4540000
|
unclassified section
|
page execute and read and write
|
 |
|
|
Name: |
00000008.00000002.3469653795.0000000004540000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
4540000
|
Size: |
376832
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected WebBrowserPassView password recovery tool |
Stealing of Sensitive Information |
|
Found strings which match to known social media urls |
Networking |
|
SQL strings found in memory and binary data |
System Summary |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
400000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
00000009.00000002.1150649991.0000000000400000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
400000
|
Size: |
376832
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected WebBrowserPassView password recovery tool |
Stealing of Sensitive Information |
|
Found strings which match to known social media urls |
Networking |
|
SQL strings found in memory and binary data |
System Summary |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
400000
|
remote allocation
|
page execute and read and write
|
 |
|
|
Name: |
00000008.00000002.3466361375.0000000000400000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
400000
|
Size: |
475136
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected Remcos RAT |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected UAC Bypass using CMSTP |
Exploits |
|
Yara detected Keylogger Generic |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
|
Yara signature match |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
11E7000
|
heap
|
page read and write
|
 |
|
|
Name: |
00000008.00000002.3467761348.00000000011E7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11E7000
|
Size: |
196608
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Found malware configuration |
AV Detection |
|
Yara detected Remcos RAT |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
5FC6000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000005.00000002.1081213353.0000000005FC6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5FC6000
|
Size: |
1298432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected Remcos RAT |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected UAC Bypass using CMSTP |
Exploits |
|
Yara detected Keylogger Generic |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
|
Yara signature match |
System Summary |
|
Public key (encryption) found |
Cryptography |
|
URLs found in memory or binary data |
Networking |
|
|
6382000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000005.00000002.1081213353.0000000006382000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6382000
|
Size: |
1167360
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected Remcos RAT |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected UAC Bypass using CMSTP |
Exploits |
|
Yara detected Keylogger Generic |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
|
Yara signature match |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
33DD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1151078577.00000000033DD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
33DD000
|
Size: |
12288
|
|
86BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1094963708.00000000086BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
86BE000
|
Size: |
8192
|
|
738A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1091426835.000000000738A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
738A000
|
Size: |
24576
|
|
5980000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1045544811.0000000005980000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5980000
|
Size: |
4096
|
|
29365861000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1364350143.0000029365861000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29365861000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
5B89000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1020431192.0000000005B89000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5B89000
|
Size: |
16384
|
|
29365832000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1364645984.0000029365832000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29365832000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4D64000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1150372409.0000000004D64000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D64000
|
Size: |
20480
|
|
3094000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1128813657.0000000003094000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3094000
|
Size: |
8192
|
|
3094000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1128775620.0000000003094000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3094000
|
Size: |
8192
|
|
799000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1021306896.0000000000799000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
799000
|
Size: |
4096
|
|
5B71000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1020489483.0000000005B71000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5B71000
|
Size: |
20480
|
|
29365835000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1363885308.0000029365835000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29365835000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
757E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1091675278.000000000757E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
757E000
|
Size: |
8192
|
|
583F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1045294461.000000000583F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
583F000
|
Size: |
4096
|
|
2A8B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1044310929.0000000002A8B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A8B000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4D81000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1127545333.0000000004D81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D81000
|
Size: |
110592
|
|
ADC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1077466665.0000000000ADC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
ADC000
|
Size: |
16384
|
|
4D81000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1146315748.0000000004D81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D81000
|
Size: |
36864
|
|
2A86000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1042571960.0000000002A86000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A86000
|
Size: |
12288
|
|
7940000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.1093211703.0000000007940000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7940000
|
Size: |
8192
|
|
2B68C7B000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2811880822.0000002B68C7B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2B68C7B000
|
Size: |
20480
|
|
4DA2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1146419186.0000000004DA2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DA2000
|
Size: |
135168
|
|
4D81000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1144150834.0000000004D81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D81000
|
Size: |
118784
|
|
4E3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1045084482.0000000004E3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4E3E000
|
Size: |
8192
|
|
52A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1023178257.00000000052A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
52A0000
|
Size: |
4096
|
|
4D2C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1022805669.0000000004D2C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4D2C000
|
Size: |
16384
|
|
7990000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1093817094.0000000007990000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7990000
|
Size: |
65536
|
|
7680000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1091725139.0000000007680000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7680000
|
Size: |
4096
|
|
5251000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1130581726.0000000005251000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5251000
|
Size: |
4096
|
|
4BEF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1022642964.0000000004BEF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4BEF000
|
Size: |
4096
|
|
21A94EB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.1204221660.0000021A94EB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21A94EB0000
|
Size: |
4096
|
|
4E50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1045112614.0000000004E50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4E50000
|
Size: |
4096
|
|
5F0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1120661158.00000000005F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5F0000
|
Size: |
4096
|
|
4F7000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1020738610.00000000004F7000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4F7000
|
Size: |
8192
|
|
7699000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1091746051.0000000007699000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7699000
|
Size: |
77824
|
|
5A6C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1045798893.0000000005A6C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5A6C000
|
Size: |
45056
|
|
79B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1093973737.00000000079B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
79B0000
|
Size: |
65536
|
|
10016000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3471536687.0000000010016000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
10016000
|
Size: |
8192
|
|
5A18000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1045692773.0000000005A18000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5A18000
|
Size: |
28672
|
|
78C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1027372778.000000000078C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
78C000
|
Size: |
16384
|
|
4D75000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1127697478.0000000004D75000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D75000
|
Size: |
4096
|
|
2FA3000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.1077758155.0000000002FA3000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
2FA3000
|
Size: |
4096
|
|
C24000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1022064761.0000000000C24000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C24000
|
Size: |
4096
|
|
21A9502E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2812668202.0000021A9502E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A9502E000
|
Size: |
61440
|
|
9DC000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1120724465.00000000009DC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9DC000
|
Size: |
24576
|
|
2936587A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1365855166.000002936587A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2936587A000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
D47000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1027972793.0000000000D47000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D47000
|
Size: |
49152
|
|
29365844000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1364601376.0000029365844000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29365844000
|
Size: |
36864
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2A90000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1021899924.0000000002A90000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A90000
|
Size: |
8192
|
|
773B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1092014147.000000000773B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
773B000
|
Size: |
8192
|
|
79A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1093898590.00000000079A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
79A0000
|
Size: |
65536
|
|
5276000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078641425.0000000005276000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5276000
|
Size: |
12288
|
|
5282000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078641425.0000000005282000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5282000
|
Size: |
36864
|
|
7B3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1021330031.00000000007B3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7B3000
|
Size: |
77824
|
|
2A95000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1021785611.0000000002A95000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A95000
|
Size: |
61440
|
|
4D7E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1141485761.0000000004D7E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D7E000
|
Size: |
4096
|
|
A4F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1021981374.0000000000A4F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
A4F000
|
Size: |
4096
|
|
5DBF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1023341462.0000000005DBF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5DBF000
|
Size: |
4096
|
|
21A94E50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.2809472514.0000021A94E50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21A94E50000
|
Size: |
4096
|
|
D3C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3467234289.0000000000D3C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
D3C000
|
Size: |
16384
|
|
29365F40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1366110504.0000029365F40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29365F40000
|
Size: |
4096
|
|
780A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1092714773.000000000780A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
780A000
|
Size: |
24576
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
ED79C7E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1364940892.000000ED79C7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
ED79C7E000
|
Size: |
8192
|
|
2A65000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1042426514.0000000002A65000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A65000
|
Size: |
4096
|
|
538E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1151633694.000000000538E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
538E000
|
Size: |
8192
|
|
758000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1021137529.0000000000758000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
758000
|
Size: |
86016
|
|
7830000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.1092879569.0000000007830000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
7830000
|
Size: |
4096
|
|
5A65000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1039125318.0000000005A65000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5A65000
|
Size: |
65536
|
|
4D7E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1138904036.0000000004D7E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D7E000
|
Size: |
4096
|
|
7D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1018686235.00000000007D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7D0000
|
Size: |
69632
|
|
825000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1018686235.0000000000825000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
825000
|
Size: |
4096
|
|
803000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1015572665.0000000000803000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
803000
|
Size: |
77824
|
|
803000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1016044709.0000000000803000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
803000
|
Size: |
77824
|
|
5251000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1128470471.0000000005251000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5251000
|
Size: |
225280
|
|
82D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1021856750.000000000082D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
82D000
|
Size: |
114688
|
|
21A90640000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.2811149856.0000021A90640000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21A90640000
|
Size: |
4096
|
|
8410000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.1094628507.0000000008410000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
8410000
|
Size: |
32768
|
|
7B3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1019693985.00000000007B3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7B3000
|
Size: |
77824
|
|
3673000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1121425570.0000000003673000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3673000
|
Size: |
4096
|
|
3294000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1120384934.0000000003294000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3294000
|
Size: |
4096
|
|
9A72000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1105375716.0000000009A72000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9A72000
|
Size: |
8192
|
|
7E9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1015290460.00000000007E9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E9000
|
Size: |
94208
|
|
4D81000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1141485761.0000000004D81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D81000
|
Size: |
151552
|
|
520E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1023135243.000000000520E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
520E000
|
Size: |
8192
|
|
4D64000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1150454430.0000000004D64000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D64000
|
Size: |
20480
|
|
2936582B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1365450419.000002936582B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2936582B000
|
Size: |
24576
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4B80000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.1078529586.0000000004B80000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
4B80000
|
Size: |
4096
|
|
4D81000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1141254877.0000000004D81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D81000
|
Size: |
155648
|
|
301B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1150759009.000000000301B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
301B000
|
Size: |
8192
|
|
ED79B7E000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000E.00000002.1364913401.000000ED79B7E000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
ED79B7E000
|
Size: |
4096
|
|
4D83000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1146393589.0000000004D83000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D83000
|
Size: |
28672
|
|
3E4F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3469519147.0000000003E4F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3E4F000
|
Size: |
4096
|
|
5BE3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1038755780.0000000005BE3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5BE3000
|
Size: |
61440
|
|
2936585A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1364626820.000002936585A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2936585A000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
21A94D90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.1204248812.0000021A94D90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21A94D90000
|
Size: |
8192
|
|
6D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1021015483.00000000006D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6D0000
|
Size: |
4096
|
|
53A1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1120075869.00000000053A1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
53A1000
|
Size: |
65536
|
|
59DB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1045637073.00000000059DB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
59DB000
|
Size: |
4096
|
|
21A8F85B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2812153699.0000021A8F85B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A8F85B000
|
Size: |
20480
|
|
7780000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1092525250.0000000007780000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7780000
|
Size: |
65536
|
|
5862000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1149172796.0000000005862000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5862000
|
Size: |
1220608
|
|
3190000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078131261.0000000003190000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3190000
|
Size: |
4096
|
|
5251000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1130067098.0000000005251000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5251000
|
Size: |
4096
|
|
3390000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1121703556.0000000003390000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3390000
|
Size: |
24576
|
|
585000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1020823159.0000000000585000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
585000
|
Size: |
16384
|
|
4D8A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1144791726.0000000004D8A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D8A000
|
Size: |
45056
|
|
2DFC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1150737559.0000000002DFC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2DFC000
|
Size: |
16384
|
|
7210000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1091141981.0000000007210000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7210000
|
Size: |
262144
|
|
3294000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1120371900.0000000003294000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3294000
|
Size: |
4096
|
|
4D61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1141018969.0000000004D61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D61000
|
Size: |
36864
|
|
5251000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1129871757.0000000005251000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5251000
|
Size: |
4096
|
|
4D5D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1044957949.0000000004D5D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4D5D000
|
Size: |
12288
|
|
825000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1019031613.0000000000825000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
825000
|
Size: |
4096
|
|
5A6C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1042660961.0000000005A6C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5A6C000
|
Size: |
45056
|
|
4D81000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1141360415.0000000004D81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D81000
|
Size: |
167936
|
|
4D6C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1143872342.0000000004D6C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D6C000
|
Size: |
20480
|
|
3294000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1121353986.0000000003294000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3294000
|
Size: |
4096
|
|
