
|
Size: |
4096
|
|
99E5000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1523845606.00000000099E5000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
99E5000
|
Size: |
421888
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
7FF5BE891000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1544098397.00007FF5BE891000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE891000
|
Size: |
8192
|
|
7FF5BE969000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2677755689.00007FF5BE969000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE969000
|
Size: |
16384
|
|
97E0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2662547189.00000000097E0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
97E0000
|
Size: |
8192
|
|
22D20129000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1352294337.0000022D20129000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D20129000
|
Size: |
24576
|
|
CB77000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1533280630.000000000CB77000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB77000
|
Size: |
4096
|
|
2D4B000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.1645597367.0000000002D4B000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
2D4B000
|
Size: |
4096
|
|
C9347FA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1515976160.000000C9347FA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C9347FA000
|
Size: |
24576
|
|
5858000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1519187039.0000000005858000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5858000
|
Size: |
4096
|
|
2F2C7FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1352882828.0000002F2C7FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2F2C7FE000
|
Size: |
8192
|
|
7F70000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2660470574.0000000007F70000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7F70000
|
Size: |
4096
|
|
7B56000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1519605877.0000000007B56000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7B56000
|
Size: |
303104
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
8081000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1521599309.0000000008081000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
8081000
|
Size: |
200704
|
|
7FF5BE815000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2675776420.00007FF5BE815000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE815000
|
Size: |
4096
|
|
8BFF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1522551388.0000000008BFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8BFF000
|
Size: |
4096
|
|
C934B3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1516110240.000000C934B3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C934B3E000
|
Size: |
8192
|
|
C46B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1532869455.000000000C46B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C46B000
|
Size: |
20480
|
|
22D2019F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1352697967.0000022D2019F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D2019F000
|
Size: |
28672
|
|
7FF5BEA37000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1547974039.00007FF5BEA37000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BEA37000
|
Size: |
16384
|
|
CB91000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2667015077.000000000CB91000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB91000
|
Size: |
4096
|
|
61A41FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1815514399.00000061A41FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
61A41FE000
|
Size: |
8192
|
|
61A417E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1815451846.00000061A417E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
61A417E000
|
Size: |
8192
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1713975815.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|
A680000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2664682592.000000000A680000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A680000
|
Size: |
4096
|
|
9E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1645914185.00000000009E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9E0000
|
Size: |
4096
|
|
7FF5BE61F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1540599308.00007FF5BE61F000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE61F000
|
Size: |
32768
|
|
38D3000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1517616931.00000000038D3000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
38D3000
|
Size: |
53248
|
|
7A42000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1519605877.0000000007A42000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A42000
|
Size: |
4096
|
|
22D201C8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1352310645.0000022D201C8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D201C8000
|
Size: |
77824
|
|
C93497E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1516032575.000000C93497E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C93497E000
|
Size: |
8192
|
|
39AD000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1517673112.00000000039AD000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
39AD000
|
Size: |
4096
|
|
7FF5BE50D000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2672649151.00007FF5BE50D000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE50D000
|
Size: |
12288
|
|
7FF5BE4D1000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2672314608.00007FF5BE4D1000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE4D1000
|
Size: |
16384
|
|
7FF5BE8B4000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1544550008.00007FF5BE8B4000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE8B4000
|
Size: |
20480
|
|
A660000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1527731139.000000000A660000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
A660000
|
Size: |
20480
|
|
2B59E48B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1517714752.000002B59E48B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B59E48B000
|
Size: |
12288
|
|
397A000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1517673112.000000000397A000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
397A000
|
Size: |
45056
|
|
7BB1000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2660007184.0000000007BB1000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7BB1000
|
Size: |
36864
|
|
A560000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2664285013.000000000A560000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
A560000
|
Size: |
4096
|
|
7FF5BE565000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2672975862.00007FF5BE565000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE565000
|
Size: |
4096
|
|
7FF5BE8AB000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1544485913.00007FF5BE8AB000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE8AB000
|
Size: |
4096
|
|
1A67AD90000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1853921630.000001A67AD90000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A67AD90000
|
Size: |
4096
|
|
37E2000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.2655735535.00000000037E2000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
37E2000
|
Size: |
40960
|
|
7FF5BE91F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2677154451.00007FF5BE91F000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE91F000
|
Size: |
4096
|
|
2B5A2F5F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1517714752.000002B5A2F5F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B5A2F5F000
|
Size: |
10485760
|
|
7FF5BE426000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1538901587.00007FF5BE426000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE426000
|
Size: |
32768
|
|
7FF5BE478000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2671936172.00007FF5BE478000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE478000
|
Size: |
8192
|
|
7FF5BE51D000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1540156553.00007FF5BE51D000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE51D000
|
Size: |
20480
|
|
4E60000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658136963.0000000004E60000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4E60000
|
Size: |
4096
|
|
7A3A000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658707759.0000000007A3A000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A3A000
|
Size: |
8192
|
|
39A2000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2656227759.00000000039A2000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
39A2000
|
Size: |
24576
|
|
8F00000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2662175842.0000000008F00000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8F00000
|
Size: |
8192
|
|
8480000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2660975114.0000000008480000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
8480000
|
Size: |
5242880
|
|
7FF5BE4E7000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1539893603.00007FF5BE4E7000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE4E7000
|
Size: |
4096
|
|
CC79000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1535163726.000000000CC79000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CC79000
|
Size: |
4096
|
|
1A600106000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1815974500.000001A600106000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1A600106000
|
Size: |
8192
|
|
AB54000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1528246779.000000000AB54000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AB54000
|
Size: |
4096
|
|
B920000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1532234737.000000000B920000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
B920000
|
Size: |
4096
|
|
AB6A000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2664786423.000000000AB6A000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AB6A000
|
Size: |
16384
|
|
9AF0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1523845606.0000000009AF0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9AF0000
|
Size: |
77824
|
|
9CEC000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1523845606.0000000009CEC000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9CEC000
|
Size: |
299008
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2B59E080000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1517668361.000002B59E080000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B59E080000
|
Size: |
28672
|
|
8009000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1521512366.0000000008009000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8009000
|
Size: |
28672
|
|
7FF5BE687000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1541197242.00007FF5BE687000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE687000
|
Size: |
4096
|
|
7FF5BE4AB000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1539480547.00007FF5BE4AB000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE4AB000
|
Size: |
36864
|
|
7FFC3C850000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1868930700.00007FFC3C850000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFC3C850000
|
Size: |
65536
|
|
7A74000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658707759.0000000007A74000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A74000
|
Size: |
12288
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1643326580.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|
1630000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2655046056.0000000001630000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1630000
|
Size: |
12288
|
|
7FF5BE6A5000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1541580811.00007FF5BE6A5000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE6A5000
|
Size: |
8192
|
|
7A60000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1519605877.0000000007A60000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A60000
|
Size: |
4096
|
|
39BA000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2656227759.00000000039BA000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
39BA000
|
Size: |
4096
|
|
A9D8000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1528246779.000000000A9D8000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
A9D8000
|
Size: |
4096
|
|
12B0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1516304156.00000000012B0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
12B0000
|
Size: |
4096
|
|
7FF5BE8F6000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2677023133.00007FF5BE8F6000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE8F6000
|
Size: |
12288
|
|
A660000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2664633843.000000000A660000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
A660000
|
Size: |
20480
|
|
1A67AFD1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1856126504.000001A67AFD1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A67AFD1000
|
Size: |
4096
|
|
C7FF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2666930842.000000000C7FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C7FF000
|
Size: |
4096
|
|
CBE3000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1535163726.000000000CBE3000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CBE3000
|
Size: |
4096
|
|
2B59C590000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1516637066.000002B59C590000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B59C590000
|
Size: |
36864
|
|
7C1D000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2072617750.0000000007C1D000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7C1D000
|
Size: |
73728
|
|
2B59E493000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1517714752.000002B59E493000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B59E493000
|
Size: |
12288
|
|
9AF0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2662764839.0000000009AF0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9AF0000
|
Size: |
77824
|
|
7FF5BE989000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2678152683.00007FF5BE989000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE989000
|
Size: |
12288
|
|
CF27000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1536456695.000000000CF27000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CF27000
|
Size: |
4096
|
|
2F2CAFF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1352921130.0000002F2CAFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2F2CAFF000
|
Size: |
4096
|
|
7FF5BE7F7000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2675670013.00007FF5BE7F7000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE7F7000
|
Size: |
12288
|
|
7FF5BE4D6000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1539699249.00007FF5BE4D6000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE4D6000
|
Size: |
12288
|
|
A680000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1527863345.000000000A680000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A680000
|
Size: |
4096
|
|
CB8F000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2667015077.000000000CB8F000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB8F000
|
Size: |
4096
|
|
3771000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.2655735535.0000000003771000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3771000
|
Size: |
458752
|
|
7E80000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2660288575.0000000007E80000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7E80000
|
Size: |
4096
|
|
4D46000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2657432976.0000000004D46000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4D46000
|
Size: |
16384
|
|
B790000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1531160037.000000000B790000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
B790000
|
Size: |
4096
|
|
22D21EDB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1348690866.0000022D21EDB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D21EDB000
|
Size: |
16384
|
|
3780000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2655926492.0000000003780000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
3780000
|
Size: |
16384
|
|
9659000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2662479830.0000000009659000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9659000
|
Size: |
28672
|
|
57AA000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658430253.00000000057AA000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
57AA000
|
Size: |
4096
|
|
2EF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1766377154.0000000002EF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EF0000
|
Size: |
167936
|
|
9B25000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2072108638.0000000009B25000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9B25000
|
Size: |
139264
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
31B9000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.1656803800.00000000031B9000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
31B9000
|
Size: |
4096
|
|
C935A0C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1516380288.000000C935A0C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C935A0C000
|
Size: |
16384
|
|
22D2012D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1353109346.0000022D2012D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D2012D000
|
Size: |
8192
|
|
7FF5BE1C9000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2670875139.00007FF5BE1C9000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE1C9000
|
Size: |
36864
|
|
2B59C615000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1516637066.000002B59C615000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B59C615000
|
Size: |
4096
|
|
2B59E2B2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1517714752.000002B59E2B2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B59E2B2000
|
Size: |
1863680
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
7FF5BE0E7000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1538175015.00007FF5BE0E7000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE0E7000
|
Size: |
12288
|
|
7FF5BE514000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1540156553.00007FF5BE514000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE514000
|
Size: |
16384
|
|
CEFC000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1536456695.000000000CEFC000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CEFC000
|
Size: |
151552
|
|
BAAE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2666494275.000000000BAAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BAAE000
|
Size: |
8192
|
|
7BBA000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2073049803.0000000007BBA000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7BBA000
|
Size: |
118784
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1663357318.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|
1670000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2655143928.0000000001670000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1670000
|
Size: |
4096
|
|
CBAF000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2667669675.000000000CBAF000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CBAF000
|
Size: |
20480
|
|
7FF5BE943000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1545806788.00007FF5BE943000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE943000
|
Size: |
4096
|
|
CB68000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2667015077.000000000CB68000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB68000
|
Size: |
8192
|
|
A5EE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2664320415.000000000A5EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
A5EE000
|
Size: |
8192
|
|
7FF5BE77B000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1542523709.00007FF5BE77B000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE77B000
|
Size: |
12288
|
|
7FF5BE3CD000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1538711515.00007FF5BE3CD000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE3CD000
|
Size: |
12288
|
|
AA44000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2664786423.000000000AA44000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AA44000
|
Size: |
28672
|
|
1A67AF55000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1856126504.000001A67AF55000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A67AF55000
|
Size: |
20480
|
|
3240000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.2655458567.0000000003240000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
3240000
|
Size: |
65536
|
|
22D201D8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1353244519.0000022D201D8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D201D8000
|
Size: |
12288
|
|
CF27000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2071160029.000000000CF27000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CF27000
|
Size: |
4096
|
|
10CD6000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2669741529.0000000010CD6000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
10CD6000
|
Size: |
16384
|
|
D6C6000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1536938353.000000000D6C6000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D6C6000
|
Size: |
12288
|
|
99E5000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2662764839.00000000099E5000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
99E5000
|
Size: |
831488
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
7FF5BE523000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2672675526.00007FF5BE523000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE523000
|
Size: |
16384
|
|
7FF5BE779000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1542523709.00007FF5BE779000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE779000
|
Size: |
4096
|
|
7E90000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2660320547.0000000007E90000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7E90000
|
Size: |
4096
|
|
D6C2000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2073378129.000000000D6C2000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D6C2000
|
Size: |
12288
|
|
7FF5BE43B000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2671523951.00007FF5BE43B000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE43B000
|
Size: |
24576
|
|
38E0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1517648668.00000000038E0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
38E0000
|
Size: |
8192
|
|
9A4D000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2072108638.0000000009A4D000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9A4D000
|
Size: |
405504
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
7FF5BE87F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1543948687.00007FF5BE87F000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE87F000
|
Size: |
24576
|
|
7FFC3C614000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1866001568.00007FFC3C614000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFC3C614000
|
Size: |
36864
|
|
520000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1645673508.0000000000520000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
520000
|
Size: |
4096
|
|
2B59C690000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1517117627.000002B59C690000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
2B59C690000
|
Size: |
73728
|
|
7FF5BE3CA000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1538711515.00007FF5BE3CA000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE3CA000
|
Size: |
4096
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1643977189.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|
22D2012C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1352808392.0000022D2012C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D2012C000
|
Size: |
12288
|
|
CBEB000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2667669675.000000000CBEB000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CBEB000
|
Size: |
503808
|
|
7FF5BE6D3000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1541885249.00007FF5BE6D3000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE6D3000
|
Size: |
4096
|
|
7FF5BE8AB000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2676785728.00007FF5BE8AB000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE8AB000
|
Size: |
4096
|
|
22D20159000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1353123974.0000022D20159000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D20159000
|
Size: |
126976
|
|
10F8F000
|
system
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2670125824.0000000010F8F000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
10F8F000
|
Size: |
69632
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
CD08000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2667669675.000000000CD08000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CD08000
|
Size: |
4096
|
|
7F30000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2660356741.0000000007F30000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7F30000
|
Size: |
8192
|
|
D05A000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2071543503.000000000D05A000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D05A000
|
Size: |
684032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1644752236.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|
D160000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2071160029.000000000D160000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D160000
|
Size: |
8192
|
|
CD43000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1535163726.000000000CD43000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CD43000
|
Size: |
28672
|
|
CB91000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1533280630.000000000CB91000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB91000
|
Size: |
4096
|
|
1A67AF43000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1856126504.000001A67AF43000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A67AF43000
|
Size: |
4096
|
|
61A407C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1815283670.00000061A407C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
61A407C000
|
Size: |
16384
|
|
7FF5BE94B000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1545869743.00007FF5BE94B000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE94B000
|
Size: |
32768
|
|
7FF5BEA48000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1548677395.00007FF5BEA48000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BEA48000
|
Size: |
16384
|
|
7FF5BE3DF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2671373028.00007FF5BE3DF000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE3DF000
|
Size: |
28672
|
|
37C0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1517532658.00000000037C0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
37C0000
|
Size: |
4096
|
|
7FF5AACB4000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2670717908.00007FF5AACB4000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5AACB4000
|
Size: |
20480
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1714068014.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|
7A56000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658707759.0000000007A56000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A56000
|
Size: |
4096
|
|
9109000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2662357856.0000000009109000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9109000
|
Size: |
28672
|
|
322E000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.1656803800.000000000322E000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
322E000
|
Size: |
24576
|
|
4E25000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2657432976.0000000004E25000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4E25000
|
Size: |
57344
|
|
2B59E079000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1517633690.000002B59E079000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B59E079000
|
Size: |
24576
|
|
8480000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1521905649.0000000008480000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
8480000
|
Size: |
5242880
|
|
22D21EE2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1348690866.0000022D21EE2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D21EE2000
|
Size: |
53248
|
|
5F70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2071889703.0000000005F70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F70000
|
Size: |
143360
|
|
CEF0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1536456695.000000000CEF0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CEF0000
|
Size: |
28672
|
|
B8E0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1531833463.000000000B8E0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B8E0000
|
Size: |
8192
|
|
7FF5BE876000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2676454969.00007FF5BE876000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE876000
|
Size: |
8192
|
|
9B06000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2072108638.0000000009B06000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9B06000
|
Size: |
122880
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
7DF4C97F1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000007.00000000.1538009488.00007DF4C97F1000.00000020.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7DF4C97F1000
|
Size: |
4096
|
|
1A67C9E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1860930525.000001A67C9E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A67C9E0000
|
Size: |
16384
|
|
7FF5BE92F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2677384257.00007FF5BE92F000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE92F000
|
Size: |
8192
|
|
7FF5BE58E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1540385289.00007FF5BE58E000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE58E000
|
Size: |
57344
|
|
CB60000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2667015077.000000000CB60000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB60000
|
Size: |
16384
|
|
C60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2654771770.0000000000C60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C60000
|
Size: |
4096
|
|
C66A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1533008448.000000000C66A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C66A000
|
Size: |
24576
|
|
22D2018F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1352662505.0000022D2018F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D2018F000
|
Size: |
94208
|
|
A94E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1528153943.000000000A94E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
A94E000
|
Size: |
8192
|
|
7FF5BE9F2000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2678834689.00007FF5BE9F2000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE9F2000
|
Size: |
32768
|
|
CB7D000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2667015077.000000000CB7D000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB7D000
|
Size: |
4096
|
|
7DF4C97E0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2670523557.00007DF4C97E0000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7DF4C97E0000
|
Size: |
4096
|
|
7FF5BE6B1000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1541611226.00007FF5BE6B1000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE6B1000
|
Size: |
4096
|
|
F3EB000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.2669496536.000000000F3EB000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
F3EB000
|
Size: |
8192
|
|
7FF5BE55D000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2672946871.00007FF5BE55D000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE55D000
|
Size: |
8192
|
|
7FF5BE744000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2674816615.00007FF5BE744000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE744000
|
Size: |
57344
|
|
A107000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2663815422.000000000A107000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
A107000
|
Size: |
192512
|
|
7FF5BE895000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2676601895.00007FF5BE895000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE895000
|
Size: |
4096
|
|
9109000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1522893358.0000000009109000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9109000
|
Size: |
28672
|
|
7FF5BEA3D000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1548614411.00007FF5BEA3D000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BEA3D000
|
Size: |
8192
|
|
1A67AF3B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1856126504.000001A67AF3B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A67AF3B000
|
Size: |
12288
|
|
10CD6000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1537541955.0000000010CD6000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
10CD6000
|
Size: |
16384
|
|
13D9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2072388591.00000000013D9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13D9000
|
Size: |
24576
|
|
7FF5BE6C3000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2674234324.00007FF5BE6C3000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE6C3000
|
Size: |
8192
|
|
8D7D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1522609113.0000000008D7D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8D7D000
|
Size: |
12288
|
|
CE0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2654843310.0000000000CE0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE0000
|
Size: |
16384
|
|
7C1D000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2660117349.0000000007C1D000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7C1D000
|
Size: |
73728
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
CF36000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2668928714.000000000CF36000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CF36000
|
Size: |
860160
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
7FF5BE335000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1538559046.00007FF5BE335000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE335000
|
Size: |
24576
|
|
39AF000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1517673112.00000000039AF000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
39AF000
|
Size: |
4096
|
|
1A600109000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1815974500.000001A600109000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1A600109000
|
Size: |
8192
|
|
7FF5BE495000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1539238170.00007FF5BE495000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE495000
|
Size: |
8192
|
|
C93467E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1515924821.000000C93467E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C93467E000
|
Size: |
8192
|
|
7BBB000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2660047814.0000000007BBB000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7BBB000
|
Size: |
278528
|
|
2B59E075000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1517604526.000002B59E075000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B59E075000
|
Size: |
12288
|
|
B640000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2666171317.000000000B640000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B640000
|
Size: |
8192
|
|
7FF5BE697000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1541350455.00007FF5BE697000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE697000
|
Size: |
4096
|
|
2F3A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2655145082.0000000002F3A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F3A000
|
Size: |
40960
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1644792532.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|
7F50000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2660417733.0000000007F50000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7F50000
|
Size: |
8192
|
|
C20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2486535844.0000000000C20000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
C20000
|
Size: |
143360
|
|
7FF5BE9A3000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1546909167.00007FF5BE9A3000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE9A3000
|
Size: |
8192
|
|
8C7F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2662022340.0000000008C7F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8C7F000
|
Size: |
4096
|
|
7FF5BE9B3000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1547075301.00007FF5BE9B3000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE9B3000
|
Size: |
4096
|
|
5858000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658430253.0000000005858000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5858000
|
Size: |
4096
|
|
39AB000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1517673112.00000000039AB000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
39AB000
|
Size: |
4096
|
|
4D80000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2657432976.0000000004D80000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4D80000
|
Size: |
4096
|
|
7FF5AACAE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2670717908.00007FF5AACAE000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5AACAE000
|
Size: |
20480
|
|
D160000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2071451455.000000000D160000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D160000
|
Size: |
8192
|
|
7BA3000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1519605877.0000000007BA3000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7BA3000
|
Size: |
495616
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
33D8000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.1656803800.00000000033D8000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
33D8000
|
Size: |
16384
|
|
B5FD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2666138433.000000000B5FD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B5FD000
|
Size: |
12288
|
|
1A67CFB2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1863818697.000001A67CFB2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A67CFB2000
|
Size: |
73728
|
|
7FF5BE76B000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1542446382.00007FF5BE76B000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE76B000
|
Size: |
4096
|
|
2F49000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1641724109.0000000002F49000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F49000
|
Size: |
24576
|
|
A2BD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1526695824.000000000A2BD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
A2BD000
|
Size: |
12288
|
|
7A62000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1519605877.0000000007A62000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A62000
|
Size: |
4096
|
|
7FF5BE5A1000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2673013178.00007FF5BE5A1000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE5A1000
|
Size: |
4096
|
|
14E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1644030200.00000000014E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14E0000
|
Size: |
12288
|
|
1A60055E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1815974500.000001A60055E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1A60055E000
|
Size: |
249856
|
|
2F2E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2655123086.0000000002F2E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2F2E000
|
Size: |
8192
|
|
7FF5BE911000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2677154451.00007FF5BE911000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE911000
|
Size: |
32768
|
|
D042000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2072084517.000000000D042000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D042000
|
Size: |
98304
|
|
5F70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2020547275.0000000005F70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F70000
|
Size: |
147456
|
|
22D21EE2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1352269094.0000022D21EE2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D21EE2000
|
Size: |
57344
|
|
CB42000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2667015077.000000000CB42000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB42000
|
Size: |
53248
|
|
7FF5BE478000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1539238170.00007FF5BE478000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE478000
|
Size: |
8192
|
|
81B0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2660742017.00000000081B0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
81B0000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
7D70000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1521200978.0000000007D70000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7D70000
|
Size: |
4096
|
|
4DD3000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1518362137.0000000004DD3000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4DD3000
|
Size: |
208896
|
|
7FF5BE985000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1546518329.00007FF5BE985000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE985000
|
Size: |
8192
|
|
57D6000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1519187039.00000000057D6000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
57D6000
|
Size: |
4096
|
|
7FF5BE75C000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2674816615.00007FF5BE75C000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE75C000
|
Size: |
12288
|
|
7FF5BE73E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2674754751.00007FF5BE73E000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE73E000
|
Size: |
4096
|
|
2F2CDFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1352950204.0000002F2CDFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2F2CDFE000
|
Size: |
8192
|
|
143F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1643801066.000000000143F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
143F000
|
Size: |
4096
|
|
97DA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2662519770.00000000097DA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
97DA000
|
Size: |
24576
|
|
2B5A255F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1517714752.000002B5A255F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B5A255F000
|
Size: |
10485760
|
|
8B7F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1522527006.0000000008B7F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8B7F000
|
Size: |
4096
|
|
9221000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1523023735.0000000009221000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9221000
|
Size: |
4096
|
|
7FF5BE4D6000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2672314608.00007FF5BE4D6000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE4D6000
|
Size: |
12288
|
|
9968000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2662609847.0000000009968000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9968000
|
Size: |
4096
|
|
7FF5BE44D000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2671523951.00007FF5BE44D000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE44D000
|
Size: |
28672
|
|
CBBE000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1535163726.000000000CBBE000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CBBE000
|
Size: |
24576
|
|
D87F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1537122728.000000000D87F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
D87F000
|
Size: |
4096
|
|
10D14000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2669741529.0000000010D14000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
10D14000
|
Size: |
229376
|
|
4E07000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2657432976.0000000004E07000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4E07000
|
Size: |
16384
|
|
4E3D000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2657432976.0000000004E3D000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4E3D000
|
Size: |
8192
|
|
7A30000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1519605877.0000000007A30000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A30000
|
Size: |
12288
|
|
81A0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2660708263.00000000081A0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
81A0000
|
Size: |
4096
|
|
344A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2655703340.000000000344A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
344A000
|
Size: |
24576
|
|
7FF5BE4C6000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2672170388.00007FF5BE4C6000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE4C6000
|
Size: |
12288
|
|
AFC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2654643526.0000000000AFC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
AFC000
|
Size: |
16384
|
|
22D201F3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1352404694.0000022D201F3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D201F3000
|
Size: |
57344
|
|
9CEC000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2071685840.0000000009CEC000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9CEC000
|
Size: |
299008
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
7FF5BE81E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1542827443.00007FF5BE81E000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE81E000
|
Size: |
8192
|
|
2B59C530000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1516514339.000002B59C530000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B59C530000
|
Size: |
16384
|
|
7FF5BE939000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1545579407.00007FF5BE939000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE939000
|
Size: |
8192
|
|
7FF5BE7D8000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1542644503.00007FF5BE7D8000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE7D8000
|
Size: |
32768
|
|
22D201F3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1351762306.0000022D201F3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D201F3000
|
Size: |
212992
|
|
7FF5BE787000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1542581848.00007FF5BE787000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE787000
|
Size: |
57344
|
|
2F2C8FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1352904373.0000002F2C8FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2F2C8FE000
|
Size: |
8192
|
|
1A6006AC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1815974500.000001A6006AC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1A6006AC000
|
Size: |
45056
|
|
7FF5BE80C000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1542827443.00007FF5BE80C000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE80C000
|
Size: |
12288
|
|
22D21ED0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1353391167.0000022D21ED0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D21ED0000
|
Size: |
4096
|
|
1A30000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1516744787.0000000001A30000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1A30000
|
Size: |
368640
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
22D201C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1352178432.0000022D201C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D201C0000
|
Size: |
110592
|
|