303E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1077986034.000000000303E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
303E000
|
Size: |
94208
|
|
3294000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1120473562.0000000003294000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3294000
|
Size: |
4096
|
|
3398000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1121703556.0000000003398000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3398000
|
Size: |
102400
|
|
4D7E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1141254877.0000000004D7E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D7E000
|
Size: |
4096
|
|
4D61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1143728748.0000000004D61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D61000
|
Size: |
40960
|
|
21A8F780000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2811965824.0000021A8F780000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A8F780000
|
Size: |
12288
|
|
9A30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1105296812.0000000009A30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9A30000
|
Size: |
4096
|
|
29F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1043888883.00000000029F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29F0000
|
Size: |
45056
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4FA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1020738610.00000000004FA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4FA000
|
Size: |
24576
|
|
5251000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1120998130.0000000005251000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5251000
|
Size: |
65536
|
|
38E0000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3469164599.00000000038E0000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
38E0000
|
Size: |
106496
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Found strings which match to known social media urls |
Networking |
|
URLs found in memory or binary data |
Networking |
|
|
21A94D40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.2810830737.0000021A94D40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21A94D40000
|
Size: |
4096
|
|
59BA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1039285589.00000000059BA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
59BA000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4D75000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1146354376.0000000004D75000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D75000
|
Size: |
40960
|
|
353A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1127444559.000000000353A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
353A000
|
Size: |
20480
|
|
475000
|
remote allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3466361375.0000000000475000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
475000
|
Size: |
8192
|
|
2B03000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1039227909.0000000002B03000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B03000
|
Size: |
24576
|
|
3094000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1129177520.0000000003094000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3094000
|
Size: |
8192
|
|
3490000
|
heap
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.1121737569.0000000003490000.00000002.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page readonly
|
Base address: |
3490000
|
Size: |
4096
|
|
2AA3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1044325506.0000000002AA3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AA3000
|
Size: |
12288
|
|
4DA8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1141485761.0000000004DA8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DA8000
|
Size: |
8192
|
|
3095000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1129741201.0000000003095000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3095000
|
Size: |
4096
|
|
4DA2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1148561017.0000000004DA2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DA2000
|
Size: |
135168
|
|
5670000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1138078170.0000000005670000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5670000
|
Size: |
4096
|
|
84BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1094820049.00000000084BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
84BE000
|
Size: |
8192
|
|
21A8F8B3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.2811525813.0000021A8F8B3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A8F8B3000
|
Size: |
8192
|
|
5BBE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1038898942.0000000005BBE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5BBE000
|
Size: |
49152
|
|
806000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1021831698.0000000000806000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
806000
|
Size: |
65536
|
|
2FF2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1077886372.0000000002FF2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FF2000
|
Size: |
36864
|
|
59DB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1039285589.00000000059DB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
59DB000
|
Size: |
188416
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
21A94DD1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.1204066669.0000021A94DD1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21A94DD1000
|
Size: |
28672
|
|
5BA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1045927535.0000000005BA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5BA0000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
21A90CA1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.2810928827.0000021A90CA1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21A90CA1000
|
Size: |
4096
|
|
4D61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1139562618.0000000004D61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D61000
|
Size: |
90112
|
|
4DBC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1044973461.0000000004DBC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4DBC000
|
Size: |
16384
|
|
4D70000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1041975299.0000000004D70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D70000
|
Size: |
4096
|
|
ED797FE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1364826934.000000ED797FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
ED797FE000
|
Size: |
8192
|
|
2936584D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1364574940.000002936584D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2936584D000
|
Size: |
8192
|
|
6ECA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1081213353.0000000006ECA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6ECA000
|
Size: |
569344
|
|
400000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.1121592224.0000000000400000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
400000
|
Size: |
106496
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Found strings which match to known social media urls |
Networking |
|
URLs found in memory or binary data |
Networking |
|
|
86FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1094990953.00000000086FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
86FE000
|
Size: |
8192
|
|
816000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1015191461.0000000000816000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
816000
|
Size: |
8192
|
|
7592000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1091701472.0000000007592000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7592000
|
Size: |
4096
|
|
2AAB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1042533868.0000000002AAB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AAB000
|
Size: |
57344
|
|
57E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1020802521.000000000057E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
57E000
|
Size: |
8192
|
|
ED793DB000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1364751016.000000ED793DB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
ED793DB000
|
Size: |
20480
|
|
2A95000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1021899924.0000000002A95000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A95000
|
Size: |
12288
|
|
3294000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1120505746.0000000003294000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3294000
|
Size: |
4096
|
|
4D81000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1139107019.0000000004D81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D81000
|
Size: |
16384
|
|
10001000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3471536687.0000000010001000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
10001000
|
Size: |
77824
|
|
5A61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1040899569.0000000005A61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5A61000
|
Size: |
40960
|
|
3034000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1150759009.0000000003034000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3034000
|
Size: |
49152
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
459E000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3469653795.000000000459E000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
459E000
|
Size: |
4096
|
|
353A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1150333178.000000000353A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
353A000
|
Size: |
20480
|
|
2B692FE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2811926065.0000002B692FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2B692FE000
|
Size: |
8192
|
|
4DBA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1144411744.0000000004DBA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DBA000
|
Size: |
77824
|
|
5A20000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1045784469.0000000005A20000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5A20000
|
Size: |
12288
|
|
4D7E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1139293105.0000000004D7E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D7E000
|
Size: |
4096
|
|
70CD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1090910887.00000000070CD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
70CD000
|
Size: |
12288
|
|
5251000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1131797941.0000000005251000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5251000
|
Size: |
4096
|
|
2AA9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1021983109.0000000002AA9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AA9000
|
Size: |
28672
|
|
29365878000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1363908355.0000029365878000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29365878000
|
Size: |
69632
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2B0A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1044691350.0000000002B0A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B0A000
|
Size: |
86016
|
|
4D61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1140574179.0000000004D61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D61000
|
Size: |
40960
|
|
341E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1151102323.000000000341E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
341E000
|
Size: |
8192
|
|
5BFC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1039002518.0000000005BFC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5BFC000
|
Size: |
319488
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
5BCA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1038755780.0000000005BCA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5BCA000
|
Size: |
57344
|
|
5868000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1148844139.0000000005868000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5868000
|
Size: |
1073152
|
|
3520000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1151151711.0000000003520000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3520000
|
Size: |
4096
|
|
5350000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1121058409.0000000005350000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5350000
|
Size: |
167936
|
|
DD5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3467432700.0000000000DD5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DD5000
|
Size: |
16384
|
|
4D81000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1141160641.0000000004D81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D81000
|
Size: |
139264
|
|
30B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1150953518.00000000030B0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30B0000
|
Size: |
4096
|
|
29365843000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1365539019.0000029365843000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29365843000
|
Size: |
4096
|
|
74BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1091573633.00000000074BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
74BE000
|
Size: |
8192
|
|
680000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1020877305.0000000000680000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
680000
|
Size: |
4096
|
|
293658AD000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1366051709.00000293658AD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
293658AD000
|
Size: |
8192
|
|
2F10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1077627303.0000000002F10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F10000
|
Size: |
4096
|
|
2C1E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1044734982.0000000002C1E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2C1E000
|
Size: |
8192
|
|
4D7E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1141018969.0000000004D7E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D7E000
|
Size: |
4096
|
|
1F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1020718196.00000000001F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F0000
|
Size: |
8192
|
|
4D81000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1144485930.0000000004D81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D81000
|
Size: |
24576
|
|
5BE3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1038932370.0000000005BE3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5BE3000
|
Size: |
53248
|
|
2ADC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1041599868.0000000002ADC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2ADC000
|
Size: |
24576
|
|
2F8E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1077676458.0000000002F8E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2F8E000
|
Size: |
8192
|
|
548F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1151652842.000000000548F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
548F000
|
Size: |
4096
|
|
3294000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1120101241.0000000003294000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3294000
|
Size: |
4096
|
|
32E9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078437818.00000000032E9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32E9000
|
Size: |
16384
|
|
3260000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078288433.0000000003260000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3260000
|
Size: |
16384
|
|
2FFC000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1121640020.0000000002FFC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2FFC000
|
Size: |
16384
|
|
4D81000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1139562618.0000000004D81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D81000
|
Size: |
106496
|
|
5A65000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1045798893.0000000005A65000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5A65000
|
Size: |
24576
|
|
29365850000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1364415371.0000029365850000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29365850000
|
Size: |
4096
|
|
C80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1027898738.0000000000C80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C80000
|
Size: |
16384
|
|
4F68000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1121403943.0000000004F68000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4F68000
|
Size: |
12288
|
|
453E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1044786040.000000000453E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
453E000
|
Size: |
8192
|
|
3094000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1129310688.0000000003094000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3094000
|
Size: |
8192
|
|
5670000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1138129417.0000000005670000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5670000
|
Size: |
4096
|
|
3094000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1128957188.0000000003094000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3094000
|
Size: |
8192
|
|
56C000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1120608193.000000000056C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
56C000
|
Size: |
16384
|
|
7800000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1092714773.0000000007800000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7800000
|
Size: |
36864
|
|
4D81000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1141589206.0000000004D81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D81000
|
Size: |
151552
|
|
21A9510C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2813199344.0000021A9510C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A9510C000
|
Size: |
4096
|
|
1255000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3467761348.0000000001255000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1255000
|
Size: |
28672
|
|
4550000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1041955719.0000000004550000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4550000
|
Size: |
4096
|
|
4810000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1022463080.0000000004810000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4810000
|
Size: |
4096
|
|
21A94E30000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.2811031621.0000021A94E30000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21A94E30000
|
Size: |
4096
|
|
4C17000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078585929.0000000004C17000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4C17000
|
Size: |
4096
|
|
5251000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1131738118.0000000005251000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5251000
|
Size: |
4096
|
|
21A94E50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.2809578079.0000021A94E50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21A94E50000
|
Size: |
4096
|
|
5B8E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1020431192.0000000005B8E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5B8E000
|
Size: |
8192
|
|
7B3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1018686235.00000000007B3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7B3000
|
Size: |
77824
|
|
4DC3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1148299513.0000000004DC3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC3000
|
Size: |
286720
|
|
527A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078641425.000000000527A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
527A000
|
Size: |
20480
|
|
7AD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1019693985.00000000007AD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7AD000
|
Size: |
20480
|
|
4DA8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1141589206.0000000004DA8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DA8000
|
Size: |
8192
|
|
7E9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1019031613.00000000007E9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E9000
|
Size: |
241664
|
|
499E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1022490834.000000000499E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
499E000
|
Size: |
8192
|
|
21A90113000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.2811451183.0000021A90113000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A90113000
|
Size: |
28672
|
|
29365864000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1364217079.0000029365864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29365864000
|
Size: |
4096
|
|
57E5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078641425.00000000057E5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
57E5000
|
Size: |
888832
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
C16000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1022002418.0000000000C16000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C16000
|
Size: |
12288
|
|
3294000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1121293542.0000000003294000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3294000
|
Size: |
4096
|
|
D40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1027972793.0000000000D40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D40000
|
Size: |
24576
|
|
3294000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1121312338.0000000003294000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3294000
|
Size: |
4096
|
|
7950000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1093240117.0000000007950000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7950000
|
Size: |
61440
|
|
3094000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1128686889.0000000003094000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3094000
|
Size: |
8192
|
|
7D1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1020021552.00000000007D1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7D1000
|
Size: |
65536
|
|
4D8A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1143384123.0000000004D8A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D8A000
|
Size: |
4096
|
|
3094000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1129222937.0000000003094000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3094000
|
Size: |
8192
|
|
59DC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1040953290.00000000059DC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
59DC000
|
Size: |
184320
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
5A78000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1045896673.0000000005A78000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5A78000
|
Size: |
4096
|
|
21A950C4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2812836192.0000021A950C4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A950C4000
|
Size: |
20480
|
|
2B6787E000
|
stack
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2811770223.0000002B6787E000.00000002.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page readonly
|
Base address: |