B1F1000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2073216051.000000000B1F1000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
B1F1000
|
Size: |
131072
|
|
7FF5BE9D0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2678598725.00007FF5BE9D0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE9D0000
|
Size: |
20480
|
|
7E70000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1521239048.0000000007E70000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7E70000
|
Size: |
4096
|
|
CB95000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1533280630.000000000CB95000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB95000
|
Size: |
4096
|
|
7FF5BE32D000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1538535838.00007FF5BE32D000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE32D000
|
Size: |
8192
|
|
7FF5BEA12000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1547974039.00007FF5BEA12000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BEA12000
|
Size: |
20480
|
|
F3FB000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.2669496536.000000000F3FB000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
F3FB000
|
Size: |
4096
|
|
4D96000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1518362137.0000000004D96000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4D96000
|
Size: |
20480
|
|
7A98000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658707759.0000000007A98000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A98000
|
Size: |
4096
|
|
37A0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2656012892.00000000037A0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
37A0000
|
Size: |
8192
|
|
9C20000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2071685840.0000000009C20000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9C20000
|
Size: |
4096
|
|
7FF5BE6C3000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1541790441.00007FF5BE6C3000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE6C3000
|
Size: |
8192
|
|
B1FE000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2073292747.000000000B1FE000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
B1FE000
|
Size: |
53248
|
|
9CDE000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2071685840.0000000009CDE000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9CDE000
|
Size: |
12288
|
|
7FFC3C7E0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1867685112.00007FFC3C7E0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7FFC3C7E0000
|
Size: |
4096
|
|
C934A3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1516066747.000000C934A3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C934A3E000
|
Size: |
8192
|
|
CB6F000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2667015077.000000000CB6F000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB6F000
|
Size: |
4096
|
|
7FF5BE98D000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2678152683.00007FF5BE98D000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE98D000
|
Size: |
4096
|
|
9B49000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2072108638.0000000009B49000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9B49000
|
Size: |
118784
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
61A3E73000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1814879491.00000061A3E73000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
61A3E73000
|
Size: |
53248
|
|
5F5F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2657092534.0000000005F5F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5F5F000
|
Size: |
4096
|
|
7FF5BE69A000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1541442996.00007FF5BE69A000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE69A000
|
Size: |
4096
|
|
AB50000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2664786423.000000000AB50000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AB50000
|
Size: |
4096
|
|
1A60052D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1815974500.000001A60052D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1A60052D000
|
Size: |
196608
|
|
7DF4C9801000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000007.00000002.2670665354.00007DF4C9801000.00000020.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7DF4C9801000
|
Size: |
4096
|
|
AB60000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1528246779.000000000AB60000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AB60000
|
Size: |
4096
|
|
4D96000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2657432976.0000000004D96000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4D96000
|
Size: |
20480
|
|
22D21EEF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1349526199.0000022D21EEF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D21EEF000
|
Size: |
8192
|
|
2B59C770000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.1517169867.000002B59C770000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
2B59C770000
|
Size: |
4096
|
|
B5FD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1530862399.000000000B5FD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B5FD000
|
Size: |
12288
|
|
C934CBE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1516168645.000000C934CBE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C934CBE000
|
Size: |
8192
|
|
7FF5BEA35000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2678834689.00007FF5BEA35000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BEA35000
|
Size: |
4096
|
|
7FFC3C6C6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1866474154.00007FFC3C6C6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFC3C6C6000
|
Size: |
24576
|
|
7FFC3C900000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1871913687.00007FFC3C900000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFC3C900000
|
Size: |
65536
|
|
9992000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2662764839.0000000009992000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9992000
|
Size: |
24576
|
|
1A67CBC0000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1861245155.000001A67CBC0000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
1A67CBC0000
|
Size: |
4096
|
|
9AB4000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1523845606.0000000009AB4000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9AB4000
|
Size: |
32768
|
|
8A30000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2661736223.0000000008A30000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8A30000
|
Size: |
8192
|
|
22D201B2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1352605197.0000022D201B2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D201B2000
|
Size: |
8192
|
|
D6E3000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1536938353.000000000D6E3000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D6E3000
|
Size: |
8192
|
|
CAFF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1533224881.000000000CAFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
CAFF000
|
Size: |
4096
|
|
7E90000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1521290055.0000000007E90000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7E90000
|
Size: |
4096
|
|
7FF5BE4EA000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1539986008.00007FF5BE4EA000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE4EA000
|
Size: |
16384
|
|
2B59E4F8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1517714752.000002B59E4F8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B59E4F8000
|
Size: |
102400
|
|
4D46000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1518362137.0000000004D46000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4D46000
|
Size: |
16384
|
|
A84F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1527965566.000000000A84F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
A84F000
|
Size: |
4096
|
|
341E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2655605473.000000000341E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
341E000
|
Size: |
8192
|
|
1A67D11A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1865332423.000001A67D11A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A67D11A000
|
Size: |
16384
|
|
7FF5BE5D4000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2673182237.00007FF5BE5D4000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE5D4000
|
Size: |
12288
|
|
7FF5BE5D4000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1540501312.00007FF5BE5D4000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE5D4000
|
Size: |
12288
|
|
CC79000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2667669675.000000000CC79000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CC79000
|
Size: |
4096
|
|
399A000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1517673112.000000000399A000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
399A000
|
Size: |
20480
|
|
1A67C910000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1860718864.000001A67C910000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
1A67C910000
|
Size: |
20480
|
|
BC0E000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.2666555153.000000000BC0E000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
BC0E000
|
Size: |
4096
|
|
C20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2333158851.0000000000C20000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
C20000
|
Size: |
139264
|
|
78B0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658678729.00000000078B0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
78B0000
|
Size: |
4096
|
|
B70B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2666199524.000000000B70B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B70B000
|
Size: |
20480
|
|
CD92000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2667669675.000000000CD92000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CD92000
|
Size: |
368640
|
|
7885000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658580283.0000000007885000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7885000
|
Size: |
45056
|
|
2B59C6B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1517149787.000002B59C6B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B59C6B0000
|
Size: |
8192
|
|
1A600001000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1815974500.000001A600001000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1A600001000
|
Size: |
368640
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
8A00000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1522309395.0000000008A00000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8A00000
|
Size: |
8192
|
|
CEA7000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2072496324.000000000CEA7000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CEA7000
|
Size: |
8192
|
|
375A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2655887598.000000000375A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
375A000
|
Size: |
24576
|
|
344A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1517240078.000000000344A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
344A000
|
Size: |
24576
|
|
7FF5BE8CE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2676959893.00007FF5BE8CE000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE8CE000
|
Size: |
45056
|
|
CE18000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1535163726.000000000CE18000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CE18000
|
Size: |
290816
|
|
39B1000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2656227759.00000000039B1000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
39B1000
|
Size: |
4096
|
|
CBAF000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1535163726.000000000CBAF000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CBAF000
|
Size: |
20480
|
|
7FF5BE55D000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1540334832.00007FF5BE55D000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE55D000
|
Size: |
8192
|
|
B186000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1530341065.000000000B186000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
B186000
|
Size: |
110592
|
|
7FF5BE7E2000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2675384107.00007FF5BE7E2000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE7E2000
|
Size: |
12288
|
|
7FF5BE82C000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1543432390.00007FF5BE82C000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE82C000
|
Size: |
8192
|
|
AA90000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1528246779.000000000AA90000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AA90000
|
Size: |
4096
|
|
7FF5BE9C6000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1547479090.00007FF5BE9C6000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE9C6000
|
Size: |
8192
|
|
57D6000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658430253.00000000057D6000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
57D6000
|
Size: |
4096
|
|
144D000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.1643848166.000000000144D000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
144D000
|
Size: |
4096
|
|
C9346FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1515941993.000000C9346FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C9346FE000
|
Size: |
8192
|
|
7FF5BE38B000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1538609981.00007FF5BE38B000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE38B000
|
Size: |
36864
|
|
398A000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1517673112.000000000398A000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
398A000
|
Size: |
4096
|
|
AB60000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2664786423.000000000AB60000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AB60000
|
Size: |
4096
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1644555159.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|
9ADA000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1523845606.0000000009ADA000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9ADA000
|
Size: |
69632
|
|
7FF5BE76E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2674990729.00007FF5BE76E000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE76E000
|
Size: |
16384
|
|
12D0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.1643180458.00000000012D0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
12D0000
|
Size: |
65536
|
|
7A34000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658707759.0000000007A34000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A34000
|
Size: |
12288
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1644617812.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|
B78C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1531112909.000000000B78C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B78C000
|
Size: |
16384
|
|
7FF5BE6B1000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2674071182.00007FF5BE6B1000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE6B1000
|
Size: |
4096
|
|
7FF5BE432000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1538901587.00007FF5BE432000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE432000
|
Size: |
32768
|
|
D099000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2669098163.000000000D099000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D099000
|
Size: |
630784
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
7FF5BE3A2000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1538685880.00007FF5BE3A2000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE3A2000
|
Size: |
8192
|
|
7FFC3C7F2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1867743153.00007FFC3C7F2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFC3C7F2000
|
Size: |
4096
|
|
C20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2282086017.0000000000C20000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
C20000
|
Size: |
139264
|
|
7A5A000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658707759.0000000007A5A000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A5A000
|
Size: |
4096
|
|
61A433F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1815710516.00000061A433F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
61A433F000
|
Size: |
4096
|
|
7FF5BE71C000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1542082234.00007FF5BE71C000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE71C000
|
Size: |
4096
|
|
7FF5BE97A000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1546431954.00007FF5BE97A000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE97A000
|
Size: |
8192
|
|
1A600062000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1815974500.000001A600062000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1A600062000
|
Size: |
135168
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
A9ED000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2664786423.000000000A9ED000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
A9ED000
|
Size: |
4096
|
|
8F00000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1522709689.0000000008F00000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8F00000
|
Size: |
8192
|
|
AB52000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2664786423.000000000AB52000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AB52000
|
Size: |
4096
|
|
7FF5BE695000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2673807112.00007FF5BE695000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE695000
|
Size: |
4096
|
|
99E5000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2072846978.00000000099E5000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
99E5000
|
Size: |
397312
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
A640000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2664503254.000000000A640000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
A640000
|
Size: |
4096
|
|
1A600159000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1815974500.000001A600159000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1A600159000
|
Size: |
32768
|
|
7AA2000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1519605877.0000000007AA2000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7AA2000
|
Size: |
241664
|
|
7FF5BE969000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1545869743.00007FF5BE969000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE969000
|
Size: |
16384
|
|
7FF5BE895000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1544098397.00007FF5BE895000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE895000
|
Size: |
4096
|
|
AB47000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1528246779.000000000AB47000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AB47000
|
Size: |
4096
|
|
7FF5BE52C000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2672835048.00007FF5BE52C000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE52C000
|
Size: |
12288
|
|
10C54000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1537541955.0000000010C54000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
10C54000
|
Size: |
229376
|
|
7FF5BE873000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2676454969.00007FF5BE873000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE873000
|
Size: |
8192
|
|
78B0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1519565457.00000000078B0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
78B0000
|
Size: |
4096
|
|
C56F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1532936955.000000000C56F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C56F000
|
Size: |
4096
|
|
7FF5BE3F9000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1538853261.00007FF5BE3F9000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE3F9000
|
Size: |
4096
|
|
8C7F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1522578321.0000000008C7F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8C7F000
|
Size: |
4096
|
|
22D201B2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1353188725.0000022D201B2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D201B2000
|
Size: |
8192
|
|
7FF5BE2A3000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1538481815.00007FF5BE2A3000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE2A3000
|
Size: |
4096
|
|
8270000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1521808879.0000000008270000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
8270000
|
Size: |
4096
|
|
2B59EF12000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1517714752.000002B59EF12000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B59EF12000
|
Size: |
10485760
|
|
ABBD000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1528246779.000000000ABBD000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
ABBD000
|
Size: |
8192
|
|
8A00000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2661605522.0000000008A00000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8A00000
|
Size: |
8192
|
|
7FF5BE773000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2674990729.00007FF5BE773000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE773000
|
Size: |
12288
|
|
AA75000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1528246779.000000000AA75000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AA75000
|
Size: |
12288
|
|
CE80000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2072496324.000000000CE80000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CE80000
|
Size: |
65536
|
|
7FF5BE4EF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1540013289.00007FF5BE4EF000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE4EF000
|
Size: |
8192
|
|
7FF5BE335000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2671124767.00007FF5BE335000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE335000
|
Size: |
24576
|
|
7FF5BE3CA000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2671283910.00007FF5BE3CA000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE3CA000
|
Size: |
4096
|
|
39D9000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2656227759.00000000039D9000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
39D9000
|
Size: |
90112
|
|
8EC0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2662149517.0000000008EC0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
8EC0000
|
Size: |
4096
|
|
7FF5BE729000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2674497640.00007FF5BE729000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE729000
|
Size: |
8192
|
|
2EBD000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.1645980502.0000000002EBD000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
2EBD000
|
Size: |
4096
|
|
1A6005A2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1815974500.000001A6005A2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1A6005A2000
|
Size: |
1077248
|
|
1A600111000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1815974500.000001A600111000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1A600111000
|
Size: |
8192
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1644865457.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|
39A9000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1517673112.00000000039A9000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
39A9000
|
Size: |
4096
|
|
8199000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2660669688.0000000008199000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8199000
|
Size: |
28672
|
|
7F60000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2660442649.0000000007F60000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7F60000
|
Size: |
4096
|
|
7FF5BE422000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2671523951.00007FF5BE422000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE422000
|
Size: |
12288
|
|
9A4D000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1523845606.0000000009A4D000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9A4D000
|
Size: |
405504
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
7FF5BE4EF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2672551279.00007FF5BE4EF000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE4EF000
|
Size: |
8192
|
|
9A46000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2072108638.0000000009A46000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9A46000
|
Size: |
24576
|
|
7FF5BE285000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1538401606.00007FF5BE285000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE285000
|
Size: |
8192
|
|
B140000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2665962094.000000000B140000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
B140000
|
Size: |
4096
|
|
9016000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1522778875.0000000009016000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9016000
|
Size: |
139264
|
|
2B5A1B5F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1517714752.000002B5A1B5F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B5A1B5F000
|
Size: |
10485760
|
|
7FF5BE835000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1543460875.00007FF5BE835000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE835000
|
Size: |
4096
|
|
7FF5BEA66000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1548786655.00007FF5BEA66000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BEA66000
|
Size: |
36864
|
|
31BD000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.1656803800.00000000031BD000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
31BD000
|
Size: |
458752
|
|
22D21ED1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1348808599.0000022D21ED1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D21ED1000
|
Size: |
8192
|
|
B7A0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2666311179.000000000B7A0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B7A0000
|
Size: |
8192
|
|
1529000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1516518860.0000000001529000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1529000
|
Size: |
28672
|
|
DB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1642557281.0000000000DB0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DB0000
|
Size: |
4096
|
|
A233000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2663875091.000000000A233000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
A233000
|
Size: |
20480
|
|
D680000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2669253444.000000000D680000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D680000
|
Size: |
45056
|
|
7FFC3C6F6000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1866721262.00007FFC3C6F6000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7FFC3C6F6000
|
Size: |
49152
|
|
3995000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2656227759.0000000003995000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3995000
|
Size: |
16384
|
|
7FF5BE58E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2673013178.00007FF5BE58E000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE58E000
|
Size: |
57344
|
|
7FF5BE47C000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2671936172.00007FF5BE47C000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE47C000
|
Size: |
16384
|
|
7FF5BE685000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2673712556.00007FF5BE685000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE685000
|
Size: |
4096
|
|
1A60011E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1815974500.000001A60011E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1A60011E000
|
Size: |
8192
|
|
CD7E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2667669675.000000000CD7E000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CD7E000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
CB6D000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2667015077.000000000CB6D000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB6D000
|
Size: |
4096
|
|
7BA3000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658707759.0000000007BA3000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7BA3000
|
Size: |
45056
|
|
7FF5BE779000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2675098936.00007FF5BE779000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE779000
|
Size: |
4096
|
|
335D000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.1656803800.000000000335D000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
335D000
|
Size: |
4096
|
|
1690000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2655176348.0000000001690000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1690000
|
Size: |
16384
|
|
7FF5BE93E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1545707970.00007FF5BE93E000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE93E000
|
Size: |
8192
|
|
CB0B000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2667015077.000000000CB0B000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB0B000
|
Size: |
221184
|
|
AA08000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2664786423.000000000AA08000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AA08000
|
Size: |
12288
|
|
CD43000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2667669675.000000000CD43000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CD43000
|
Size: |
28672
|
|
1A67AE70000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1855958359.000001A67AE70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A67AE70000
|
Size: |
12288
|
|
7FF5BE41C000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2671523951.00007FF5BE41C000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE41C000
|
Size: |
16384
|
|
9659000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1523158743.0000000009659000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9659000
|
Size: |
28672
|
|
8AFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1522500079.0000000008AFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8AFE000
|
Size: |
8192
|
|
2B59C4B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1516464554.000002B59C4B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B59C4B0000
|
Size: |
8192
|
|
8A60000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1522475412.0000000008A60000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8A60000
|
Size: |
8192
|
|
9C28000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2662764839.0000000009C28000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9C28000
|
Size: |
757760
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
12F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1643625153.00000000012F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12F0000
|
Size: |
16384
|
|
B7C0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2666376707.000000000B7C0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
B7C0000
|
Size: |
4096
|
|
7FF5BE857000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2676212326.00007FF5BE857000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE857000
|
Size: |
20480
|
|
7FF5BE50D000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1540118033.00007FF5BE50D000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE50D000
|
Size: |
12288
|
|
2B59C794000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1517190394.000002B59C794000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B59C794000
|
Size: |
28672
|
|
3490000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2655737755.0000000003490000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3490000
|
Size: |
8192
|
|
CD92000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1535163726.000000000CD92000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CD92000
|
Size: |
495616
|
|
7FF5BE87F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2676536259.00007FF5BE87F000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE87F000
|
Size: |
24576
|
|
7A44000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658707759.0000000007A44000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A44000
|
Size: |
20480
|
|
7FF5BE6D0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1541885249.00007FF5BE6D0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE6D0000
|
Size: |
8192
|
|
D00F000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2669011988.000000000D00F000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D00F000
|
Size: |
409600
|
|
37D0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1517557471.00000000037D0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
37D0000
|
Size: |
4096
|
|
12D0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2654744734.00000000012D0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
12D0000
|
Size: |
24576
|
|
7FF5BE7F7000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1542767679.00007FF5BE7F7000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE7F7000
|
Size: |
12288
|
|
12E1000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.1643180458.00000000012E1000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
12E1000
|
Size: |
4096
|
|
2F45000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1641659872.0000000002F45000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F45000
|
Size: |
20480
|
|
C7FF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1533055989.000000000C7FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C7FF000
|
Size: |
4096
|
|
7FF5BE85D000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1543655864.00007FF5BE85D000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE85D000
|
Size: |
4096
|
|
7A6A000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1519605877.0000000007A6A000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A6A000
|
Size: |
4096
|
|
3986000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2656227759.0000000003986000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3986000
|
Size: |
12288
|
|
2FB0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1516871941.0000000002FB0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2FB0000
|
Size: |
4096
|
|
7FF5BE98D000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1546518329.00007FF5BE98D000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE98D000
|
Size: |
4096
|
|
7FF5BE6BB000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2674206779.00007FF5BE6BB000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE6BB000
|
Size: |
12288
|
|
8AFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2661874264.0000000008AFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8AFE000
|
Size: |
8192
|
|
7AEB000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1519605877.0000000007AEB000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7AEB000
|
Size: |
421888
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
CBCA000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1535163726.000000000CBCA000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CBCA000
|
Size: |
73728
|
|
1A67CF66000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1861529844.000001A67CF66000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A67CF66000
|
Size: |
4096
|
|
9DFA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1526477819.0000000009DFA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9DFA000
|
Size: |
20480
|
|
7DF4C97F1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000007.00000002.2670606510.00007DF4C97F1000.00000020.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7DF4C97F1000
|
Size: |
4096
|
|
7885000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1519475886.0000000007885000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7885000
|
Size: |
45056
|
|
7FFC3C920000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1872354990.00007FFC3C920000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFC3C920000
|
Size: |
61440
|
|
CC6A000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2667669675.000000000CC6A000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CC6A000
|
Size: |
12288
|
|
7FF5BE8C4000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2676959893.00007FF5BE8C4000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE8C4000
|
Size: |
32768
|
|
F410000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.2669496536.000000000F410000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
F410000
|
Size: |
8192
|
|
56E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1645690498.000000000056E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
56E000
|
Size: |
8192
|
|
7FF5BE937000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1545579407.00007FF5BE937000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE937000
|
Size: |
4096
|
|
9221000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2662416830.0000000009221000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9221000
|
Size: |
4096
|
|
7FF5BE39A000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2671231161.00007FF5BE39A000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE39A000
|
Size: |
16384
|
|
3141000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1643739727.0000000003141000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3141000
|
Size: |
229376
|
|
4D80000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1518362137.0000000004D80000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4D80000
|
Size: |
4096
|
|
7FF5BE82C000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2676183343.00007FF5BE82C000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE82C000
|
Size: |
8192
|
|
C9343D3000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1515904323.000000C9343D3000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C9343D3000
|
Size: |
53248
|
|
B8D0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2666402843.000000000B8D0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
B8D0000
|
Size: |
4096
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1714009043.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|
2B5A4D5F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1517714752.000002B5A4D5F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B5A4D5F000
|
Size: |
10485760
|
|
9083000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2662323239.0000000009083000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9083000
|
Size: |
20480
|
|
7890000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1519535162.0000000007890000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7890000
|
Size: |
4096
|
|
F220000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1537163958.000000000F220000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
F220000
|
Size: |
5242880
|
|
B1A2000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1530341065.000000000B1A2000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
B1A2000
|
Size: |
8192
|
|
A9E9000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1528246779.000000000A9E9000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
A9E9000
|
Size: |
4096
|
|
22D20179000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1353123974.0000022D20179000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D20179000
|
Size: |
90112
|
|
7FF5BE7FC000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1542827443.00007FF5BE7FC000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE7FC000
|
Size: |
40960
|
|
22D201A6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1352605197.0000022D201A6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D201A6000
|
Size: |
24576
|
|
C93487E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1515997122.000000C93487E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C93487E000
|
Size: |
8192
|
|
8478000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1521882545.0000000008478000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8478000
|
Size: |
32768
|
|
CEF0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2668834654.000000000CEF0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CEF0000
|
Size: |
28672
|
|
CAFF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2666985210.000000000CAFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
CAFF000
|
Size: |
4096
|
|
37D0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2656081716.00000000037D0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
37D0000
|
Size: |
4096
|
|
3649000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1517384990.0000000003649000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3649000
|
Size: |
28672
|
|
7FF5BE3A2000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2671259070.00007FF5BE3A2000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE3A2000
|
Size: |
8192
|
|
9C0B000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2071685840.0000000009C0B000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9C0B000
|
Size: |
69632
|
|
D098000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2073007519.000000000D098000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D098000
|
Size: |
430080
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2F2A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1516819589.0000000002F2A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2F2A000
|
Size: |
24576
|
|
7FF5BE71F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1542082234.00007FF5BE71F000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE71F000
|
Size: |
24576
|
|
7FF5BE9AD000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2678355422.00007FF5BE9AD000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE9AD000
|
Size: |
12288
|
|
7FFC3C620000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1866255614.00007FFC3C620000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFC3C620000
|
Size: |
40960
|
|
9CEC000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2662764839.0000000009CEC000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9CEC000
|
Size: |
299008
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
B790000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2666262287.000000000B790000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
B790000
|
Size: |
4096
|
|
9AB4000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2662764839.0000000009AB4000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9AB4000
|
Size: |
32768
|
|
2B59C4F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1516490498.000002B59C4F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B59C4F0000
|
Size: |
4096
|
|
2FAE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2655413915.0000000002FAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2FAE000
|
Size: |
8192
|
|
7FFC3C8F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1871671554.00007FFC3C8F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFC3C8F0000
|
Size: |
65536
|
|
22D201CA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1352643916.0000022D201CA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D201CA000
|
Size: |
69632
|
|
A539000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2664151545.000000000A539000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
A539000
|
Size: |
28672
|
|
61A453E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1815752227.00000061A453E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
61A453E000
|
Size: |
8192
|
|
7FF5BE442000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2671523951.00007FF5BE442000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE442000
|
Size: |
4096
|
|
7FF5BE2A5000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1538511680.00007FF5BE2A5000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE2A5000
|
Size: |
4096
|
|
22D201B4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1351762306.0000022D201B4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D201B4000
|
Size: |
241664
|
|
2F46000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2655145082.0000000002F46000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F46000
|
Size: |
73728
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7F30000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1521341507.0000000007F30000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7F30000
|
Size: |
8192
|
|
7FFC3C8C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1870870519.00007FFC3C8C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFC3C8C0000
|
Size: |
65536
|
|
9AC2000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2072108638.0000000009AC2000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9AC2000
|
Size: |
12288
|
|
7A54000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1519605877.0000000007A54000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A54000
|
Size: |
4096
|
|
ABBD000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2664786423.000000000ABBD000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
ABBD000
|
Size: |
8192
|
|
B8F0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2666432711.000000000B8F0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
B8F0000
|
Size: |
4096
|
|
2F4F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1641683106.0000000002F4F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F4F000
|
Size: |
20480
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1643846405.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|
7A44000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1519605877.0000000007A44000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A44000
|
Size: |
20480
|
|
7FF5BE530000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2672835048.00007FF5BE530000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE530000
|
Size: |
4096
|
|
7A38000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1519605877.0000000007A38000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A38000
|
Size: |
4096
|
|
BD25000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2666702200.000000000BD25000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BD25000
|
Size: |
45056
|
|
7A30000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658707759.0000000007A30000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A30000
|
Size: |
12288
|
|
CE0E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2073074163.000000000CE0E000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CE0E000
|
Size: |
20480
|
|
7FF5BE831000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2676212326.00007FF5BE831000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE831000
|
Size: |
12288
|
|
7F70000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1521458288.0000000007F70000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7F70000
|
Size: |
4096
|
|
2B59E512000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1517714752.000002B59E512000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B59E512000
|
Size: |
10485760
|
|
7FF5BE955000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1545869743.00007FF5BE955000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE955000
|
Size: |
53248
|
|
BB30000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.2666555153.000000000BB30000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
BB30000
|
Size: |
905216
|
|
7FF5BE45F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2671869730.00007FF5BE45F000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE45F000
|
Size: |
53248
|
|
7FF5BEA32000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1547974039.00007FF5BEA32000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BEA32000
|
Size: |
8192
|
|
37F6000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2656472532.00000000037F6000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
37F6000
|
Size: |
4096
|
|
7FF5BEA48000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2679391641.00007FF5BEA48000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BEA48000