2B6787E000
|
Size: |
4096
|
|
5251000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1129919286.0000000005251000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5251000
|
Size: |
4096
|
|
21A90000000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2812548774.0000021A90000000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A90000000
|
Size: |
4096
|
|
45C000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.1120527803.000000000045C000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
45C000
|
Size: |
24576
|
|
3198000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1150976955.0000000003198000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3198000
|
Size: |
237568
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
B1D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1077492241.0000000000B1D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B1D000
|
Size: |
12288
|
|
1244000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3467761348.0000000001244000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1244000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
4D9F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1144226711.0000000004D9F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D9F000
|
Size: |
12288
|
|
2B66E8B000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2811626956.0000002B66E8B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2B66E8B000
|
Size: |
20480
|
|
7820000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1092803387.0000000007820000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7820000
|
Size: |
65536
|
|
5A94000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1146823967.0000000005A94000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5A94000
|
Size: |
1220608
|
|
4D40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1151259794.0000000004D40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D40000
|
Size: |
4096
|
|
720A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1091102886.000000000720A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
720A000
|
Size: |
24576
|
|
C20000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1022064761.0000000000C20000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C20000
|
Size: |
4096
|
|
293657B0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1365131317.00000293657B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
293657B0000
|
Size: |
8192
|
|
59DB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1043182015.00000000059DB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
59DB000
|
Size: |
4096
|
|
21A950FF000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2813113874.0000021A950FF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A950FF000
|
Size: |
8192
|
|
2ABA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1044412866.0000000002ABA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2ABA000
|
Size: |
122880
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
5BF3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1038755780.0000000005BF3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5BF3000
|
Size: |
356352
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
9C8000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1120724465.00000000009C8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9C8000
|
Size: |
77824
|
|
4D60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1150372409.0000000004D60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D60000
|
Size: |
12288
|
|
4616000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3470682634.0000000004616000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
4616000
|
Size: |
8192
|
|
2B6937E000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2811948276.0000002B6937E000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2B6937E000
|
Size: |
4096
|
|
29365870000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1364058321.0000029365870000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29365870000
|
Size: |
4096
|
|
2A95000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1021833259.0000000002A95000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A95000
|
Size: |
61440
|
|
7E2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1019693985.00000000007E2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E2000
|
Size: |
8192
|
|
3190000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1150976955.0000000003190000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3190000
|
Size: |
24576
|
|
798000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1019375717.0000000000798000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
798000
|
Size: |
8192
|
|
5030000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1041992007.0000000005030000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5030000
|
Size: |
4096
|
|
5A1F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1041449252.0000000005A1F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5A1F000
|
Size: |
16384
|
|
5A0B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1045692773.0000000005A0B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5A0B000
|
Size: |
8192
|
|
29365856000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1363934468.0000029365856000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29365856000
|
Size: |
12288
|
|
2FEF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3468916251.0000000002FEF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2FEF000
|
Size: |
4096
|
|
2A86000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1042499980.0000000002A86000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A86000
|
Size: |
12288
|
|
7A00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1094416349.0000000007A00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7A00000
|
Size: |
65536
|
|
4DBA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1144366726.0000000004DBA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DBA000
|
Size: |
73728
|
|
32DD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1151058470.00000000032DD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
32DD000
|
Size: |
12288
|
|
54CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1151671946.00000000054CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
54CE000
|
Size: |
8192
|
|
4D81000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1138690768.0000000004D81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D81000
|
Size: |
16384
|
|
29365871000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1363995424.0000029365871000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29365871000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4DA2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1144010298.0000000004DA2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DA2000
|
Size: |
73728
|
|
4D71000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1143417489.0000000004D71000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D71000
|
Size: |
57344
|
|
4DA1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1140732598.0000000004DA1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DA1000
|
Size: |
28672
|
|
7EF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1015900467.00000000007EF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7EF000
|
Size: |
8192
|
|
474000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000009.00000002.1150649991.0000000000474000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
474000
|
Size: |
36864
|
|
17A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1020678756.000000000017A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
17A000
|
Size: |
24576
|
|
2A98000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1041770222.0000000002A98000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A98000
|
Size: |
57344
|
|
5251000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1130114065.0000000005251000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5251000
|
Size: |
4096
|
|
25E9000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1043818993.00000000025E9000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
25E9000
|
Size: |
28672
|
|
45B4000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3469653795.00000000045B4000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
45B4000
|
Size: |
36864
|
|
B90000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1027622042.0000000000B90000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B90000
|
Size: |
4096
|
|
7744000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1092014147.0000000007744000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7744000
|
Size: |
147456
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
5980000
|
remote allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1025242408.0000000005980000.00000004.00000400.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
remote allocation
|
Protect: |
page read and write
|
Base address: |
5980000
|
Size: |
4096
|
|
4F50000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1121842226.0000000004F50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4F50000
|
Size: |
8192
|
|
C10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1022002418.0000000000C10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C10000
|
Size: |
16384
|
|
5C49000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1045966669.0000000005C49000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5C49000
|
Size: |
12288
|
|
5250000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1151613452.0000000005250000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5250000
|
Size: |
4096
|
|
78BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1093035517.00000000078BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
78BE000
|
Size: |
8192
|
|
5BA6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1038822868.0000000005BA6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5BA6000
|
Size: |
147456
|
|
59B9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1043182015.00000000059B9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
59B9000
|
Size: |
20480
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
5BE3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1039048879.0000000005BE3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5BE3000
|
Size: |
20480
|
|
29365853000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1364035197.0000029365853000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29365853000
|
Size: |
4096
|
|
560E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1151732651.000000000560E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
560E000
|
Size: |
8192
|
|
52B5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078641425.00000000052B5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
52B5000
|
Size: |
20480
|
|
4D61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1138859642.0000000004D61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D61000
|
Size: |
4096
|
|
ED79E7E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1364996291.000000ED79E7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
ED79E7E000
|
Size: |
8192
|
|
572E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1149075798.000000000572E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
572E000
|
Size: |
1220608
|
|
4D8A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1147989720.0000000004D8A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D8A000
|
Size: |
45056
|
|
5BB9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1039048879.0000000005BB9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5BB9000
|
Size: |
20480
|
|
76E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1021137529.000000000076E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
76E000
|
Size: |
73728
|
|
4D60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1150243779.0000000004D60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D60000
|
Size: |
12288
|
|
4D71000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1146315748.0000000004D71000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D71000
|
Size: |
57344
|
|
2AFD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1041232593.0000000002AFD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AFD000
|
Size: |
139264
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
4D81000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1141844420.0000000004D81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D81000
|
Size: |
98304
|
|
3094000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1129466601.0000000003094000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3094000
|
Size: |
8192
|
|
2A80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1044275712.0000000002A80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A80000
|
Size: |
16384
|
|
21A94E40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.2811055726.0000021A94E40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21A94E40000
|
Size: |
8192
|
|
151F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3468641748.000000000151F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
151F000
|
Size: |
4096
|
|
38FB000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3469164599.00000000038FB000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
38FB000
|
Size: |
36864
|
|
10FC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3467685237.00000000010FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
10FC000
|
Size: |
16384
|
|
29FC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1043888883.00000000029FC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29FC000
|
Size: |
12288
|
|
29365894000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1365926274.0000029365894000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29365894000
|
Size: |
16384
|
|
4D75000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1144150834.0000000004D75000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D75000
|
Size: |
40960
|
|
21A8F917000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2812500711.0000021A8F917000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A8F917000
|
Size: |
8192
|
|
7035000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.1090837824.0000000007035000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
7035000
|
Size: |
8192
|
|
4D69000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1127586833.0000000004D69000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D69000
|
Size: |
8192
|
|
2B6757E000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2811698615.0000002B6757E000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2B6757E000
|
Size: |
4096
|
|
29365831000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1364665890.0000029365831000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29365831000
|
Size: |
4096
|
|
29365866000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1365717183.0000029365866000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29365866000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
10000000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3471501503.0000000010000000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
10000000
|
Size: |
4096
|
|
2AA6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1041666626.0000000002AA6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AA6000
|
Size: |
204800
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
7A2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1018686235.00000000007A2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A2000
|
Size: |
8192
|
|
5A23000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1041391505.0000000005A23000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5A23000
|
Size: |
32768
|
|
21A94EC0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.1204012571.0000021A94EC0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21A94EC0000
|
Size: |
8192
|
|
2936589A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1365949528.000002936589A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2936589A000
|
Size: |
12288
|
|
406A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3469578902.000000000406A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
406A000
|
Size: |
8192
|
|
4D81000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1141018969.0000000004D81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D81000
|
Size: |
135168
|
|
21A950CA000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2812977809.0000021A950CA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A950CA000
|
Size: |
77824
|
|
320E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078237017.000000000320E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
320E000
|
Size: |
8192
|
|
21A9508F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2812836192.0000021A9508F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A9508F000
|
Size: |
143360
|
|
4D94000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1138690768.0000000004D94000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D94000
|
Size: |
4096
|
|
29365889000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1363862299.0000029365889000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29365889000
|
Size: |
36864
|
|
29365837000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1365486589.0000029365837000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29365837000
|
Size: |
28672
|
|
21A95330000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.2811223843.0000021A95330000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21A95330000
|
Size: |
4096
|
|
4D7E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1139562618.0000000004D7E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D7E000
|
Size: |
4096
|
|
7AD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1018686235.00000000007AD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7AD000
|
Size: |
20480
|
|
79E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1094217310.00000000079E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
79E0000
|
Size: |
65536
|
|
2A80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1042499980.0000000002A80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A80000
|
Size: |
20480
|
|
21A90CD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.2810855666.0000021A90CD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21A90CD0000
|
Size: |
4096
|
|
21A8F800000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2812052636.0000021A8F800000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A8F800000
|
Size: |
73728
|
|
2A92000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1021833259.0000000002A92000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A92000
|
Size: |
4096
|
|
803000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1015701775.0000000000803000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
803000
|
Size: |
77824
|
|
2FB9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1077816099.0000000002FB9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2FB9000
|
Size: |
16384
|
|
32E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078437818.00000000032E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32E0000
|
Size: |
32768
|
|
4CDF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1044906807.0000000004CDF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4CDF000
|
Size: |
4096
|
|
4D70000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1128214305.0000000004D70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D70000
|
Size: |
8192
|
|
4D99000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1140752568.0000000004D99000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D99000
|
Size: |
32768
|
|
4D9B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1141441493.0000000004D9B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D9B000
|
Size: |
61440
|
|
7030000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.1090837824.0000000007030000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
7030000
|
Size: |
12288
|
|
7C8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1018686235.00000000007C8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7C8000
|
Size: |
12288
|
|
8420000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1094679953.0000000008420000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8420000
|
Size: |
49152
|
|
2936585D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1364546066.000002936585D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2936585D000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
9730000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1103193592.0000000009730000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
9730000
|
Size: |
1802240
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
ED796FE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1364777995.000000ED796FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
ED796FE000
|
Size: |
8192
|
|
2AA9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1044325506.0000000002AA9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AA9000
|
Size: |
8192
|
|
21A8F906000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2812420644.0000021A8F906000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A8F906000
|
Size: |
28672
|
|
4D6D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1141745372.0000000004D6D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D6D000
|
Size: |
49152
|
|
21A95021000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2812616815.0000021A95021000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A95021000
|
Size: |
49152
|
|
21A8F8B3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2812312350.0000021A8F8B3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A8F8B3000
|
Size: |
8192
|
|
21A8F8AC000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2812312350.0000021A8F8AC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A8F8AC000
|
Size: |
16384
|
|
53F7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078641425.00000000053F7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
53F7000
|
Size: |
4116480
|
|
4D7E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1140574179.0000000004D7E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D7E000
|
Size: |
4096
|
|
3095000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1128981084.0000000003095000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3095000
|
Size: |
4096
|
|
21A94D62000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.2810811137.0000021A94D62000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21A94D62000
|
Size: |
4096
|
|
4D7E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1141160641.0000000004D7E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D7E000
|
Size: |
4096
|
|
21A94CD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.2811254277.0000021A94CD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21A94CD0000
|
Size: |
4096
|
|
4D81000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1138904036.0000000004D81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D81000
|
Size: |
16384
|
|
51DE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1151570354.00000000051DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
51DE000
|
Size: |
8192
|
|
2890000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1043860544.0000000002890000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2890000
|
Size: |
16384
|
|
787E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1092974483.000000000787E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
787E000
|
Size: |
8192
|
|
B8F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1027539780.0000000000B8F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B8F000
|
Size: |
4096
|
|
33B1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1121511920.00000000033B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33B1000
|
Size: |
159744
|
|
DD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3467432700.0000000000DD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DD0000
|
Size: |
16384
|
|
2B68479000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2811839758.0000002B68479000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2B68479000
|
Size: |
28672
|
|
2E63000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1120389414.0000000002E63000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E63000
|
Size: |
8192
|
|
7E2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1018686235.00000000007E2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E2000
|
Size: |
270336
|
|
2F0E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1077609933.0000000002F0E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2F0E000
|
Size: |
8192
|
|
7ED000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1015355954.00000000007ED000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7ED000
|
Size: |
77824
|
|
5251000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1150590006.0000000005251000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5251000
|
Size: |
4096
|
|
597E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1045521222.000000000597E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
597E000
|
Size: |
8192
|
|
78FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1093089901.00000000078FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
78FE000
|
Size: |
8192
|
|
4D84000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1143780872.0000000004D84000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D84000
|
Size: |
12288
|
|
2C7F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1120773397.0000000002C7F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2C7F000
|
Size: |
4096
|
|
21A90015000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2812592657.0000021A90015000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A90015000
|
Size: |
4096
|
|
478000
|
remote allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3466361375.0000000000478000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
478000
|
Size: |
36864
|
|
367D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1121425570.000000000367D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
367D000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
6FDD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1090775194.0000000006FDD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6FDD000
|
Size: |
12288
|
|
21A8F870000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2812214284.0000021A8F870000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A8F870000
|
Size: |
53248
|
|
2DE0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3468842267.0000000002DE0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DE0000
|
Size: |
16384
|
|
5BF3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1038845850.0000000005BF3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5BF3000
|
Size: |
356352
|
|
21A8F890000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2812214284.0000021A8F890000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A8F890000
|
Size: |
12288
|
|
5B70000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1023194815.0000000005B70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5B70000
|
Size: |
4096
|
|
52C7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078641425.00000000052C7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
52C7000
|
Size: |
65536
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
4DE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1146588319.0000000004DE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DE4000
|
Size: |
151552
|
|
5A18000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1040953290.0000000005A18000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5A18000
|
Size: |
77824
|
|
5BC1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1038932370.0000000005BC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5BC1000
|
Size: |
36864
|
|
319A000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.1078147725.000000000319A000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
319A000
|
Size: |
4096
|
|
3095000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1128755556.0000000003095000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3095000
|
Size: |
4096
|
|
7F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1015572665.00000000007F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7F1000
|
Size: |
61440
|
|
336F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3469131229.000000000336F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
336F000
|
Size: |
4096
|
|
21A8F8BD000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2812396948.0000021A8F8BD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A8F8BD000
|
Size: |
4096
|
|
3010000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1077986034.0000000003010000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3010000
|
Size: |
139264
|
|
2FA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1077710369.0000000002FA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2FA0000
|
Size: |
12288
|
|
4D61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1140772758.0000000004D61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D61000
|
Size: |
32768
|
|
2A87000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1043057905.0000000002A87000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A87000
|
Size: |
8192
|
|
2A63000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1042701323.0000000002A63000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A63000
|
Size: |
4096
|
|
7E4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1015834963.00000000007E4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E4000
|
Size: |
20480
|
|
4D6C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1143728748.0000000004D6C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D6C000
|
Size: |
20480
|
|
693000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1020933835.0000000000693000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
693000
|
Size: |
12288
|
|
B18000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1077492241.0000000000B18000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B18000
|
Size: |
16384
|
|
456000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.1120527803.0000000000456000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
456000
|
Size: |
8192
|
|
141E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3468599299.000000000141E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
141E000
|
Size: |
8192
|
|
21A94F00000
|
remote allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.1205759456.0000021A94F00000.00000004.00000400.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
remote allocation
|
Protect: |
page read and write
|
Base address: |
21A94F00000
|
Size: |
4096
|
|
5683000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1146207533.0000000005683000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5683000
|
Size: |
610304
|
|
326E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3469082586.000000000326E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
326E000
|
Size: |
8192
|
|
7738000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1092014147.0000000007738000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7738000
|
Size: |
8192
|
|
734E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1091394555.000000000734E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
734E000
|
Size: |
8192
|
|
3094000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1129015948.0000000003094000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3094000
|
Size: |
8192
|
|
53F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078641425.00000000053F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
53F0000
|
Size: |
24576
|
|
2B0F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1041787504.0000000002B0F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B0F000
|
Size: |
65536
|
|
2A87000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1044296843.0000000002A87000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A87000
|
Size: |
8192
|
|
2AFA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1044588740.0000000002AFA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AFA000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
35E0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1121783603.00000000035E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35E0000
|
Size: |
4096
|
|
2AA1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1021983109.0000000002AA1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AA1000
|
Size: |
12288
|
|
60AC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1023491600.00000000060AC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
60AC000
|
Size: |
16384
|
|
4D81000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1148398831.0000000004D81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D81000
|
Size: |
36864
|
|
3271000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078288433.0000000003271000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3271000
|
Size: |
16384
|
|
21A8F843000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2812130131.0000021A8F843000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A8F843000
|
Size: |
94208
|
|
31A5000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.1078201346.00000000031A5000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
31A5000
|
Size: |
45056
|
|
4D61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1143872342.0000000004D61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D61000
|
Size: |
32768
|
|
7E2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1019961642.00000000007E2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E2000
|
Size: |
8192
|
|
21A94E60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.2809536433.0000021A94E60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21A94E60000
|
Size: |
4096
|
|
2B67D7E000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2811820189.0000002B67D7E000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2B67D7E000
|
Size: |
4096
|
|
5670000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1137983240.0000000005670000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5670000
|
Size: |
4096
|
|
7980000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1093717214.0000000007980000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7980000
|
Size: |
65536
|
|
2B0F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1039266252.0000000002B0F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B0F000
|
Size: |
65536
|
|
2B03000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1042747687.0000000002B03000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B03000
|
Size: |
114688
|
|
2936585B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1365651716.000002936585B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2936585B000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
7FC90000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.1105447201.000000007FC90000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7FC90000
|
Size: |
4096
|
|
3294000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1121333651.0000000003294000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3294000
|
Size: |
4096
|
|
563E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1045237935.000000000563E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
563E000
|
Size: |
8192
|
|
21A9510A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2813199344.0000021A9510A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A9510A000
|
Size: |
4096
|
|
2FCA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1077886372.0000000002FCA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FCA000
|
Size: |
147456
|
|
2B6767E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2811722575.0000002B6767E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2B6767E000
|
Size: |
8192
|
|
7A2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1019693985.00000000007A2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A2000
|
Size: |
8192
|
|
4BDF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1044875841.0000000004BDF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4BDF000
|
Size: |
4096
|
|
580000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1020823159.0000000000580000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
580000
|
Size: |
16384
|
|
4FBE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1022940079.0000000004FBE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4FBE000
|
Size: |
8192
|
|
5BF3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1038966575.0000000005BF3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5BF3000
|
Size: |
356352
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4D61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1141485761.0000000004D61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D61000
|
Size: |
98304
|
|
2AE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1044588740.0000000002AE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AE4000
|
Size: |
49152
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
29365800000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1365255782.0000029365800000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29365800000
|
Size: |
73728
|
|
5395000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078641425.0000000005395000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5395000
|
Size: |
106496
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
805000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1016189820.0000000000805000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
805000
|
Size: |
69632
|
|
2AE2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1041232593.0000000002AE2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AE2000
|
Size: |
57344
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
31A2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078181912.00000000031A2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31A2000
|
Size: |
12288
|
|
4D81000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1139293105.0000000004D81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D81000
|
Size: |
16384
|
|
44FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1044767940.00000000044FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
44FE000
|
Size: |
8192
|
|
5251000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1130300296.0000000005251000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5251000
|
Size: |
4096
|
|
4D9F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1131682061.0000000004D9F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D9F000
|
Size: |
4096
|
|
5A61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1042660961.0000000005A61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5A61000
|
Size: |
40960
|
|
5A77000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1041421820.0000000005A77000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5A77000
|
Size: |
8192
|
|
5251000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1131824951.0000000005251000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5251000
|
Size: |
4096
|
|
4C10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078585929.0000000004C10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4C10000
|
Size: |
20480
|
|
4DA2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1144119886.0000000004DA2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DA2000
|
Size: |
94208
|
|
84C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1020090400.000000000084C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
84C000
|
Size: |
4096
|
|
2A99000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1022024648.0000000002A99000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A99000
|
Size: |
32768
|
|
4D7D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1138690768.0000000004D7D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D7D000
|
Size: |
8192
|
|
90E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1120676841.000000000090E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
90E000
|
Size: |
8192
|
|
867E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1094917095.000000000867E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
867E000
|
Size: |
8192
|
|
12F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3468454659.00000000012F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12F0000
|
Size: |
32768
|
|
29365854000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1363975751.0000029365854000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29365854000
|
Size: |
4096
|
|
5A41000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1039144200.0000000005A41000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5A41000
|
Size: |
147456
|
|
82D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1019882435.000000000082D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
82D000
|
Size: |
114688
|
|
363E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1121798196.000000000363E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
363E000
|
Size: |
8192
|
|
4D75000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1127791119.0000000004D75000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D75000
|
Size: |
4096
|
|
4D75000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1127586833.0000000004D75000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D75000
|
Size: |
4096
|
|
4D8E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1131682061.0000000004D8E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D8E000
|
Size: |
61440
|
|
A30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1027441147.0000000000A30000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A30000
|
Size: |
4096
|
|
21A90104000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.2811381852.0000021A90104000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A90104000
|
Size: |
16384
|
|
21A94E50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.2809612214.0000021A94E50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21A94E50000
|
Size: |
4096
|
|
4D87000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1144315149.0000000004D87000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D87000
|
Size: |
94208
|
|
5A89000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1148961267.0000000005A89000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5A89000
|
Size: |
1220608
|
|
5251000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1130339839.0000000005251000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5251000
|
Size: |
4096
|
|
21A90300000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.2811340992.0000021A90300000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21A90300000
|
Size: |
4096
|
|
2895000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1043860544.0000000002895000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2895000
|
Size: |
20480
|
|
818000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1021856750.0000000000818000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
818000
|
Size: |
49152
|
|
7D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1019693985.00000000007D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7D0000
|
Size: |
69632
|
|
BDE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1027698147.0000000000BDE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BDE000
|
Size: |
8192
|
|
29365842000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1364247213.0000029365842000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29365842000
|
Size: |
65536
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4D86000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1150351901.0000000004D86000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D86000
|
Size: |
16384
|
|
21A96000000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.2811477064.0000021A96000000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A96000000
|
Size: |
4096
|
|
29365873000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1365827747.0000029365873000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29365873000
|
Size: |
20480
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
3094000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1129537350.0000000003094000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3094000
|
Size: |
8192
|
|
305F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078067600.000000000305F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
305F000
|
Size: |
126976
|
|
568A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1148239025.000000000568A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
568A000
|
Size: |
610304
|
|
21A9505B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2812724902.0000021A9505B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A9505B000
|
Size: |
24576
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
3080000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078067600.0000000003080000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3080000
|
Size: |
258048
|
|
4E2E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1022915845.0000000004E2E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4E2E000
|
Size: |
8192
|
|
4560000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1041938136.0000000004560000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4560000
|
Size: |
4096
|
|