|
Size: |
16384
|
|
A9ED000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1528246779.000000000A9ED000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
A9ED000
|
Size: |
4096
|
|
D101000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2071451455.000000000D101000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D101000
|
Size: |
204800
|
|
996A000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1523527435.000000000996A000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
996A000
|
Size: |
8192
|
|
9ACE000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1523845606.0000000009ACE000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9ACE000
|
Size: |
4096
|
|
7A52000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1519605877.0000000007A52000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A52000
|
Size: |
4096
|
|
C6EA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1533031696.000000000C6EA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C6EA000
|
Size: |
24576
|
|
7C02000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2660117349.0000000007C02000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7C02000
|
Size: |
106496
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
22D21EE2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1348808599.0000022D21EE2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D21EE2000
|
Size: |
53248
|
|
4EBA000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658311829.0000000004EBA000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4EBA000
|
Size: |
12288
|
|
9AC6000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1523845606.0000000009AC6000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9AC6000
|
Size: |
16384
|
|
CEB2000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2668671033.000000000CEB2000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CEB2000
|
Size: |
249856
|
|
4EBA000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1519028450.0000000004EBA000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4EBA000
|
Size: |
12288
|
|
AA4D000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1528246779.000000000AA4D000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AA4D000
|
Size: |
28672
|
|
3995000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1517673112.0000000003995000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3995000
|
Size: |
16384
|
|
2B59C7D5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1517245352.000002B59C7D5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B59C7D5000
|
Size: |
40960
|
|
AA44000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1528246779.000000000AA44000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AA44000
|
Size: |
28672
|
|
7FF5BE442000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1538901587.00007FF5BE442000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE442000
|
Size: |
24576
|
|
8A30000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1522400927.0000000008A30000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8A30000
|
Size: |
8192
|
|
9AB4000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2072108638.0000000009AB4000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9AB4000
|
Size: |
32768
|
|
CB00000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2667015077.000000000CB00000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB00000
|
Size: |
40960
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1643953440.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|
7FF5BE7F4000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1542767679.00007FF5BE7F4000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE7F4000
|
Size: |
8192
|
|
7FF5BE6AE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2674071182.00007FF5BE6AE000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE6AE000
|
Size: |
8192
|
|
7FF5BE927000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2677281947.00007FF5BE927000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE927000
|
Size: |
24576
|
|
1A67AEF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1856126504.000001A67AEF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A67AEF0000
|
Size: |
274432
|
|
1A67AF82000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1856126504.000001A67AF82000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A67AF82000
|
Size: |
294912
|
|
7A98000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1519605877.0000000007A98000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A98000
|
Size: |
4096
|
|
2B59C5CB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1516637066.000002B59C5CB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B59C5CB000
|
Size: |
4096
|
|
DC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1642638226.0000000000DC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DC0000
|
Size: |
4096
|
|
F310000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.2669496536.000000000F310000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
F310000
|
Size: |
884736
|
|
C93598E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1516355008.000000C93598E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C93598E000
|
Size: |
8192
|
|
3090000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.1656803800.0000000003090000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3090000
|
Size: |
1208320
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7A60000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658707759.0000000007A60000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A60000
|
Size: |
4096
|
|
13D3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2072825997.00000000013D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13D3000
|
Size: |
24576
|
|
35C9000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2655815303.00000000035C9000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
35C9000
|
Size: |
28672
|
|
AA79000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2664786423.000000000AA79000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AA79000
|
Size: |
4096
|
|
7A6A000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658707759.0000000007A6A000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A6A000
|
Size: |
4096
|
|
8FCB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1522749524.0000000008FCB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8FCB000
|
Size: |
20480
|
|
22D2012B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1353095989.0000022D2012B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D2012B000
|
Size: |
4096
|
|
22D201E3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1352310645.0000022D201E3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D201E3000
|
Size: |
49152
|
|
D6B1000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2073438939.000000000D6B1000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D6B1000
|
Size: |
24576
|
|
7FF5BE646000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1540712339.00007FF5BE646000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE646000
|
Size: |
4096
|
|
920C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2662391136.000000000920C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
920C000
|
Size: |
16384
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1644000484.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|
D6BD000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1536938353.000000000D6BD000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D6BD000
|
Size: |
8192
|
|
7A9E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1519605877.0000000007A9E000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A9E000
|
Size: |
8192
|
|
C934E3B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1516225660.000000C934E3B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C934E3B000
|
Size: |
20480
|
|
7FF5BE9E5000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1547974039.00007FF5BE9E5000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE9E5000
|
Size: |
8192
|
|
39A9000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2656227759.00000000039A9000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
39A9000
|
Size: |
4096
|
|
7FF5BE2A5000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2671070549.00007FF5BE2A5000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE2A5000
|
Size: |
4096
|
|
1275000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2654661386.0000000001275000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1275000
|
Size: |
45056
|
|
1A6001F6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1815974500.000001A6001F6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1A6001F6000
|
Size: |
1974272
|
|
D154000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2071451455.000000000D154000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D154000
|
Size: |
45056
|
|
9CE2000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2071685840.0000000009CE2000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9CE2000
|
Size: |
12288
|
|
7FFC3C810000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1867809655.00007FFC3C810000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFC3C810000
|
Size: |
65536
|
|
7FF5BE831000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1543460875.00007FF5BE831000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE831000
|
Size: |
12288
|
|
ABAF000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2664786423.000000000ABAF000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
ABAF000
|
Size: |
4096
|
|
1690000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1516652763.0000000001690000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1690000
|
Size: |
16384
|
|
8A40000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1522447196.0000000008A40000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8A40000
|
Size: |
8192
|
|
7FF5BE32D000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2671097714.00007FF5BE32D000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE32D000
|
Size: |
8192
|
|
1A67AE90000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1856037914.000001A67AE90000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A67AE90000
|
Size: |
4096
|
|
7FF5BE1D5000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1538299156.00007FF5BE1D5000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE1D5000
|
Size: |
28672
|
|
7AEB000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2072664500.0000000007AEB000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7AEB000
|
Size: |
421888
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
7FF5BE9DC000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1547479090.00007FF5BE9DC000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE9DC000
|
Size: |
16384
|
|
7FF5BE715000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2674497640.00007FF5BE715000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE715000
|
Size: |
12288
|
|
4EAA000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658277334.0000000004EAA000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4EAA000
|
Size: |
12288
|
|
7FF5BE417000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1538901587.00007FF5BE417000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE417000
|
Size: |
16384
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1644814254.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|
7ADF000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1519605877.0000000007ADF000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7ADF000
|
Size: |
45056
|
|
FC0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2654611053.0000000000FC0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
FC0000
|
Size: |
4096
|
|
7A84000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658707759.0000000007A84000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A84000
|
Size: |
61440
|
|
1A67CFC5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1863818697.000001A67CFC5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A67CFC5000
|
Size: |
110592
|
|
3549000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1517322905.0000000003549000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3549000
|
Size: |
28672
|
|
CE69000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2668365476.000000000CE69000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CE69000
|
Size: |
94208
|
|
22D1FFB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1353013928.0000022D1FFB0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D1FFB0000
|
Size: |
4096
|
|
22D20227000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1351719055.0000022D20227000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D20227000
|
Size: |
106496
|
|
4E0D000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2657432976.0000000004E0D000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4E0D000
|
Size: |
73728
|
|
7FFC3C612000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1865910615.00007FFC3C612000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFC3C612000
|
Size: |
4096
|
|
7FF5BE1DE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1538299156.00007FF5BE1DE000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE1DE000
|
Size: |
20480
|
|
9B66000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2071685840.0000000009B66000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9B66000
|
Size: |
630784
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
7FF5BE835000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2676212326.00007FF5BE835000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE835000
|
Size: |
4096
|
|
7A5C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658707759.0000000007A5C000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A5C000
|
Size: |
4096
|
|
CC6F000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2667669675.000000000CC6F000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CC6F000
|
Size: |
24576
|
|
C934C3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1516147562.000000C934C3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C934C3E000
|
Size: |
8192
|
|
7FF5BE4FE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1540045277.00007FF5BE4FE000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE4FE000
|
Size: |
8192
|
|
CB79000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1533280630.000000000CB79000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB79000
|
Size: |
4096
|
|
7FF5BE996000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2678266047.00007FF5BE996000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE996000
|
Size: |
20480
|
|
7FF5BE927000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1545133640.00007FF5BE927000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE927000
|
Size: |
24576
|
|
8270000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2660799597.0000000008270000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
8270000
|
Size: |
4096
|
|
22D201B2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1352545123.0000022D201B2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D201B2000
|
Size: |
8192
|
|
B7B0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1531350471.000000000B7B0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B7B0000
|
Size: |
8192
|
|
9B25000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2662764839.0000000009B25000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9B25000
|
Size: |
139264
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
B180000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1530341065.000000000B180000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
B180000
|
Size: |
16384
|
|
9C22000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2071685840.0000000009C22000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9C22000
|
Size: |
4096
|
|
398C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1517673112.000000000398C000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
398C000
|
Size: |
12288
|
|
7BD7000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2072926105.0000000007BD7000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7BD7000
|
Size: |
163840
|
|
7FF5BE9C9000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2678598725.00007FF5BE9C9000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE9C9000
|
Size: |
12288
|
|
7E70000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2660254276.0000000007E70000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7E70000
|
Size: |
4096
|
|
1A67AFCD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1856126504.000001A67AFCD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A67AFCD000
|
Size: |
12288
|
|
7FF5BE64E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2673510884.00007FF5BE64E000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE64E000
|
Size: |
4096
|
|
7FF5BE6C7000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2674278992.00007FF5BE6C7000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE6C7000
|
Size: |
12288
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1644658733.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|
2B59E47B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1517714752.000002B59E47B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B59E47B000
|
Size: |
36864
|
|
7FF5BE397000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1538609981.00007FF5BE397000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE397000
|
Size: |
4096
|
|
304C000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.1654119281.000000000304C000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
304C000
|
Size: |
8192
|
|
7FF5BE565000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1540356708.00007FF5BE565000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE565000
|
Size: |
4096
|
|
7FF5BE72E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1542309806.00007FF5BE72E000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE72E000
|
Size: |
20480
|
|
A610000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1527501966.000000000A610000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
A610000
|
Size: |
4096
|
|
97DA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1523240098.00000000097DA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
97DA000
|
Size: |
24576
|
|
D6C6000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2073478423.000000000D6C6000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D6C6000
|
Size: |
12288
|
|
D160000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2071605930.000000000D160000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D160000
|
Size: |
8192
|
|
CBB9000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2667669675.000000000CBB9000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CBB9000
|
Size: |
12288
|
|
51E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1645655156.000000000051E000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
51E000
|
Size: |
8192
|
|
AA55000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2664786423.000000000AA55000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AA55000
|
Size: |
8192
|
|
7FF5BE298000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1538428096.00007FF5BE298000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE298000
|
Size: |
12288
|
|
7FF5BE514000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2672675526.00007FF5BE514000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE514000
|
Size: |
16384
|
|
7DF4C9811000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000007.00000002.2670689117.00007DF4C9811000.00000020.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7DF4C9811000
|
Size: |
4096
|
|
7FF5BE9EC000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1547974039.00007FF5BE9EC000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE9EC000
|
Size: |
20480
|
|
7FF5BE5A1000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1540385289.00007FF5BE5A1000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE5A1000
|
Size: |
4096
|
|
8A20000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2661651507.0000000008A20000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8A20000
|
Size: |
8192
|
|
7FF5BE4E1000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2672426694.00007FF5BE4E1000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE4E1000
|
Size: |
4096
|
|
4DB9000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2657432976.0000000004DB9000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4DB9000
|
Size: |
12288
|
|
61A3F7D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1815177916.00000061A3F7D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
61A3F7D000
|
Size: |
12288
|
|
C9348FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1516014497.000000C9348FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C9348FE000
|
Size: |
8192
|
|
A9D8000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2664786423.000000000A9D8000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
A9D8000
|
Size: |
4096
|
|
7FF5BE955000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2677755689.00007FF5BE955000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE955000
|
Size: |
53248
|
|
3EDF000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2656472532.0000000003EDF000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
3EDF000
|
Size: |
4096
|
|
7FF5BE3CD000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2671283910.00007FF5BE3CD000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE3CD000
|
Size: |
12288
|
|
9DCD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1526368517.0000000009DCD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9DCD000
|
Size: |
12288
|
|
22D20120000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1353061187.0000022D20120000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D20120000
|
Size: |
16384
|
|
9AB1000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2662764839.0000000009AB1000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9AB1000
|
Size: |
8192
|
|
7FFC3C613000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1865964206.00007FFC3C613000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7FFC3C613000
|
Size: |
4096
|
|
7FF5BE68A000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1541305505.00007FF5BE68A000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE68A000
|
Size: |
24576
|
|
7FFC3C8B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1870625823.00007FFC3C8B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFC3C8B0000
|
Size: |
65536
|
|
3003000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1517136540.0000000003003000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3003000
|
Size: |
49152
|
|
CBE3000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2667669675.000000000CBE3000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CBE3000
|
Size: |
4096
|
|
7FF5BEA40000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2679309701.00007FF5BEA40000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BEA40000
|
Size: |
12288
|
|
AA92000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1528246779.000000000AA92000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AA92000
|
Size: |
208896
|
|
22D20125000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1353061187.0000022D20125000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D20125000
|
Size: |
12288
|
|
2FC0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1517083333.0000000002FC0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2FC0000
|
Size: |
8192
|
|
22D201B2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1352697967.0000022D201B2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D201B2000
|
Size: |
8192
|
|
CE18000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2073074163.000000000CE18000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CE18000
|
Size: |
290816
|
|
7FF5BE4FE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2672585120.00007FF5BE4FE000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE4FE000
|
Size: |
8192
|
|
7FF5BE2A3000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2671047589.00007FF5BE2A3000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE2A3000
|
Size: |
4096
|
|
22D2022E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1353348721.0000022D2022E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D2022E000
|
Size: |
61440
|
|
7FF5BE61F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2673321801.00007FF5BE61F000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE61F000
|
Size: |
32768
|
|
7FF5BE6B3000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1541611226.00007FF5BE6B3000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE6B3000
|
Size: |
4096
|
|
22D201C8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1352404694.0000022D201C8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D201C8000
|
Size: |
77824
|
|
22D21ED3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1348722161.0000022D21ED3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D21ED3000
|
Size: |
32768
|
|
A9D5000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2664786423.000000000A9D5000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
A9D5000
|
Size: |
8192
|
|
38E0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2656194132.00000000038E0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
38E0000
|
Size: |
8192
|
|
CD7E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1535163726.000000000CD7E000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CD7E000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
7FF5BE996000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1546797344.00007FF5BE996000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE996000
|
Size: |
20480
|
|
7FF5BE4CA000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1539480547.00007FF5BE4CA000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE4CA000
|
Size: |
4096
|
|
12B0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2654692880.00000000012B0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
12B0000
|
Size: |
4096
|
|
22D21EE2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1348779216.0000022D21EE2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D21EE2000
|
Size: |
53248
|
|
2B59E4BB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1517714752.000002B59E4BB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B59E4BB000
|
Size: |
4096
|
|
7FF5BE76B000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2674951620.00007FF5BE76B000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE76B000
|
Size: |
4096
|
|
7FF5BE85D000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2676365414.00007FF5BE85D000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE85D000
|
Size: |
4096
|
|
D155000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2071605930.000000000D155000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D155000
|
Size: |
40960
|
|
D6E3000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2073336816.000000000D6E3000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D6E3000
|
Size: |
8192
|
|
C93580E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1516250768.000000C93580E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C93580E000
|
Size: |
8192
|
|
CE0E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2668365476.000000000CE0E000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CE0E000
|
Size: |
20480
|
|
7FF5BE828000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2676147864.00007FF5BE828000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE828000
|
Size: |
4096
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1644677780.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|
39B1000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1517673112.00000000039B1000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
39B1000
|
Size: |
4096
|
|
A560000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1527410516.000000000A560000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
A560000
|
Size: |
4096
|
|
9AB1000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2072108638.0000000009AB1000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9AB1000
|
Size: |
8192
|
|
CB95000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2667015077.000000000CB95000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB95000
|
Size: |
4096
|
|
7FF5BE898000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1544364434.00007FF5BE898000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE898000
|
Size: |
8192
|
|
8020000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2660545088.0000000008020000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8020000
|
Size: |
8192
|
|
7FF5AACAE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1538104764.00007FF5AACAE000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5AACAE000
|
Size: |
20480
|
|
7FF5BE8BE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1544582153.00007FF5BE8BE000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE8BE000
|
Size: |
4096
|
|
9B49000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2662764839.0000000009B49000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9B49000
|
Size: |
749568
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
CE60000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2073074163.000000000CE60000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CE60000
|
Size: |
24576
|
|
7FF5BE761000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1542421637.00007FF5BE761000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE761000
|
Size: |
20480
|
|
1A67B090000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1860404395.000001A67B090000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A67B090000
|
Size: |
16384
|
|
AB5E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2664786423.000000000AB5E000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AB5E000
|
Size: |
4096
|
|
7FF5BE923000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1545133640.00007FF5BE923000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE923000
|
Size: |
12288
|
|
CE95000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2072496324.000000000CE95000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CE95000
|
Size: |
16384
|
|
2F2CEFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1352966415.0000002F2CEFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2F2CEFE000
|
Size: |
8192
|
|
9ADA000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2662764839.0000000009ADA000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9ADA000
|
Size: |
69632
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1644892789.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|
3141000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1643298758.0000000003141000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3141000
|
Size: |
65536
|
|
CEB2000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2072496324.000000000CEB2000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CEB2000
|
Size: |
249856
|
|
7FF5BE838000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2676212326.00007FF5BE838000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE838000
|
Size: |
4096
|
|
39D9000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1517673112.00000000039D9000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
39D9000
|
Size: |
90112
|
|
AB54000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2664786423.000000000AB54000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AB54000
|
Size: |
4096
|
|
22D20128000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1348765707.0000022D20128000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D20128000
|
Size: |
16384
|
|
1A30000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2655281517.0000000001A30000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1A30000
|
Size: |
368640
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
2FE0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2655507383.0000000002FE0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2FE0000
|
Size: |
8192
|
|
8020000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1521541385.0000000008020000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8020000
|
Size: |
8192
|
|
7BA3000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2072664500.0000000007BA3000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7BA3000
|
Size: |
45056
|
|
22D201E2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1352235267.0000022D201E2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D201E2000
|
Size: |
53248
|
|
4D7B000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2657432976.0000000004D7B000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4D7B000
|
Size: |
4096
|
|
16A0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1516713624.00000000016A0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
16A0000
|
Size: |
36864
|
|
2E40000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1516800068.0000000002E40000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2E40000
|
Size: |
8192
|
|
2EF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1817280511.0000000002EF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EF0000
|
Size: |
163840
|
|
9999000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2662764839.0000000009999000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9999000
|
Size: |
299008
|
|
2F49000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1641762095.0000000002F49000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F49000
|
Size: |
24576
|
|
7FF5BE9C6000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2678598725.00007FF5BE9C6000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE9C6000
|
Size: |
8192
|
|
B70B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1530995436.000000000B70B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B70B000
|
Size: |
20480
|
|
1A67AF7D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1856126504.000001A67AF7D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A67AF7D000
|
Size: |
16384
|
|
61A46BB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1815873968.00000061A46BB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
61A46BB000
|
Size: |
20480
|
|
3000000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2655537861.0000000003000000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3000000
|
Size: |
8192
|
|
7FF5BEA35000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1547974039.00007FF5BEA35000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BEA35000
|
Size: |
4096
|
|
CE69000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2073074163.000000000CE69000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CE69000
|
Size: |
94208
|
|
39B3000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2656227759.00000000039B3000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
39B3000
|
Size: |
4096
|
|
2B59C676000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1516637066.000002B59C676000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B59C676000
|
Size: |
102400
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1644714812.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|
7DF4C97E0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1537919562.00007DF4C97E0000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7DF4C97E0000
|
Size: |
4096
|
|
7FF5BEA54000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2679454567.00007FF5BEA54000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BEA54000
|
Size: |
8192
|
|
2B59C570000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1516590716.000002B59C570000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B59C570000
|
Size: |
65536
|
|
7FF5BE4C3000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1539480547.00007FF5BE4C3000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE4C3000
|
Size: |
8192
|
|
D075000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2669011988.000000000D075000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D075000
|
Size: |
143360
|
|
7FFC3C910000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1872183789.00007FFC3C910000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFC3C910000
|
Size: |
24576
|
|
CB85000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1533280630.000000000CB85000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB85000
|
Size: |
4096
|
|
7FF5BE889000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2676601895.00007FF5BE889000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE889000
|
Size: |
24576
|
|
920B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1522998421.000000000920B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
920B000
|
Size: |
20480
|
|
BE2A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1532804128.000000000BE2A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BE2A000
|
Size: |
24576
|
|
38F0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2656227759.00000000038F0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
38F0000
|
Size: |
610304
|
|
7FF5BE618000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1540599308.00007FF5BE618000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE618000
|
Size: |
4096
|
|
10D96000
|
system
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2670125824.0000000010D96000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
10D96000
|
Size: |
4096
|
|
AA55000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1528246779.000000000AA55000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AA55000
|
Size: |
8192
|
|
A3BD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2664070643.000000000A3BD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
A3BD000
|
Size: |
12288
|
|
7FF5BE5F9000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1540574329.00007FF5BE5F9000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE5F9000
|
Size: |
12288
|
|
CB7D000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1533280630.000000000CB7D000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB7D000
|
Size: |
4096
|
|
7FF5BE41C000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1538901587.00007FF5BE41C000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE41C000
|
Size: |
16384
|
|
C6EA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2666902600.000000000C6EA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C6EA000
|
Size: |
24576
|
|
2FA5000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.1651214835.0000000002FA5000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
2FA5000
|
Size: |
4096
|
|
D134000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2669098163.000000000D134000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D134000
|
Size: |
110592
|
|
7FF5BE886000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1543948687.00007FF5BE886000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE886000
|
Size: |
4096
|
|
BC4D000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.2666555153.000000000BC4D000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
BC4D000
|
Size: |
4096
|
|
2B59C790000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1517190394.000002B59C790000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B59C790000
|
Size: |
12288
|
|
7FF5BE9BE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1547231379.00007FF5BE9BE000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE9BE000
|
Size: |
4096
|
|
7FF5BE4B5000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2672170388.00007FF5BE4B5000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE4B5000
|
Size: |
32768
|
|
9DF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1526477819.0000000009DF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9DF0000
|
Size: |
4096
|
|
CB50000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2667015077.000000000CB50000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB50000
|
Size: |
8192
|
|
3780000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1517447005.0000000003780000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
3780000
|
Size: |
16384
|
|
22D201E3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1352467182.0000022D201E3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D201E3000
|
Size: |
49152
|
|
A9F0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2664786423.000000000A9F0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
A9F0000
|
Size: |
90112
|
|
B1FB000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2073313573.000000000B1FB000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
B1FB000
|
Size: |
12288
|
|
B920000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2666463803.000000000B920000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
B920000
|
Size: |
4096
|
|
A9E9000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2664786423.000000000A9E9000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
A9E9000
|
Size: |
4096
|
|
7FF5BE9EC000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2678834689.00007FF5BE9EC000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE9EC000
|
Size: |
20480
|
|
8F40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1522728557.0000000008F40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F40000
|
Size: |
4096
|
|
CBC7000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1535163726.000000000CBC7000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CBC7000
|
Size: |
8192
|
|
B640000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1530936278.000000000B640000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B640000
|
Size: |
8192
|
|
CE60000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2668365476.000000000CE60000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CE60000
|
Size: |
24576
|
|
1A67CB10000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1861207023.000001A67CB10000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
1A67CB10000
|
Size: |
4096
|
|
7FF5BE415000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1538876331.00007FF5BE415000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE415000
|
Size: |
4096
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1644575726.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|
7FF5BE9CD000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2678598725.00007FF5BE9CD000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE9CD000
|
Size: |
8192
|
|
4D82000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2657432976.0000000004D82000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4D82000
|
Size: |
20480
|
|
2D60000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.1645885708.0000000002D60000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
2D60000
|
Size: |
4096
|
|
2B59FD5F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1517714752.000002B59FD5F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B59FD5F000
|
Size: |
10485760
|
|
3003000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2655537861.0000000003003000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3003000
|
Size: |
49152
|
|
9964000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2662609847.0000000009964000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9964000
|
Size: |
8192
|
|
CB68000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1533280630.000000000CB68000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB68000
|
Size: |
8192
|
|
AA29000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2664786423.000000000AA29000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AA29000
|
Size: |
12288
|
|
E4C000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.2654976741.0000000000E4C000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
E4C000
|
Size: |
8192
|
|
2B59C550000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1516537508.000002B59C550000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B59C550000
|
Size: |
4096
|
|
7DF4C97F0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1537978383.00007DF4C97F0000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7DF4C97F0000
|
Size: |
4096
|
|
93B8000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1523082046.00000000093B8000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
93B8000
|
Size: |
32768
|
|
1A67AFD9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1856126504.000001A67AFD9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A67AFD9000
|
Size: |
90112
|
|
7FF5BE618000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2673321801.00007FF5BE618000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE618000
|
Size: |
4096
|
|
10CDB000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2669741529.0000000010CDB000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
10CDB000
|
Size: |
188416
|
|
7FFC3C730000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1866878848.00007FFC3C730000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7FFC3C730000
|
Size: |
16384
|
|
7FF5BE430000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1538901587.00007FF5BE430000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE430000
|
Size: |
4096
|
|
7FF5BE523000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1540156553.00007FF5BE523000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE523000
|
Size: |
16384
|
|
2F49000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1641814451.0000000002F49000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F49000
|
Size: |
24576
|
|
C20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2435307382.0000000000C20000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
C20000
|
Size: |
139264
|
|
7FF5BE4B5000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1539480547.00007FF5BE4B5000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE4B5000
|
Size: |
32768
|
|
1A67C9E5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1860930525.000001A67C9E5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A67C9E5000
|
Size: |
4096
|
|
7FFC3C7B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1866951899.00007FFC3C7B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFC3C7B0000
|
Size: |
65536
|
|
7FF5AACB4000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1538104764.00007FF5AACB4000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5AACB4000
|
Size: |
20480
|
|
B40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2654741081.0000000000B40000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B40000
|
Size: |
4096
|
|
AB2D000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1528246779.000000000AB2D000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AB2D000
|
Size: |
4096
|
|
376D000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.2655735535.000000000376D000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
376D000
|
Size: |
4096
|
|
2B59C5D1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1516637066.000002B59C5D1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B59C5D1000
|
Size: |
4096
|
|
4E60000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1518870771.0000000004E60000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4E60000
|
Size: |
4096
|
|
FD0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1516247751.0000000000FD0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
FD0000
|
Size: |
4096
|
|
C20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2384330873.0000000000C20000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