2F40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1077643675.0000000002F40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F40000
|
Size: |
20480
|
|
4D6C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1151350931.0000000004D6C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D6C000
|
Size: |
20480
|
|
21A8F913000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2812500711.0000021A8F913000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A8F913000
|
Size: |
12288
|
|
82D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1018686235.000000000082D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
82D000
|
Size: |
131072
|
|
4DAD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1144288675.0000000004DAD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DAD000
|
Size: |
106496
|
|
4D83000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1144550952.0000000004D83000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D83000
|
Size: |
16384
|
|
52A2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078641425.00000000052A2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
52A2000
|
Size: |
45056
|
|
5251000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1130523689.0000000005251000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5251000
|
Size: |
4096
|
|
2A98000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1021876366.0000000002A98000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A98000
|
Size: |
49152
|
|
3094000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1128863790.0000000003094000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3094000
|
Size: |
8192
|
|
4D81000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1149565883.0000000004D81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D81000
|
Size: |
36864
|
|
4D86000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1151458069.0000000004D86000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D86000
|
Size: |
16384
|
|
5251000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1130148547.0000000005251000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5251000
|
Size: |
4096
|
|
51E2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078641425.00000000051E2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
51E2000
|
Size: |
589824
|
|
2A86000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1042426514.0000000002A86000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A86000
|
Size: |
12288
|
|
283E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1043833593.000000000283E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
283E000
|
Size: |
8192
|
|
3095000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1128652700.0000000003095000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3095000
|
Size: |
4096
|
|
4D76000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1127493020.0000000004D76000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D76000
|
Size: |
86016
|
|
4D30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1151235062.0000000004D30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D30000
|
Size: |
8192
|
|
3095000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1129413996.0000000003095000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3095000
|
Size: |
4096
|
|
21A94DA4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.1204331062.0000021A94DA4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21A94DA4000
|
Size: |
4096
|
|
6620000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1023538141.0000000006620000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6620000
|
Size: |
8192
|
|
7D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1021330031.00000000007D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7D0000
|
Size: |
4096
|
|
2A80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1042426514.0000000002A80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A80000
|
Size: |
20480
|
|
3094000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1128506143.0000000003094000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3094000
|
Size: |
8192
|
|
21A8F902000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2812420644.0000021A8F902000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A8F902000
|
Size: |
8192
|
|
4D81000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1143479905.0000000004D81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D81000
|
Size: |
36864
|
|
4D7E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1141360415.0000000004D7E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D7E000
|
Size: |
4096
|
|
4D87000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1143534335.0000000004D87000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D87000
|
Size: |
12288
|
|
21A8F7E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2812032255.0000021A8F7E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21A8F7E0000
|
Size: |
4096
|
|
2ADC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1041666626.0000000002ADC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2ADC000
|
Size: |
24576
|
|
2A49000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1042586627.0000000002A49000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A49000
|
Size: |
90112
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
84C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1094851584.00000000084C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
84C0000
|
Size: |
4096
|
|
59BB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1045637073.00000000059BB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
59BB000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4DC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1041921258.0000000004DC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC0000
|
Size: |
4096
|
|
21A8F8A0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2812214284.0000021A8F8A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A8F8A0000
|
Size: |
40960
|
|
5A18000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1039285589.0000000005A18000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5A18000
|
Size: |
86016
|
|
29365826000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1365372131.0000029365826000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29365826000
|
Size: |
16384
|
|
781000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1019989304.0000000000781000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
781000
|
Size: |
94208
|
|
2936586A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1364138584.000002936586A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2936586A000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4D81000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1148049820.0000000004D81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D81000
|
Size: |
36864
|
|
3094000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1129124121.0000000003094000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3094000
|
Size: |
8192
|
|
2AAB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1022045155.0000000002AAB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AAB000
|
Size: |
20480
|
|
4D75000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1143479905.0000000004D75000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D75000
|
Size: |
40960
|
|
5210000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1023161570.0000000005210000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5210000
|
Size: |
4096
|
|
3090000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1150902596.0000000003090000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3090000
|
Size: |
16384
|
|
8430000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1094759600.0000000008430000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8430000
|
Size: |
8192
|
|
4D81000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1140574179.0000000004D81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D81000
|
Size: |
114688
|
|
4D83000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1144226711.0000000004D83000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D83000
|
Size: |
110592
|
|
3FF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3469550265.0000000003FF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3FF0000
|
Size: |
4096
|
|
125E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3467761348.000000000125E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
125E000
|
Size: |
32768
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
5251000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1130190475.0000000005251000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5251000
|
Size: |
4096
|
|
4F61000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078641425.0000000004F61000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4F61000
|
Size: |
348160
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
5273000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078641425.0000000005273000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5273000
|
Size: |
8192
|
|
50BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1023025431.00000000050BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
50BE000
|
Size: |
8192
|
|
4D81000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1141745372.0000000004D81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D81000
|
Size: |
172032
|
|
21A94D90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.2810400617.0000021A94D90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21A94D90000
|
Size: |
4096
|
|
3294000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1120423224.0000000003294000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3294000
|
Size: |
4096
|
|
82D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1019031613.000000000082D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
82D000
|
Size: |
131072
|
|
4D81000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1148449107.0000000004D81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D81000
|
Size: |
36864
|
|
21A8F8AA000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.2811525813.0000021A8F8AA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A8F8AA000
|
Size: |
24576
|
|
3269000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078288433.0000000003269000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3269000
|
Size: |
4096
|
|
4D94000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1138797889.0000000004D94000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D94000
|
Size: |
4096
|
|
4DE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1146419186.0000000004DE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DE4000
|
Size: |
151552
|
|
2B68D7E000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2811902772.0000002B68D7E000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2B68D7E000
|
Size: |
4096
|
|
ED7A17E000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000E.00000002.1365095213.000000ED7A17E000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
ED7A17E000
|
Size: |
4096
|
|
4D78000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1127396352.0000000004D78000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D78000
|
Size: |
98304
|
|
ED7A07E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1365053530.000000ED7A07E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
ED7A07E000
|
Size: |
8192
|
|
781000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1021280078.0000000000781000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
781000
|
Size: |
94208
|
|
C2F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1022064761.0000000000C2F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C2F000
|
Size: |
4096
|
|
5B72000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1023194815.0000000005B72000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5B72000
|
Size: |
16384
|
|
4D75000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1127850502.0000000004D75000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D75000
|
Size: |
4096
|
|
73CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1091467159.00000000073CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
73CE000
|
Size: |
8192
|
|
9A48000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1105296812.0000000009A48000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9A48000
|
Size: |
4096
|
|
740B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1091522826.000000000740B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
740B000
|
Size: |
20480
|
|
3095000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1128577926.0000000003095000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3095000
|
Size: |
4096
|
|
45A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1044802293.00000000045A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
45A0000
|
Size: |
4096
|
|
714E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1090994804.000000000714E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
714E000
|
Size: |
8192
|
|
5F69000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1081213353.0000000005F69000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F69000
|
Size: |
299008
|
|
2936588E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1365898224.000002936588E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2936588E000
|
Size: |
16384
|
|
21A8F8FF000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.2810878433.0000021A8F8FF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A8F8FF000
|
Size: |
8192
|
|
2A73000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1042701323.0000000002A73000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A73000
|
Size: |
36864
|
|
4D60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1150414568.0000000004D60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D60000
|
Size: |
12288
|
|
21A90002000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2812548774.0000021A90002000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A90002000
|
Size: |
4096
|
|
2936585E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1364446043.000002936585E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2936585E000
|
Size: |
8192
|
|
553F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1045135225.000000000553F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
553F000
|
Size: |
4096
|
|
3094000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1129293151.0000000003094000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3094000
|
Size: |
8192
|
|
587E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1045480537.000000000587E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
587E000
|
Size: |
8192
|
|
4D65000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1139218202.0000000004D65000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D65000
|
Size: |
73728
|
|
367D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1121454434.000000000367D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
367D000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
21A94D60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.1204066669.0000021A94D60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21A94D60000
|
Size: |
425984
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4D7E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1141589206.0000000004D7E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D7E000
|
Size: |
4096
|
|
21A94E90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.2811081041.0000021A94E90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21A94E90000
|
Size: |
4096
|
|
4D99000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1141819602.0000000004D99000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D99000
|
Size: |
94208
|
|
3294000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1121479911.0000000003294000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3294000
|
Size: |
4096
|
|
4D9F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1144315149.0000000004D9F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D9F000
|
Size: |
57344
|
|
2AA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1042551595.0000000002AA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AA0000
|
Size: |
24576
|
|
2936586F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1364082552.000002936586F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2936586F000
|
Size: |
4096
|
|
11E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3467761348.00000000011E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11E0000
|
Size: |
20480
|
|
5F61000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1081213353.0000000005F61000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F61000
|
Size: |
28672
|
|
573C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1045274465.000000000573C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
573C000
|
Size: |
16384
|
|
5971000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1148748679.0000000005971000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5971000
|
Size: |
1073152
|
|
52C000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1120590979.000000000052C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
52C000
|
Size: |
16384
|
|
4D64000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1151259794.0000000004D64000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D64000
|
Size: |
20480
|
|
21A9011A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.1255312649.0000021A9011A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A9011A000
|
Size: |
4096
|
|
5CBE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1023323939.0000000005CBE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5CBE000
|
Size: |
8192
|
|
21A8F902000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.2810878433.0000021A8F902000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A8F902000
|
Size: |
45056
|
|
49E4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1022583247.00000000049E4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
49E4000
|
Size: |
8192
|
|
5723000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1146914439.0000000005723000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5723000
|
Size: |
1220608
|
|
4D7E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1140866704.0000000004D7E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D7E000
|
Size: |
4096
|
|
4D85000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1141915463.0000000004D85000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D85000
|
Size: |
81920
|
|
2AB9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1041729244.0000000002AB9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AB9000
|
Size: |
126976
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
34DE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1121755706.00000000034DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
34DE000
|
Size: |
8192
|
|
803000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1015430418.0000000000803000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
803000
|
Size: |
77824
|
|
50B8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078641425.00000000050B8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
50B8000
|
Size: |
1216512
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4FB7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078641425.0000000004FB7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4FB7000
|
Size: |
1040384
|
|
4DA2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1144366726.0000000004DA2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DA2000
|
Size: |
45056
|
|
9900000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1105190661.0000000009900000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
9900000
|
Size: |
32768
|
|
5251000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1129975393.0000000005251000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5251000
|
Size: |
4096
|
|
2DBC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3468785650.0000000002DBC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2DBC000
|
Size: |
16384
|
|
4D61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1141254877.0000000004D61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D61000
|
Size: |
40960
|
|
324F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078254320.000000000324F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
324F000
|
Size: |
4096
|
|
2B67C7B000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2811794470.0000002B67C7B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2B67C7B000
|
Size: |
20480
|
|
7E4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1019132172.00000000007E4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E4000
|
Size: |
20480
|
|
2AA4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1021684261.0000000002AA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AA4000
|
Size: |
102400
|
|
4D70000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1127850502.0000000004D70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D70000
|
Size: |
8192
|
|
4D70000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1127586833.0000000004D70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D70000
|
Size: |
8192
|
|
4DA5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1143918704.0000000004DA5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DA5000
|
Size: |
36864
|
|
21A950B3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2812836192.0000021A950B3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A950B3000
|
Size: |
53248
|
|
7FC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1016044709.00000000007FC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7FC000
|
Size: |
16384
|
|
21A95000000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2812616815.0000021A95000000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A95000000
|
Size: |
118784
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
3280000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.1078380748.0000000003280000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
3280000
|
Size: |
61440
|
|
4D81000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1140866704.0000000004D81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D81000
|
Size: |
135168
|
|
3094000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1129329806.0000000003094000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3094000
|
Size: |
8192
|
|
608C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1046028595.000000000608C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
608C000
|
Size: |
16384
|
|
322F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3469035616.000000000322F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
322F000
|
Size: |
4096
|
|