C20000
|
Size: |
139264
|
|
CEF8000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1536456695.000000000CEF8000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CEF8000
|
Size: |
12288
|
|
7FF5BE28F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1538428096.00007FF5BE28F000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE28F000
|
Size: |
32768
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1644518361.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|
8A40000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2661780165.0000000008A40000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8A40000
|
Size: |
8192
|
|
7DF4C9811000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000007.00000000.1538073835.00007DF4C9811000.00000020.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7DF4C9811000
|
Size: |
4096
|
|
7FF5BE75C000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1542367691.00007FF5BE75C000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE75C000
|
Size: |
12288
|
|
2B59C3B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1516404551.000002B59C3B0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B59C3B0000
|
Size: |
4096
|
|
7FF5BE4E7000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2672426694.00007FF5BE4E7000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE4E7000
|
Size: |
4096
|
|
1A67CF19000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1861412416.000001A67CF19000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A67CF19000
|
Size: |
20480
|
|
826E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1521790674.000000000826E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
826E000
|
Size: |
8192
|
|
7FF5BE3DF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1538801463.00007FF5BE3DF000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE3DF000
|
Size: |
28672
|
|
7DF4DEC80000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1865872348.00007DF4DEC80000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7DF4DEC80000
|
Size: |
4096
|
|
7A54000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658707759.0000000007A54000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A54000
|
Size: |
4096
|
|
CB93000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2667015077.000000000CB93000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB93000
|
Size: |
4096
|
|
9CE2000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1523845606.0000000009CE2000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9CE2000
|
Size: |
12288
|
|
9B06000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2662764839.0000000009B06000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9B06000
|
Size: |
122880
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1A60051B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1815974500.000001A60051B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1A60051B000
|
Size: |
40960
|
|
22D201E3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1353244519.0000022D201E3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D201E3000
|
Size: |
49152
|
|
7FFC3C61D000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1866174686.00007FFC3C61D000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7FFC3C61D000
|
Size: |
12288
|
|
7A7C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1519605877.0000000007A7C000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A7C000
|
Size: |
12288
|
|
CB5C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2667015077.000000000CB5C000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB5C000
|
Size: |
12288
|
|
7FF5BE6D3000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2674322359.00007FF5BE6D3000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE6D3000
|
Size: |
4096
|
|
1275000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1516272071.0000000001275000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1275000
|
Size: |
45056
|
|
7AEB000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658707759.0000000007AEB000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7AEB000
|
Size: |
421888
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
35CD000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.2655735535.00000000035CD000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
35CD000
|
Size: |
458752
|
|
3341000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.1656803800.0000000003341000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3341000
|
Size: |
16384
|
|
B7C0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1531501518.000000000B7C0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
B7C0000
|
Size: |
4096
|
|
400000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1645634367.0000000000400000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
400000
|
Size: |
4096
|
|
7FF5BE73E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1542335601.00007FF5BE73E000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE73E000
|
Size: |
4096
|
|
7FF5BE72E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2674707114.00007FF5BE72E000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE72E000
|
Size: |
20480
|
|
57AA000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1519187039.00000000057AA000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
57AA000
|
Size: |
4096
|
|
CB87000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1533280630.000000000CB87000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB87000
|
Size: |
4096
|
|
7FF5BE4C6000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1539480547.00007FF5BE4C6000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE4C6000
|
Size: |
12288
|
|
34A0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.2655735535.00000000034A0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
34A0000
|
Size: |
1208320
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7FF5BE9AD000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1547024290.00007FF5BE9AD000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE9AD000
|
Size: |
12288
|
|
1641000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2655102744.0000000001641000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1641000
|
Size: |
12288
|
|
7FFC3C8E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1871394917.00007FFC3C8E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFC3C8E0000
|
Size: |
65536
|
|
2B59C560000
|
heap
|
page readonly
|
|
|
|
Name: |
00000003.00000002.1516566638.000002B59C560000.00000002.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page readonly
|
Base address: |
2B59C560000
|
Size: |
4096
|
|
C4EB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1532894550.000000000C4EB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C4EB000
|
Size: |
20480
|
|
7FFC3C8A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1870378995.00007FFC3C8A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFC3C8A0000
|
Size: |
65536
|
|
AA4D000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2664786423.000000000AA4D000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AA4D000
|
Size: |
28672
|
|
837D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2660823433.000000000837D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
837D000
|
Size: |
12288
|
|
12C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2654722517.00000000012C0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12C0000
|
Size: |
4096
|
|
8DF8000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2662086552.0000000008DF8000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8DF8000
|
Size: |
32768
|
|
7FF5BE72C000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1542265186.00007FF5BE72C000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE72C000
|
Size: |
4096
|
|
7FF5BE44D000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1538901587.00007FF5BE44D000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE44D000
|
Size: |
28672
|
|
22D201DC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1352310645.0000022D201DC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D201DC000
|
Size: |
24576
|
|
7FF5BE857000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1543460875.00007FF5BE857000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE857000
|
Size: |
20480
|
|
9C20000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2662764839.0000000009C20000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9C20000
|
Size: |
4096
|
|
9C06000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2071685840.0000000009C06000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9C06000
|
Size: |
12288
|
|
2FAE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1516838907.0000000002FAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2FAE000
|
Size: |
8192
|
|
CB79000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2667015077.000000000CB79000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB79000
|
Size: |
4096
|
|
9C28000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2071685840.0000000009C28000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9C28000
|
Size: |
741376
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
1A67B010000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1859882524.000001A67B010000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1A67B010000
|
Size: |
12288
|
|
2B59E4BD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1517714752.000002B59E4BD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B59E4BD000
|
Size: |
237568
|
|
7FF5BE43B000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1538901587.00007FF5BE43B000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE43B000
|
Size: |
24576
|
|
ABAF000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1528246779.000000000ABAF000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
ABAF000
|
Size: |
4096
|
|
4E9A000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658241863.0000000004E9A000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4E9A000
|
Size: |
12288
|
|
2B59E497000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1517714752.000002B59E497000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B59E497000
|
Size: |
94208
|
|
61A3EFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1815116459.00000061A3EFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
61A3EFE000
|
Size: |
8192
|
|
3140000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2655340409.0000000003140000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3140000
|
Size: |
192512
|
|
2B59C5D7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1516637066.000002B59C5D7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B59C5D7000
|
Size: |
12288
|
|
1147F000
|
system
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2670125824.000000001147F000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
1147F000
|
Size: |
4096
|
|
7C1D000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1519605877.0000000007C1D000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7C1D000
|
Size: |
73728
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
7FF5BEA59000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1548786655.00007FF5BEA59000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BEA59000
|
Size: |
24576
|
|
22D21EEE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1353404057.0000022D21EEE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D21EEE000
|
Size: |
8192
|
|
1A67D3F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1865835712.000001A67D3F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A67D3F0000
|
Size: |
4096
|
|
D4C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1642235066.0000000000D4C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
D4C000
|
Size: |
16384
|
|
2F5D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2655145082.0000000002F5D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F5D000
|
Size: |
20480
|
|
97E0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1523347577.00000000097E0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
97E0000
|
Size: |
8192
|
|
7FF5BE64C000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1540797059.00007FF5BE64C000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE64C000
|
Size: |
4096
|
|
CB60000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1533280630.000000000CB60000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB60000
|
Size: |
16384
|
|
39AF000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2656227759.00000000039AF000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
39AF000
|
Size: |
4096
|
|
7F60000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1521435083.0000000007F60000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7F60000
|
Size: |
4096
|
|
CCBC000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2667669675.000000000CCBC000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CCBC000
|
Size: |
4096
|
|
C20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2639547989.0000000000C20000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
C20000
|
Size: |
139264
|
|
7FF5BE0E7000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2670793564.00007FF5BE0E7000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE0E7000
|
Size: |
12288
|
|
7FF5BE7E8000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2675643321.00007FF5BE7E8000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE7E8000
|
Size: |
12288
|
|
7FF5BE39A000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1538660870.00007FF5BE39A000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE39A000
|
Size: |
16384
|
|
9AC2000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2662764839.0000000009AC2000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9AC2000
|
Size: |
12288
|
|
7FF5BE64A000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1540712339.00007FF5BE64A000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE64A000
|
Size: |
4096
|
|
9C22000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2662764839.0000000009C22000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9C22000
|
Size: |
4096
|
|
2B59C5ED000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1516637066.000002B59C5ED000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B59C5ED000
|
Size: |
20480
|
|
5F70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2124567743.0000000005F70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F70000
|
Size: |
143360
|
|
37A0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1517506607.00000000037A0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
37A0000
|
Size: |
8192
|
|
22D201F3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1352513444.0000022D201F3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D201F3000
|
Size: |
57344
|
|
C20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2537491823.0000000000C20000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
C20000
|
Size: |
139264
|
|
149A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1644030200.000000000149A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
149A000
|
Size: |
131072
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
22D201D7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1352682450.0000022D201D7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D201D7000
|
Size: |
16384
|
|
2B59C490000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1516441874.000002B59C490000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B59C490000
|
Size: |
20480
|
|
CC6A000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1535163726.000000000CC6A000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CC6A000
|
Size: |
12288
|
|
1A67CF1F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1861529844.000001A67CF1F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A67CF1F000
|
Size: |
286720
|
|
7ADF000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2072664500.0000000007ADF000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7ADF000
|
Size: |
45056
|
|
7FF5BE9E8000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2678834689.00007FF5BE9E8000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE9E8000
|
Size: |
12288
|
|
7FF5BE9FB000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2678834689.00007FF5BE9FB000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE9FB000
|
Size: |
65536
|
|
7FF5BEA60000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2679518718.00007FF5BEA60000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BEA60000
|
Size: |
12288
|
|
13CD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2654937842.00000000013CD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13CD000
|
Size: |
73728
|
|
D154000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2071160029.000000000D154000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D154000
|
Size: |
45056
|
|
9AF0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2072108638.0000000009AF0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9AF0000
|
Size: |
77824
|
|
61A427E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1815617899.00000061A427E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
61A427E000
|
Size: |
8192
|
|
A540000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1527343662.000000000A540000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
A540000
|
Size: |
4096
|
|
7FF5BE810000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1542827443.00007FF5BE810000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE810000
|
Size: |
16384
|
|
7FF5BE4E3000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1539893603.00007FF5BE4E3000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE4E3000
|
Size: |
12288
|
|
38D3000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2656159546.00000000038D3000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
38D3000
|
Size: |
53248
|
|
2FC0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2655483925.0000000002FC0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2FC0000
|
Size: |
8192
|
|
4E80000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1518947042.0000000004E80000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4E80000
|
Size: |
4096
|
|
3141000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1663310738.0000000003141000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3141000
|
Size: |
225280
|
|
C934D3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1516186832.000000C934D3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C934D3E000
|
Size: |
8192
|
|
1A67AED0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1856085778.000001A67AED0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A67AED0000
|
Size: |
4096
|
|
AA92000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2664786423.000000000AA92000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AA92000
|
Size: |
208896
|
|
22D201F3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1352235267.0000022D201F3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D201F3000
|
Size: |
57344
|
|
9D37000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2662764839.0000000009D37000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9D37000
|
Size: |
98304
|
|
5A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1645709056.00000000005A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5A0000
|
Size: |
20480
|
|
2B59C617000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1516637066.000002B59C617000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B59C617000
|
Size: |
8192
|
|
7FF5BE6BB000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1541761153.00007FF5BE6BB000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE6BB000
|
Size: |
12288
|
|
C9FB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2666958880.000000000C9FB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C9FB000
|
Size: |
20480
|
|
2B5A075F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1517714752.000002B5A075F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B5A075F000
|
Size: |
10485760
|
|
CBBE000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2667669675.000000000CBBE000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CBBE000
|
Size: |
24576
|
|
B186000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2665962094.000000000B186000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
B186000
|
Size: |
110592
|
|
C97C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1533081576.000000000C97C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C97C000
|
Size: |
16384
|
|
7B53000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658707759.0000000007B53000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7B53000
|
Size: |
4096
|
|
2B59C5CD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1516637066.000002B59C5CD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B59C5CD000
|
Size: |
12288
|
|
39F0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2657272017.00000000039F0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
39F0000
|
Size: |
925696
|
|
D6DF000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2073336816.000000000D6DF000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D6DF000
|
Size: |
8192
|
|
CB75000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1533280630.000000000CB75000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB75000
|
Size: |
4096
|
|
3857000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2656124249.0000000003857000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3857000
|
Size: |
36864
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1663486350.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|
3790000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2655969619.0000000003790000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3790000
|
Size: |
4096
|
|
1A600121000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1815974500.000001A600121000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1A600121000
|
Size: |
217088
|
|
9C0B000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1523845606.0000000009C0B000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9C0B000
|
Size: |
69632
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
CEB2000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1535163726.000000000CEB2000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CEB2000
|
Size: |
249856
|
|
7FF5BE815000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1542827443.00007FF5BE815000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE815000
|
Size: |
4096
|
|
7FF5BE4E1000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1539893603.00007FF5BE4E1000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE4E1000
|
Size: |
4096
|
|
7FF5BE7D8000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2675384107.00007FF5BE7D8000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE7D8000
|
Size: |
32768
|
|
7FF5BE65C000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2673632483.00007FF5BE65C000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE65C000
|
Size: |
4096
|
|
39A2000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1517673112.00000000039A2000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
39A2000
|
Size: |
24576
|
|
AB50000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1528246779.000000000AB50000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AB50000
|
Size: |
4096
|
|
22D201C4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1353230588.0000022D201C4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D201C4000
|
Size: |
8192
|
|
7FF5BE8CE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1544628974.00007FF5BE8CE000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE8CE000
|
Size: |
45056
|
|
375A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1517420769.000000000375A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
375A000
|
Size: |
24576
|
|
9950000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2662609847.0000000009950000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9950000
|
Size: |
4096
|
|
2B59DFD4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1517322004.000002B59DFD4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B59DFD4000
|
Size: |
4096
|
|
33CA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1517211538.00000000033CA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
33CA000
|
Size: |
24576
|
|
1A67B095000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1860404395.000001A67B095000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A67B095000
|
Size: |
40960
|
|
39AB000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2656227759.00000000039AB000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
39AB000
|
Size: |
4096
|
|
CC76000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2667669675.000000000CC76000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CC76000
|
Size: |
8192
|
|
7FF5BE695000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1541350455.00007FF5BE695000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE695000
|
Size: |
4096
|
|
7FF5BE923000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2677281947.00007FF5BE923000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE923000
|
Size: |
12288
|
|
D6DF000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1536938353.000000000D6DF000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D6DF000
|
Size: |
8192
|
|
7FF5BE975000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1545869743.00007FF5BE975000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE975000
|
Size: |
4096
|
|
7FF5BE5B1000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2673127038.00007FF5BE5B1000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE5B1000
|
Size: |
8192
|
|
7A9E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658707759.0000000007A9E000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A9E000
|
Size: |
12288
|
|
2B59DFD6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1517322004.000002B59DFD6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B59DFD6000
|
Size: |
4096
|
|
BEAB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2666757124.000000000BEAB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BEAB000
|
Size: |
20480
|
|
AA3C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1528246779.000000000AA3C000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AA3C000
|
Size: |
4096
|
|
7FF5BE973000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2677755689.00007FF5BE973000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE973000
|
Size: |
4096
|
|
7DF4C97F0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2670578366.00007DF4C97F0000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7DF4C97F0000
|
Size: |
4096
|
|
7FF5BE38B000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2671176818.00007FF5BE38B000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE38B000
|
Size: |
36864
|
|
CBC7000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2667669675.000000000CBC7000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CBC7000
|
Size: |
8192
|
|
837D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1521827661.000000000837D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
837D000
|
Size: |
12288
|
|
B180000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2665962094.000000000B180000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
B180000
|
Size: |
16384
|
|
2F49000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1641510356.0000000002F49000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F49000
|
Size: |
24576
|
|
7A68000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658707759.0000000007A68000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A68000
|
Size: |
4096
|
|
7FF5BE4A7000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1539436588.00007FF5BE4A7000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE4A7000
|
Size: |
12288
|
|
83FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1521858884.00000000083FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
83FE000
|
Size: |
8192
|
|
BD25000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1532648633.000000000BD25000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BD25000
|
Size: |
45056
|
|
81B0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1521752356.00000000081B0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
81B0000
|
Size: |
8192
|
|
39AD000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2656227759.00000000039AD000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
39AD000
|
Size: |
4096
|
|
7FF5BE911000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1544987780.00007FF5BE911000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE911000
|
Size: |
32768
|
|
2F3E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1641724109.0000000002F3E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F3E000
|
Size: |
24576
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1644489238.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|
22D201BC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1352310645.0000022D201BC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D201BC000
|
Size: |
16384
|
|
398A000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2656227759.000000000398A000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
398A000
|
Size: |
4096
|
|
7FFC3C890000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1870118679.00007FFC3C890000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFC3C890000
|
Size: |
65536
|
|
12E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2654770366.00000000012E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12E0000
|
Size: |
32768
|
|
CE0E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1535163726.000000000CE0E000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CE0E000
|
Size: |
20480
|
|
39F0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1518254911.00000000039F0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
39F0000
|
Size: |
925696
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1713958128.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|
7FF5BE889000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1544098397.00007FF5BE889000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE889000
|
Size: |
24576
|
|
7FF5BE5D8000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1540501312.00007FF5BE5D8000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE5D8000
|
Size: |
4096
|
|
22D201F3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1352310645.0000022D201F3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D201F3000
|
Size: |
57344
|
|
1A610074000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1850110008.000001A610074000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1A610074000
|
Size: |
36864
|
|
9D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1645889772.00000000009D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D0000
|
Size: |
12288
|
|
1A67AF35000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1856126504.000001A67AF35000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A67AF35000
|
Size: |
12288
|
|
22D201F3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1352467182.0000022D201F3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D201F3000
|
Size: |
57344
|
|
7FF5BE886000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2676536259.00007FF5BE886000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE886000
|
Size: |
4096
|
|
7FF5BEA18000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2678834689.00007FF5BEA18000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BEA18000
|
Size: |
12288
|
|
2F4F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1641349176.0000000002F4F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F4F000
|
Size: |
20480
|
|
D134000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2071451455.000000000D134000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D134000
|
Size: |
110592
|
|
7FF5BE989000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1546518329.00007FF5BE989000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE989000
|
Size: |
12288
|
|
12D0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1516362409.00000000012D0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
12D0000
|
Size: |
24576
|
|
7FF5BE498000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1539238170.00007FF5BE498000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE498000
|
Size: |
36864
|
|
8F40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2662198753.0000000008F40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F40000
|
Size: |
4096
|
|
A610000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2664375903.000000000A610000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
A610000
|
Size: |
4096
|
|
D6B5000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2669334400.000000000D6B5000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D6B5000
|
Size: |
8192
|
|
4EC0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2658355595.0000000004EC0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4EC0000
|
Size: |
16384
|
|
AB47000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2664786423.000000000AB47000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AB47000
|
Size: |
4096
|
|
7FF5BE457000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2671869730.00007FF5BE457000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE457000
|
Size: |
28672
|
|
C20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2588549934.0000000000C20000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
C20000
|
Size: |
139264
|
|
2B59C5D3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1516637066.000002B59C5D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B59C5D3000
|
Size: |
4096
|
|
2B59DFD9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1517446591.000002B59DFD9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B59DFD9000
|
Size: |
204800
|
|
CB8F000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1533280630.000000000CB8F000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CB8F000
|
Size: |
4096
|
|
7FF5BE7FC000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2675776420.00007FF5BE7FC000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE7FC000
|
Size: |
40960
|
|
7FF5BE810000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2675776420.00007FF5BE810000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE810000
|
Size: |
16384
|
|
4DD1000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2657432976.0000000004DD1000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4DD1000
|
Size: |
4096
|
|
7FFC3C7C1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1867274988.00007FFC3C7C1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFC3C7C1000
|
Size: |
28672
|
|
1A67C9EB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1860930525.000001A67C9EB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A67C9EB000
|
Size: |
4096
|
|
7FF5BE6A1000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1541528965.00007FF5BE6A1000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE6A1000
|
Size: |
4096
|
|
7FF5BE5B1000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1540451644.00007FF5BE5B1000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE5B1000
|
Size: |
8192
|
|
8A20000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1522331962.0000000008A20000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8A20000
|
Size: |
8192
|
|
97F0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1523374207.00000000097F0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
97F0000
|
Size: |
8192
|
|
7FF5BE6B3000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2674071182.00007FF5BE6B3000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE6B3000
|
Size: |
4096
|
|
1A67D120000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1865332423.000001A67D120000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A67D120000
|
Size: |
28672
|
|
38F0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1517673112.00000000038F0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
38F0000
|
Size: |
561152
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
7FFC3C8D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1871130982.00007FFC3C8D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FFC3C8D0000
|
Size: |
65536
|
|
7FF5BE8B4000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2676879946.00007FF5BE8B4000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE8B4000
|
Size: |
20480
|
|
19D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1645581670.000000000019D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
19D000
|
Size: |
12288
|
|
9CDE000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1523845606.0000000009CDE000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9CDE000
|
Size: |
12288
|
|
7DF4C97D1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000007.00000002.2670496893.00007DF4C97D1000.00000020.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7DF4C97D1000
|
Size: |
4096
|
|
4E07000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1518362137.0000000004E07000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4E07000
|
Size: |
16384
|
|
331E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2655578841.000000000331E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
331E000
|
Size: |
8192
|
|
7A3A000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1519605877.0000000007A3A000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A3A000
|
Size: |
8192
|
|
2F2D0FB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1352999025.0000002F2D0FB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2F2D0FB000
|
Size: |
20480
|
|
1A67CF68000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1861529844.000001A67CF68000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A67CF68000
|
Size: |
192512
|
|
AA8E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2664786423.000000000AA8E000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AA8E000
|
Size: |
4096
|
|
1A67AF39000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1856126504.000001A67AF39000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A67AF39000
|
Size: |
4096
|
|
7FF5BEA60000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1548786655.00007FF5BEA60000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BEA60000
|
Size: |
12288
|
|
7FFC3C6D0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1866630674.00007FFC3C6D0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7FFC3C6D0000
|
Size: |
24576
|
|
D096000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2073197514.000000000D096000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D096000
|
Size: |
8192
|
|
7FF5BE616000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1540599308.00007FF5BE616000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE616000
|
Size: |
4096
|
|
7FF5BE808000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2675776420.00007FF5BE808000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE808000
|
Size: |
8192
|
|
B1A2000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2073216051.000000000B1A2000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
B1A2000
|
Size: |
8192
|
|
12E9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1516382431.00000000012E9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12E9000
|
Size: |
1007616
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
5F70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2230808498.0000000005F70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F70000
|
Size: |
139264
|
|
6AF000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1645728448.00000000006AF000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
6AF000
|
Size: |
4096
|
|
3790000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1517480478.0000000003790000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3790000
|
Size: |
4096
|
|
7FF5BE64C000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2673510884.00007FF5BE64C000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE64C000
|
Size: |
4096
|
|
1A60044D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1815974500.000001A60044D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1A60044D000
|
Size: |
835584
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1644733722.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|
BEAB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1532839190.000000000BEAB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BEAB000
|
Size: |
20480
|
|
2B5A575F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1517714752.000002B5A575F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B5A575F000
|
Size: |
9240576
|
|
1A67CFE2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1863818697.000001A67CFE2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A67CFE2000
|
Size: |
16384
|
|
81A0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1521709488.00000000081A0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
81A0000
|
Size: |
4096
|
|
C5E8000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1532969483.000000000C5E8000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C5E8000
|
Size: |
32768
|
|
CBB9000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1535163726.000000000CBB9000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CBB9000
|
Size: |
12288
|
|
7FF5BEA18000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1547974039.00007FF5BEA18000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BEA18000
|
Size: |
12288
|
|
12C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1516340385.00000000012C0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12C0000
|
Size: |
4096
|
|
22D201E3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1352404694.0000022D201E3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22D201E3000
|
Size: |
49152
|
|
7FF5BE4CA000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2672170388.00007FF5BE4CA000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE4CA000
|
Size: |
4096
|
|
2DA0000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.1645980502.0000000002DA0000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
2DA0000
|
Size: |
839680
|
|
7FF5BE828000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1543359378.00007FF5BE828000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE828000
|
Size: |
4096
|
|
3130000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2655298094.0000000003130000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3130000
|
Size: |
8192
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1714085971.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|
2B59E105000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1517714752.000002B59E105000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B59E105000
|
Size: |
1728512
|
|
996A000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2662609847.000000000996A000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
996A000
|
Size: |
8192
|
|
10CDB000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1537541955.0000000010CDB000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
10CDB000
|
Size: |
188416
|
|
4EAA000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1519005418.0000000004EAA000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4EAA000
|
Size: |
12288
|
|
2E61000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.2655013115.0000000002E61000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
2E61000
|
Size: |
4096
|
|
7FF5BE0CC000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2670769440.00007FF5BE0CC000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE0CC000
|
Size: |
4096
|
|
2EF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1868055362.0000000002EF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EF0000
|
Size: |
159744
|
|
7FF5BE808000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1542827443.00007FF5BE808000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE808000
|
Size: |
8192
|
|
7FF5BE86B000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1543723765.00007FF5BE86B000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE86B000
|
Size: |
28672
|
|
A539000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1527169502.000000000A539000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
A539000
|
Size: |
28672
|
|
10C54000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2669741529.0000000010C54000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
10C54000
|
Size: |
229376
|
|
B20B000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2073272620.000000000B20B000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
B20B000
|
Size: |
24576
|
|
12E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1516382431.00000000012E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12E0000
|
Size: |
32768
|
|
7FF5BE5D2000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2673153770.00007FF5BE5D2000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE5D2000
|
Size: |
4096
|
|
7FF5BE530000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1540286560.00007FF5BE530000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE530000
|
Size: |
4096
|
|
A2BD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2663922992.000000000A2BD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
A2BD000
|
Size: |
12288
|
|
7FF5BE92F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1545289458.00007FF5BE92F000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE92F000
|
Size: |
8192
|
|
7A34000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1519605877.0000000007A34000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A34000
|
Size: |
12288
|
|
7FF5BE445000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2671523951.00007FF5BE445000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE445000
|
Size: |
12288
|
|
7DF4C97D1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000007.00000000.1537886006.00007DF4C97D1000.00000020.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7DF4C97D1000
|
Size: |
4096
|
|
7FF5BE9FB000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1547974039.00007FF5BE9FB000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF5BE9FB000
|
Size: |
65536
|
|
3271000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1641084267.0000000003271000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3271000
|
Size: |
512000
|
|
FD0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2654640437.0000000000FD0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
FD0000
|
Size: |
4096
|
|
CE69000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1535163726.000000000CE69000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
CE69000
|
Size: |
159744
|
|
399A000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2656227759.000000000399A000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
399A000
|
Size: |
20480
|
|
4D68000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1518362137.0000000004D68000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4D68000
|
Size: |
12288
|
|
1A6003DA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1815974500.000001A6003DA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1A6003DA000
|
Size: |
102400
|
|
CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1644696620.0000000000CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE4000
|
Size: |
4096
|
|