3095000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1150902596.0000000003095000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3095000
|
Size: |
4096
|
|
29365902000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1366086633.0000029365902000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29365902000
|
Size: |
16384
|
|
5A0B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1039285589.0000000005A0B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5A0B000
|
Size: |
8192
|
|
293657E0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1365187254.00000293657E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
293657E0000
|
Size: |
4096
|
|
21A94D80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.2811126867.0000021A94D80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21A94D80000
|
Size: |
4096
|
|
800000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1015262777.0000000000800000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
800000
|
Size: |
90112
|
|
21A9510C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.1258593193.0000021A9510C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A9510C000
|
Size: |
4096
|
|
3056000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1077986034.0000000003056000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3056000
|
Size: |
8192
|
|
79D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1094140097.00000000079D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
79D0000
|
Size: |
65536
|
|
3276000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078288433.0000000003276000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3276000
|
Size: |
40960
|
|
21A8F8B8000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2812312350.0000021A8F8B8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A8F8B8000
|
Size: |
16384
|
|
21A8F86C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2812153699.0000021A8F86C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A8F86C000
|
Size: |
12288
|
|
79F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1094338050.00000000079F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
79F0000
|
Size: |
65536
|
|
7AD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1021330031.00000000007AD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7AD000
|
Size: |
20480
|
|
29366002000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1366132311.0000029366002000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29366002000
|
Size: |
4096
|
|
ED7987E000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000E.00000002.1364856343.000000ED7987E000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
ED7987E000
|
Size: |
4096
|
|
4D81000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1140683734.0000000004D81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D81000
|
Size: |
159744
|
|
351F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1151126200.000000000351F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
351F000
|
Size: |
4096
|
|
4D7D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1149565883.0000000004D7D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D7D000
|
Size: |
8192
|
|
21A94D60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.1224534364.0000021A94D60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21A94D60000
|
Size: |
4096
|
|
53B1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078641425.00000000053B1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
53B1000
|
Size: |
200704
|
|
564F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1151752171.000000000564F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
564F000
|
Size: |
4096
|
|
3095000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1128709694.0000000003095000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3095000
|
Size: |
4096
|
|
83F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1094573794.00000000083F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
83F0000
|
Size: |
4096
|
|
5BFC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1039048879.0000000005BFC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5BFC000
|
Size: |
319488
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
7C8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1021330031.00000000007C8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7C8000
|
Size: |
12288
|
|
4D61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1127697478.0000000004D61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D61000
|
Size: |
32768
|
|
4D7E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1139490226.0000000004D7E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D7E000
|
Size: |
4096
|
|
4D69000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1138904036.0000000004D69000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D69000
|
Size: |
53248
|
|
5B85000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1023194815.0000000005B85000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5B85000
|
Size: |
4096
|
|
5A6C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1040899569.0000000005A6C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5A6C000
|
Size: |
53248
|
|
4D61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1143553435.0000000004D61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D61000
|
Size: |
65536
|
|
21A95066000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2812836192.0000021A95066000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A95066000
|
Size: |
163840
|
|
4D85000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1139466653.0000000004D85000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D85000
|
Size: |
73728
|
|
3290000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1121673259.0000000003290000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3290000
|
Size: |
16384
|
|
2936586E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1364102919.000002936586E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2936586E000
|
Size: |
4096
|
|
2A86000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1041599868.0000000002A86000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A86000
|
Size: |
335872
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
2A28000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1043955173.0000000002A28000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A28000
|
Size: |
131072
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
77E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1092641969.00000000077E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
77E0000
|
Size: |
24576
|
|
326C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078288433.000000000326C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
326C000
|
Size: |
8192
|
|
4D60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1150454430.0000000004D60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D60000
|
Size: |
12288
|
|
4DE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1149413213.0000000004DE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DE4000
|
Size: |
151552
|
|
4D8A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1148338351.0000000004D8A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D8A000
|
Size: |
8192
|
|
1E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1020697007.00000000001E0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E0000
|
Size: |
4096
|
|
4EB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1041867959.0000000004EB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4EB0000
|
Size: |
4096
|
|
5251000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1150551437.0000000005251000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5251000
|
Size: |
225280
|
|
2AAE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1044365056.0000000002AAE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AAE000
|
Size: |
8192
|
|
2D7F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1120789697.0000000002D7F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2D7F000
|
Size: |
4096
|
|
2AA9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1021899924.0000000002AA9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AA9000
|
Size: |
28672
|
|
1226000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3467761348.0000000001226000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1226000
|
Size: |
110592
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
URLs found in memory or binary data |
Networking |
|
|
21A90102000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.2811381852.0000021A90102000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A90102000
|
Size: |
4096
|
|
21A950DF000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2813008201.0000021A950DF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A950DF000
|
Size: |
32768
|
|
2E6C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1120389414.0000000002E6C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E6C000
|
Size: |
4096
|
|
5180000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1151546467.0000000005180000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5180000
|
Size: |
4096
|
|
4D9D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1147989720.0000000004D9D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D9D000
|
Size: |
20480
|
|
3094000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1129037126.0000000003094000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3094000
|
Size: |
8192
|
|
2936583E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1364686741.000002936583E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2936583E000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2FB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1077816099.0000000002FB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2FB0000
|
Size: |
32768
|
|
21A94CE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.2811289654.0000021A94CE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21A94CE0000
|
Size: |
4096
|
|
3670000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1121812908.0000000003670000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3670000
|
Size: |
8192
|
|
4ACC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078477502.0000000004ACC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4ACC000
|
Size: |
16384
|
|
718F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1091030728.000000000718F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
718F000
|
Size: |
4096
|
|
4D8C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1138821566.0000000004D8C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D8C000
|
Size: |
4096
|
|
4D6C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1143833117.0000000004D6C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D6C000
|
Size: |
20480
|
|
77DE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1092611962.00000000077DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
77DE000
|
Size: |
8192
|
|
3095000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1128932960.0000000003095000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3095000
|
Size: |
4096
|
|
4D8A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1149511108.0000000004D8A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D8A000
|
Size: |
45056
|
|
45C0000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3470682634.00000000045C0000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
45C0000
|
Size: |
344064
|
|
4D7E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1141844420.0000000004D7E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D7E000
|
Size: |
4096
|
|
95E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1120708830.000000000095E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
95E000
|
Size: |
8192
|
|
3290000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078400334.0000000003290000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3290000
|
Size: |
65536
|
|
5E0000
|
heap
|
page readonly
|
|
|
|
Name: |
0000000A.00000002.1120645532.00000000005E0000.00000002.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page readonly
|
Base address: |
5E0000
|
Size: |
4096
|
|
2F47000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1077643675.0000000002F47000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F47000
|
Size: |
12288
|
|
4D7E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1139107019.0000000004D7E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D7E000
|
Size: |
4096
|
|
21A94EA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.2811104219.0000021A94EA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21A94EA0000
|
Size: |
4096
|
|
4D6C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1144040335.0000000004D6C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D6C000
|
Size: |
20480
|
|
690000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1020933835.0000000000690000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
690000
|
Size: |
4096
|
|
353B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1151189070.000000000353B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
353B000
|
Size: |
16384
|
|
2B09000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1039169389.0000000002B09000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B09000
|
Size: |
90112
|
|
3539000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1151189070.0000000003539000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3539000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Found strings which match to known social media urls |
Networking |
|
URLs found in memory or binary data |
Networking |
|
|
49E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1022583247.00000000049E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
49E0000
|
Size: |
8192
|
|
4D6C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1143942373.0000000004D6C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D6C000
|
Size: |
20480
|
|
2A93000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1021713034.0000000002A93000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A93000
|
Size: |
69632
|
|
29365851000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1364289531.0000029365851000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29365851000
|
Size: |
4096
|
|
7790000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1092589295.0000000007790000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7790000
|
Size: |
4096
|
|
2A84000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1043057905.0000000002A84000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A84000
|
Size: |
4096
|
|
510D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1023089231.000000000510D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
510D000
|
Size: |
12288
|
|
2A20000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1043955173.0000000002A20000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A20000
|
Size: |
28672
|
|
2D7C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3468729180.0000000002D7C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2D7C000
|
Size: |
16384
|
|
DA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3467313613.0000000000DA0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DA0000
|
Size: |
4096
|
|
3094000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1129585218.0000000003094000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3094000
|
Size: |
8192
|
|
5A2D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1039188774.0000000005A2D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5A2D000
|
Size: |
81920
|
|
4C19000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078585929.0000000004C19000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4C19000
|
Size: |
4096
|
|
7F6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1015900467.00000000007F6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7F6000
|
Size: |
12288
|
|
4D9F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1144150834.0000000004D9F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D9F000
|
Size: |
12288
|
|
5670000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1138051447.0000000005670000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5670000
|
Size: |
4096
|
|
4D71000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1149666433.0000000004D71000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D71000
|
Size: |
49152
|
|
29365852000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1364159190.0000029365852000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29365852000
|
Size: |
4096
|
|
4DB4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1144092794.0000000004DB4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DB4000
|
Size: |
40960
|
|
825000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1021856750.0000000000825000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
825000
|
Size: |
4096
|
|
5292000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078641425.0000000005292000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5292000
|
Size: |
36864
|
|
9712000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1103155698.0000000009712000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9712000
|
Size: |
4096
|
|
4D61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1139161276.0000000004D61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D61000
|
Size: |
36864
|
|
5DF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1019624359.0000000005DF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5DF4000
|
Size: |
65536
|
|
4D81000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1146354376.0000000004D81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D81000
|
Size: |
36864
|
|
4D9D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1151489960.0000000004D9D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D9D000
|
Size: |
20480
|
|
5A55000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1039188774.0000000005A55000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5A55000
|
Size: |
65536
|
|
5BE8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1039002518.0000000005BE8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5BE8000
|
Size: |
32768
|
|
2D1E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1044754246.0000000002D1E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2D1E000
|
Size: |
8192
|
|
3294000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1120443157.0000000003294000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3294000
|
Size: |
4096
|
|
825000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1019882435.0000000000825000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
825000
|
Size: |
4096
|
|
5A08000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1045692773.0000000005A08000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5A08000
|
Size: |
4096
|
|
29365858000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1365602189.0000029365858000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29365858000
|
Size: |
4096
|
|
5B85000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1020489483.0000000005B85000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5B85000
|
Size: |
4096
|
|
21A94D50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.2810462441.0000021A94D50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21A94D50000
|
Size: |
4096
|
|
610A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1081213353.000000000610A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
610A000
|
Size: |
2273280
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
323A000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1121658076.000000000323A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
323A000
|
Size: |
24576
|
|
2A49000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1044214581.0000000002A49000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A49000
|
Size: |
90112
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
287E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1043847215.000000000287E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
287E000
|
Size: |
8192
|
|
3250000
|
heap
|
page readonly
|
|
|
|
Name: |
00000005.00000002.1078271305.0000000003250000.00000002.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page readonly
|
Base address: |
3250000
|
Size: |
4096
|
|
4D72000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1151373533.0000000004D72000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D72000
|
Size: |
45056
|
|
2A7C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1041599868.0000000002A7C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A7C000
|
Size: |
36864
|
|
2A89000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1041706954.0000000002A89000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A89000
|
Size: |
118784
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4D64000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1150414568.0000000004D64000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D64000
|
Size: |
20480
|
|
9A34000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1105296812.0000000009A34000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9A34000
|
Size: |
4096
|
|
4D9E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1143808228.0000000004D9E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D9E000
|
Size: |
61440
|
|
7970000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1093409185.0000000007970000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7970000
|
Size: |
65536
|
|
7EB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1015430418.00000000007EB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7EB000
|
Size: |
8192
|
|
8400000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1094602076.0000000008400000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8400000
|
Size: |
4096
|
|
4D7E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1140772758.0000000004D7E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D7E000
|
Size: |
4096
|
|
21A950F7000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2813008201.0000021A950F7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A950F7000
|
Size: |
16384
|
|
4F1F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1121828487.0000000004F1F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4F1F000
|
Size: |
4096
|
|
42B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1043738044.000000000042B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
42B000
|
Size: |
20480
|
|
DB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3467376156.0000000000DB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DB0000
|
Size: |
4096
|
|
7C8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1019693985.00000000007C8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7C8000
|
Size: |
12288
|
|
BE0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1027777236.0000000000BE0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BE0000
|
Size: |
20480
|
|
3530000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1151169388.0000000003530000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3530000
|
Size: |
20480
|
|
ED79D7E000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000E.00000002.1364962758.000000ED79D7E000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
ED79D7E000
|
Size: |
4096
|
|
21A8F88E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2812214284.0000021A8F88E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A8F88E000
|
Size: |
4096
|
|
74FF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1091620472.00000000074FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
74FF000
|
Size: |
4096
|
|
4D9D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1144791726.0000000004D9D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D9D000
|
Size: |
20480
|
|
7A10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1094496754.0000000007A10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7A10000
|
Size: |
65536
|
|
2AB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1021762261.0000000002AB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AB0000
|
Size: |
36864
|
|
4100000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3469618031.0000000004100000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4100000
|
Size: |
4096
|
|
21A8F8B8000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.2811525813.0000021A8F8B8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A8F8B8000
|
Size: |
16384
|
|
2FC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1077886372.0000000002FC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FC0000
|
Size: |
36864
|
|
5DD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1023379350.0000000005DD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5DD0000
|
Size: |
4096
|
|
293657D0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1365158027.00000293657D0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
293657D0000
|
Size: |
4096
|
|
21A95062000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2812799042.0000021A95062000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A95062000
|
Size: |
12288
|
|
2D3D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3468674246.0000000002D3D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2D3D000
|
Size: |
12288
|
|
76AD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1091746051.00000000076AD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
76AD000
|
Size: |
274432
|
|
53A1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1120326516.00000000053A1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
53A1000
|
Size: |
225280
|
|
21A8F82B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2812106156.0000021A8F82B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A8F82B000
|
Size: |
94208
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
4D7E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1139367886.0000000004D7E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D7E000
|
Size: |
4096
|
|
21A94DC9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.1204066669.0000021A94DC9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21A94DC9000
|
Size: |
28672
|
|
29365863000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1364327847.0000029365863000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29365863000
|
Size: |
4096
|
|
2FA4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1077777585.0000000002FA4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2FA4000
|
Size: |
36864
|
|
4D81000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1139218202.0000000004D81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D81000
|
Size: |
16384
|
|
7E6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1021765615.00000000007E6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E6000
|
Size: |
12288
|
|
21A9504E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2812724902.0000021A9504E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A9504E000
|
Size: |
12288
|
|
805000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1019190624.0000000000805000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
805000
|
Size: |
126976
|
|
6F9F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1090711037.0000000006F9F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6F9F000
|
Size: |
4096
|
|
2A63000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1042586627.0000000002A63000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A63000
|
Size: |
4096
|
|
5D0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1120628727.00000000005D0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5D0000
|
Size: |
4096
|
|
3094000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1129372580.0000000003094000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3094000
|
Size: |
8192
|
|
710000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1021035780.0000000000710000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
710000
|
Size: |
4096
|
|
21A94DA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.1204331062.0000021A94DA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21A94DA0000
|
Size: |
4096
|
|
DE0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3467617374.0000000000DE0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DE0000
|
Size: |
4096
|
|
21A8F867000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2812153699.0000021A8F867000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A8F867000
|
Size: |
4096
|
|
2AF3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1044588740.0000000002AF3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AF3000
|
Size: |
20480
|
|
52BD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078641425.00000000052BD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
52BD000
|
Size: |
28672
|
|
21A95055000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2812724902.0000021A95055000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A95055000
|
Size: |
12288
|
|
4DF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1041903948.0000000004DF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DF0000
|
Size: |
4096
|
|
825000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1019190624.0000000000825000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
825000
|
Size: |
4096
|
|
82D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1019190624.000000000082D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
82D000
|
Size: |
131072
|
|
29365813000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1365372131.0000029365813000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29365813000
|
Size: |
73728
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
7D2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1021724210.00000000007D2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7D2000
|
Size: |
61440
|
|
4A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1043804293.00000000004A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4A0000
|
Size: |
8192
|
|
4C0E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078569518.0000000004C0E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4C0E000
|
Size: |
8192
|
|
94E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1021956233.000000000094E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
94E000
|
Size: |
8192
|
|
45E000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000009.00000002.1150649991.000000000045E000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
45E000
|
Size: |
4096
|
|
2AB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1042623749.0000000002AB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AB0000
|
Size: |
36864
|
|
5AA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1041831687.0000000005AA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5AA0000
|
Size: |
319488
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2B6857E000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2811859475.0000002B6857E000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2B6857E000
|
Size: |
4096
|
|
29365855000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1363955170.0000029365855000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29365855000
|
Size: |
4096
|
|
9C0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1120724465.00000000009C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9C0000
|
Size: |
24576
|
|
5A24000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1045798893.0000000005A24000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5A24000
|
Size: |
28672
|
|
4D71000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1148049820.0000000004D71000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D71000
|
Size: |
57344
|
|
7CC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1027419572.00000000007CC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7CC000
|
Size: |
16384
|
|
5670000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1137936849.0000000005670000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5670000
|
Size: |
4096
|
|
7EE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1015430418.00000000007EE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7EE000
|
Size: |
73728
|
|
7EC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1021785540.00000000007EC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7EC000
|
Size: |
61440
|
|
5EF4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1020385678.0000000005EF4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5EF4000
|
Size: |
4096
|
|
84A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1021934572.000000000084A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
84A000
|
Size: |
8192
|
|
5A0B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1040953290.0000000005A0B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5A0B000
|
Size: |
8192
|
|
29365840000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1365512983.0000029365840000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29365840000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2A99000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1021899924.0000000002A99000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A99000
|
Size: |
45056
|
|
2A99000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1044325506.0000000002A99000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A99000
|
Size: |
28672
|
|
3294000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1120357222.0000000003294000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3294000
|
Size: |
4096
|
|
64CA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1081213353.00000000064CA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
64CA000
|
Size: |
10485760
|
|
B4E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1027464102.0000000000B4E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B4E000
|
Size: |
8192
|
|
7FB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1019866687.00000000007FB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7FB000
|
Size: |
40960
|
|
7960000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1093327616.0000000007960000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7960000
|
Size: |
65536
|
|
5BFC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1041475614.0000000005BFC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5BFC000
|
Size: |
327680
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
21A94D61000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.1270155352.0000021A94D61000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21A94D61000
|
Size: |
4096
|
|
7F9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1015786744.00000000007F9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7F9000
|
Size: |
28672
|
|
ED79AFE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1364881447.000000ED79AFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
ED79AFE000
|
Size: |
8192
|
|
C2F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1027858335.0000000000C2F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C2F000
|
Size: |
4096
|
|
9910000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1105242990.0000000009910000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9910000
|
Size: |
36864
|
|
BE0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1077572884.0000000000BE0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BE0000
|
Size: |
12288
|
|
5A2B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1040899569.0000000005A2B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5A2B000
|
Size: |
8192
|
|
4D8C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1138690768.0000000004D8C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D8C000
|
Size: |
4096
|
|
4D81000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1140772758.0000000004D81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D81000
|
Size: |
131072
|
|
4D8E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1128214305.0000000004D8E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D8E000
|
Size: |
61440
|
|
4D75000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1128214305.0000000004D75000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D75000
|
Size: |
4096
|
|
5251000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1131875249.0000000005251000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5251000
|
Size: |
4096
|
|
4D8A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1144441022.0000000004D8A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D8A000
|
Size: |
180224
|
|
31A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078167846.00000000031A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31A0000
|
Size: |
4096
|
|
41B000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.1121592224.000000000041B000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
41B000
|
Size: |
36864
|
|
5980000
|
remote allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1025181540.0000000005980000.00000004.00000400.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
remote allocation
|
Protect: |
page read and write
|
Base address: |
5980000
|
Size: |
4096
|
|
5251000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1130407747.0000000005251000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5251000
|
Size: |
4096
|
|
79C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1094047587.00000000079C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
79C0000
|
Size: |
65536
|
|
4D81000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1151399425.0000000004D81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D81000
|
Size: |
16384
|
|
4D99000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1140972606.0000000004D99000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D99000
|
Size: |
36864
|
|
5990000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1045595440.0000000005990000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5990000
|
Size: |
49152
|
|
5F8C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1046005228.0000000005F8C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5F8C000
|
Size: |
16384
|
|
4D81000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1141975774.0000000004D81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D81000
|
Size: |
16384
|
|
21A90100000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.2811431617.0000021A90100000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A90100000
|
Size: |
4096
|
|
701F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1090808986.000000000701F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
701F000
|
Size: |
4096
|
|
5BF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1038845850.0000000005BF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5BF0000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
12E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3468454659.00000000012E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12E0000
|
Size: |
32768
|
|
5670000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1138013826.0000000005670000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5670000
|
Size: |
4096
|
|
5680000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1139047896.0000000005680000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5680000
|
Size: |
167936
|
|
2936584F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1364508768.000002936584F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2936584F000
|
Size: |
4096
|
|
61AC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1023515858.00000000061AC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
61AC000
|
Size: |
16384
|
|
7714000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1092014147.0000000007714000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7714000
|
Size: |
139264
|
|
3094000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1129488880.0000000003094000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3094000
|
Size: |
8192
|
|
847D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1094786782.000000000847D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
847D000
|
Size: |
12288
|
|
5251000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1137816990.0000000005251000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5251000
|
Size: |
4096
|
|
4BCE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078552465.0000000004BCE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4BCE000
|
Size: |
8192
|
|
793D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1093172672.000000000793D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
793D000
|
Size: |
12288
|
|
52B1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078641425.00000000052B1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
52B1000
|
Size: |
12288
|
|
3294000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1120490051.0000000003294000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3294000
|
Size: |
4096
|
|
849000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1019393206.0000000000849000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
849000
|
Size: |
16384
|
|
3016000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1150759009.0000000003016000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3016000
|
Size: |
8192
|
|
2B67477000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2811675217.0000002B67477000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2B67477000
|
Size: |
36864
|
|
77F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1092678242.00000000077F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
77F0000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
21A94F00000
|
remote allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.1205676696.0000021A94F00000.00000004.00000400.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
remote allocation
|
Protect: |
page read and write
|
Base address: |
21A94F00000
|
Size: |
4096
|
|
5040000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1041813401.0000000005040000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5040000
|
Size: |
4096
|
|
3094000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1129699756.0000000003094000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3094000
|
Size: |
8192
|
|
3035000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1077986034.0000000003035000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3035000
|
Size: |
28672
|
|
2E60000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1120803729.0000000002E60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E60000
|
Size: |
12288
|
|
5251000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1138459639.0000000005251000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5251000
|
Size: |
4096
|
|
BDD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1077550941.0000000000BDD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BDD000
|
Size: |
12288
|
|
525F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1120914579.000000000525F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
525F000
|
Size: |
1028096
|
|
21A950E8000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2813008201.0000021A950E8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A950E8000
|
Size: |
20480
|
|
3094000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1121016762.0000000003094000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3094000
|
Size: |
8192
|
|
4DC3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1146277319.0000000004DC3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC3000
|
Size: |
286720
|
|
76F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1092014147.00000000076F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
76F1000
|
Size: |
139264
|
|
21A94EB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.2811315015.0000021A94EB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21A94EB0000
|
Size: |
4096
|
|
5251000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1130457020.0000000005251000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5251000
|
Size: |
4096
|
|
750000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1021137529.0000000000750000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
750000
|
Size: |
28672
|
|
7A2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1021330031.00000000007A2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A2000
|
Size: |
8192
|
|
21A950EE000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2813008201.0000021A950EE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A950EE000
|
Size: |
24576
|
|
312D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3468977422.000000000312D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
312D000
|
Size: |
12288
|
|
2ECF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1077591639.0000000002ECF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2ECF000
|
Size: |
4096
|
|
3290000
|
heap
|
page readonly
|
|
|
|
Name: |
00000009.00000002.1151035489.0000000003290000.00000002.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page readonly
|
Base address: |
3290000
|
Size: |
4096
|
|
4D71000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1127396352.0000000004D71000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D71000
|
Size: |
8192
|
|
7E2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1021748271.00000000007E2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E2000
|
Size: |
8192
|
|
5251000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1130252810.0000000005251000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5251000
|
Size: |
4096
|
|
21A950C2000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2812836192.0000021A950C2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A950C2000
|
Size: |
4096
|
|
84F0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.1094886494.00000000084F0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
84F0000
|
Size: |
8192
|
|
781000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1019318847.0000000000781000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
781000
|
Size: |
102400
|
|
3094000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1128892484.0000000003094000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3094000
|
Size: |
8192
|
|
21A95104000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2813113874.0000021A95104000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A95104000
|
Size: |
8192
|
|
2B672FD000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2811650780.0000002B672FD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2B672FD000
|
Size: |
12288
|
|
4D69000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1148398831.0000000004D69000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D69000
|
Size: |
90112
|
|
5BA2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1041475614.0000000005BA2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5BA2000
|
Size: |
16384
|
|
4DAA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1144063346.0000000004DAA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DAA000
|
Size: |
81920
|
|
2EEF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3468888786.0000000002EEF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2EEF000
|
Size: |
4096
|
|
ED79F7E000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000E.00000002.1365019166.000000ED79F7E000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
ED79F7E000
|
Size: |
4096
|
|
2B6777E000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2811746276.0000002B6777E000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2B6777E000
|
Size: |
4096
|
|
3094000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1129763381.0000000003094000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3094000
|
Size: |
8192
|
|
29365860000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1364372830.0000029365860000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29365860000
|
Size: |
4096
|
|
ED7977E000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000E.00000002.1364802147.000000ED7977E000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
ED7977E000
|
Size: |
4096
|
|
30EF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3468947376.00000000030EF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
30EF000
|
Size: |
4096
|
|
5251000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1129810059.0000000005251000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5251000
|
Size: |
4096
|
|
2AFA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1041232593.0000000002AFA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AFA000
|
Size: |
4096
|
|
2AB1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1044398732.0000000002AB1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AB1000
|
Size: |
32768
|
|
2B0A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1039227909.0000000002B0A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B0A000
|
Size: |
86016
|
|
4D81000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1143417489.0000000004D81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D81000
|
Size: |
36864
|
|
4D6C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1143968562.0000000004D6C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D6C000
|
Size: |
20480
|
|
4DA2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1144571120.0000000004DA2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DA2000
|
Size: |
81920
|
|
2F90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1077694670.0000000002F90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F90000
|
Size: |
8192
|
|
3094000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1129662945.0000000003094000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3094000
|
Size: |
8192
|
|
2A8C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1021785611.0000000002A8C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A8C000
|
Size: |
28672
|
|
4D99000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1140661425.0000000004D99000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D99000
|
Size: |
16384
|
|
53A0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1121864190.00000000053A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
53A0000
|
Size: |
4096
|
|
4D61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1143968562.0000000004D61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D61000
|
Size: |
36864
|
|
5EF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1020385678.0000000005EF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5EF0000
|
Size: |
4096
|
|
4D70000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1127697478.0000000004D70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D70000
|
Size: |
8192
|
|
461C000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3470682634.000000000461C000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
461C000
|
Size: |
24576
|
|
4D7E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1141975774.0000000004D7E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D7E000
|
Size: |
4096
|
|
816000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1019882435.0000000000816000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
816000
|
Size: |
57344
|
|
21A90820000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.2810962154.0000021A90820000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21A90820000
|
Size: |
4096
|
|
585D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1146712567.000000000585D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
585D000
|
Size: |
1073152
|
|
B90000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1077532427.0000000000B90000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B90000
|
Size: |
4096
|
|
C1A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1022002418.0000000000C1A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C1A000
|
Size: |
20480
|
|
29365845000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1365570437.0000029365845000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29365845000
|
Size: |
32768
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4D7E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1140683734.0000000004D7E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D7E000
|
Size: |
4096
|
|
2A73000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1042426514.0000000002A73000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A73000
|
Size: |
36864
|
|
400000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.1120527803.0000000000400000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
400000
|
Size: |
344064
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
53E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1020784174.000000000053E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
53E000
|
Size: |
8192
|
|
2AF3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1041232593.0000000002AF3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AF3000
|
Size: |
20480
|
|
4730000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1120821719.0000000004730000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4730000
|
Size: |
8192
|
|
5BA2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1038915416.0000000005BA2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5BA2000
|
Size: |
16384
|
|
C26000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1022064761.0000000000C26000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C26000
|
Size: |
32768
|
|
71CD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1091066165.00000000071CD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
71CD000
|
Size: |
12288
|
|
4D64000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1150243779.0000000004D64000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D64000
|
Size: |
20480
|
|
521F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1151592346.000000000521F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
521F000
|
Size: |
4096
|
|
4EB3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1041867959.0000000004EB3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4EB3000
|
Size: |
49152
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
5980000
|
remote allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1025207554.0000000005980000.00000004.00000400.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
remote allocation
|
Protect: |
page read and write
|
Base address: |
5980000
|
Size: |
4096
|
|
4D75000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1144485930.0000000004D75000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D75000
|
Size: |
40960
|
|
8701000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1095032788.0000000008701000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8701000
|
Size: |
7819264
|
|
3094000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1129097898.0000000003094000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3094000
|
Size: |
8192
|
|
3094000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1129626873.0000000003094000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3094000
|
Size: |
8192
|
|
4D60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1151259794.0000000004D60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D60000
|
Size: |
12288
|
|
7E7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1015900467.00000000007E7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E7000
|
Size: |
8192
|
|
21A8F7A0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2811986065.0000021A8F7A0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A8F7A0000
|
Size: |
4096
|
|
4D7E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1141745372.0000000004D7E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D7E000
|
Size: |
4096
|
|
21A953C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.2809230428.0000021A953C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21A953C0000
|
Size: |
4096
|
|
3539000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1150494750.0000000003539000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3539000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Found strings which match to known social media urls |
Networking |
|
URLs found in memory or binary data |
Networking |
|
|
4D81000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1139367886.0000000004D81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D81000
|
Size: |
69632
|
|
4D71000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1148449107.0000000004D71000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D71000
|
Size: |
57344
|
|
31C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078218905.00000000031C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31C0000
|
Size: |
4096
|
|
5251000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1137755962.0000000005251000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5251000
|
Size: |
4096
|
|
3032000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1150759009.0000000003032000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3032000
|
Size: |
4096
|
|
21A94FF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.2809393818.0000021A94FF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21A94FF0000
|
Size: |
4096
|
|
98F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1105129798.00000000098F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
98F0000
|
Size: |
16384
|
|
21A9011A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.1259771788.0000021A9011A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A9011A000
|
Size: |
4096
|
|
2FAD000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.1077797940.0000000002FAD000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
2FAD000
|
Size: |
8192
|
|
910000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1120693346.0000000000910000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
910000
|
Size: |
20480
|
|
21A8F7B0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2812011133.0000021A8F7B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A8F7B0000
|
Size: |
4096
|
|
5670000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1151770064.0000000005670000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5670000
|
Size: |
4096
|
|
21A8F8FF000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2812420644.0000021A8F8FF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A8F8FF000
|
Size: |
8192
|
|
4DAA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1141915463.0000000004DAA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DAA000
|
Size: |
24576
|
|
2936585F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1365684339.000002936585F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2936585F000
|
Size: |
4096
|
|
4D69000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1138859642.0000000004D69000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D69000
|
Size: |
53248
|
|
4B4E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078511835.0000000004B4E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4B4E000
|
Size: |
8192
|
|
2ADC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1041729244.0000000002ADC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2ADC000
|
Size: |
24576
|
|
5856000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1147000937.0000000005856000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5856000
|
Size: |
1220608
|
|
4D99000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1141227583.0000000004D99000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D99000
|
Size: |
40960
|
|
2FFC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1077886372.0000000002FFC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FFC000
|
Size: |
77824
|
|
3294000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1121380402.0000000003294000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3294000
|
Size: |
4096
|
|
597B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1146634298.000000000597B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
597B000
|
Size: |
1073152
|
|
29365892000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1363790925.0000029365892000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29365892000
|
Size: |
24576
|
|
4B0E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078494912.0000000004B0E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4B0E000
|
Size: |
8192
|
|
4D7E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1151399425.0000000004D7E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D7E000
|
Size: |
4096
|
|
5DD1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1020042506.0000000005DD1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5DD1000
|
Size: |
143360
|
|
518D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1128099426.000000000518D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
518D000
|
Size: |
684032
|
|
4D81000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1139490226.0000000004D81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D81000
|
Size: |
16384
|
|
3537000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1150494750.0000000003537000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3537000
|
Size: |
4096
|
|
4D1E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1044923638.0000000004D1E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4D1E000
|
Size: |
8192
|
|
4D6D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1139367886.0000000004D6D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D6D000
|
Size: |
61440
|
|
3D4E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3469474645.0000000003D4E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3D4E000
|
Size: |
8192
|
|
842D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1094679953.000000000842D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
842D000
|
Size: |
4096
|
|
4D70000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1127791119.0000000004D70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D70000
|
Size: |
8192
|
|
490000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1043753768.0000000000490000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
490000
|
Size: |
4096
|
|
753E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1091650845.000000000753E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
753E000
|
Size: |
8192
|
|
302F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1150759009.000000000302F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
302F000
|
Size: |
8192
|
|
52DB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078641425.00000000052DB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
52DB000
|
Size: |
651264
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
32B0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1121688343.00000000032B0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32B0000
|
Size: |
4096
|
|
4D9F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1128214305.0000000004D9F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D9F000
|
Size: |
4096
|
|
21A8F813000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2812082505.0000021A8F813000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A8F813000
|
Size: |
94208
|
|
538D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078641425.000000000538D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
538D000
|
Size: |
4096
|
|
21A8F894000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2812214284.0000021A8F894000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A8F894000
|
Size: |
40960
|
|
52AE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078641425.00000000052AE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
52AE000
|
Size: |
8192
|
|
35DF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1121770289.00000000035DF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
35DF000
|
Size: |
4096
|
|
2A73000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1044255617.0000000002A73000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A73000
|
Size: |
36864
|
|
29365865000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1364186133.0000029365865000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29365865000
|
Size: |
20480
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
3294000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1120403359.0000000003294000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3294000
|
Size: |
4096
|
|
2936586B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1365747346.000002936586B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2936586B000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2FEF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1077886372.0000000002FEF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FEF000
|
Size: |
8192
|
|
4D7E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1139218202.0000000004D7E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D7E000
|
Size: |
4096
|
|
21A94F00000
|
remote allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.1205841673.0000021A94F00000.00000004.00000400.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
remote allocation
|
Protect: |
page read and write
|
Base address: |
21A94F00000
|
Size: |
4096
|
|
4DE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1148561017.0000000004DE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DE4000
|
Size: |
151552
|
|
32A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078421139.00000000032A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32A0000
|
Size: |
4096
|
|
4D85000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1149726399.0000000004D85000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D85000
|
Size: |
20480
|
|
55CF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1151689660.00000000055CF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
55CF000
|
Size: |
4096
|
|
2ADC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1044412866.0000000002ADC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2ADC000
|
Size: |
24576
|
|
2A87000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1022067203.0000000002A87000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A87000
|
Size: |
20480
|
|
2AFD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1044588740.0000000002AFD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AFD000
|
Size: |
24576
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
2AB9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1021740394.0000000002AB9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AB9000
|
Size: |
16384
|
|
21A94E30000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.1204953234.0000021A94E30000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21A94E30000
|
Size: |
4096
|
|
4D9D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1149511108.0000000004D9D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D9D000
|
Size: |
20480
|
|
3294000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1121496790.0000000003294000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3294000
|
Size: |
4096
|
|
21A95041000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2812668202.0000021A95041000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21A95041000
|
Size: |
49152
|
|
599D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1045595440.000000000599D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
599D000
|
Size: |
114688
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4D9D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1148338351.0000000004D9D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D9D000
|
Size: |
155648
|
|
710B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1090955167.000000000710B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
710B000
|
Size: |
20480
|
|
4DA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1127932660.0000000004DA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DA0000
|
Size: |
8192
|
|
800000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1021809299.0000000000800000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
800000
|
Size: |
20480
|
|
53E4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1078641425.00000000053E4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
53E4000
|
Size: |
45056
|
|
2E6C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1120441071.0000000002E6C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E6C000
|
Size: |
4096
|
|
4D83000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1143576045.0000000004D83000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D83000
|
Size: |
16384
|
|